Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,244 results · page 27 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-59270 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. | CRITICAL 9.1EPSS 0.27% | 27 August 2026 |
| CVE-2026-47892 | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. | CRITICAL 9.8EPSS 0.36% | 27 August 2026 |
| CVE-2026-47891 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. | CRITICAL 9.8EPSS 0.29% | 27 August 2026 |
| CVE-2026-47890 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. | CRITICAL 9.8EPSS 0.31% | 27 August 2026 |
| CVE-2026-47884 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. | CRITICAL 9.8EPSS 0.42% | 27 August 2026 |
| CVE-2026-47875 | Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. | CRITICAL 9.8EPSS 0.29% | 27 August 2026 |
| CVE-2026-47864 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. | CRITICAL 9.8EPSS 4.08% | 27 August 2026 |
| CVE-2026-75340 | The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). | CRITICAL 9.1EPSS 0.23% | 26 August 2026 |
| CVE-2026-75338 | disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. | CRITICAL 9.8EPSS 0.33% | 26 August 2026 |
| CVE-2026-75336 | Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json. | CRITICAL 9.8EPSS 0.26% | 26 August 2026 |
| CVE-2026-75332 | Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). | CRITICAL 9.1EPSS 0.25% | 26 August 2026 |
| CVE-2026-75330 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. | CRITICAL 9.8EPSS 0.26% | 26 August 2026 |
| CVE-2026-65956 | In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached without administrator… | CRITICAL 10.0EPSS 0.36% | 26 August 2026 |
| CVE-2026-75329 | Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential. | CRITICAL 9.8EPSS 0.33% | 26 August 2026 |
| CVE-2026-65646 | Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges. | CRITICAL 9.9EPSS 0.39% | 26 August 2026 |
| CVE-2026-65641 | A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account. | CRITICAL 9.3EPSS 0.54% | 26 August 2026 |
| CVE-2026-75414 | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. | CRITICAL 9.8EPSS 0.46% | 26 August 2026 |
| CVE-2026-75411 | JeecgBoot v3.9.2 is vulnerable to Remote command execution. | CRITICAL 9.8EPSS 0.59% | 26 August 2026 |
| CVE-2026-52103 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted… | CRITICAL 9.8EPSS 0.57% | 26 August 2026 |
| CVE-2025-51679 | An issue was discovered in openRISC OR1200 commit 83ac6b. | CRITICAL 9.1EPSS 0.35% | 26 August 2026 |
| CVE-2026-75334 | The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. | CRITICAL 9.8EPSS 0.39% | 26 August 2026 |
| CVE-2026-75327 | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability: | CRITICAL 9.8EPSS 0.29% | 26 August 2026 |
| CVE-2026-68000 | The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. | CRITICAL 9.8EPSS 0.28% | 26 August 2026 |
| CVE-2026-60004 | Gitea Code Injection Vulnerability | KEVCRITICAL 9.8EPSS 86.8% | 26 August 2026 |
| CVE-2026-26448 | Stomper 5e2741e is vulnerable to Use-After-Free. | CRITICAL 9.8EPSS 0.38% | 26 August 2026 |
| CVE-2025-70293 | An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or… | CRITICAL 9.8EPSS 0.53% | 26 August 2026 |
| CVE-2025-70290 | An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. | CRITICAL 9.8EPSS 0.46% | 26 August 2026 |
| CVE-2026-75325 | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. | CRITICAL 9.8EPSS 0.35% | 26 August 2026 |
| CVE-2026-70419 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. | CRITICAL 9.1EPSS 2.19% | 26 August 2026 |
| CVE-2026-51106 | An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component | CRITICAL 9.3EPSS 0.23% | 26 August 2026 |
| CVE-2026-19485 | A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access… | CRITICAL 9.3EPSS 0.23% | 26 August 2026 |
| CVE-2025-61165 | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. | CRITICAL 9.8EPSS 0.35% | 26 August 2026 |
| CVE-2025-61163 | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. | CRITICAL 9.8EPSS 0.28% | 26 August 2026 |
| CVE-2026-47837 | Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. | CRITICAL 9.8EPSS 0.30% | 26 August 2026 |
| CVE-2023-42179 | Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. | CRITICAL 9.8EPSS 0.28% | 26 August 2026 |
| CVE-2026-81032 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. | CRITICAL 9.3EPSS 0.29% | 26 August 2026 |
| CVE-2026-80428 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and… | EXPLOITCRITICAL 9.3EPSS 2.33% | 26 August 2026 |
| CVE-2026-54569 | From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. | CRITICAL 9.8EPSS 0.78% | 26 August 2026 |
| CVE-2026-80589 | In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allocated_queue() for a disk whose probe failed before add_disk(), but it only calls… | CRITICAL 9.8EPSS 0.38% | 26 August 2026 |
| CVE-2026-80587 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the RFC8684, but also because in different places, the code doesn't expect some… | CRITICAL 9.8EPSS 0.39% | 26 August 2026 |
| CVE-2026-80586 | In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send a malformed DSS with a wrong size, followed by another DSS or MPC + Data. | CRITICAL 9.8EPSS 0.40% | 26 August 2026 |
| CVE-2026-80585 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie SYN even when it carries no data. | CRITICAL 9.4EPSS 0.32% | 26 August 2026 |
| CVE-2026-80561 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_locker() decode_locker() in cls_lock_client.c contains three unsafe decode operations that allow a malicious or compromised OSD to trigger… | CRITICAL 9.8EPSS 0.52% | 26 August 2026 |
| CVE-2026-80558 | In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from primary_temp A corrupted osdmap received from a Ceph monitor or OSD may contain osd indices in its pg_temp, primary_temp, pg_upmap, and… | CRITICAL 9.8EPSS 0.52% | 26 August 2026 |
| CVE-2026-80557 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via missing bounds check ceph_start_decoding() validates that struct_len bytes remain in the buffer after the encoding header, but accepts… | CRITICAL 9.8EPSS 0.52% | 26 August 2026 |
| CVE-2026-80554 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel program segments The processing of channel programs, and the CCWs within them, is done recursively. | CRITICAL 9.3EPSS 0.14% | 26 August 2026 |
| CVE-2026-80551 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant The first IDAW in a list does not need to be on a 2K/4K boundary like all others, and so is read separately to accurately calculate the… | CRITICAL 9.3EPSS 0.14% | 26 August 2026 |
| CVE-2026-80528 | In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` pointer in `current->journal_info` while filling the inode and dentry cache from an… | CRITICAL 9.8EPSS 0.52% | 26 August 2026 |
| CVE-2026-80519 | In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer release Crypto completion callbacks hold both key-slot and peer references. | CRITICAL 9.8EPSS 0.45% | 26 August 2026 |
| CVE-2026-75062 | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated attackers to execute arbitrary Python code in the… | CRITICAL 9.2EPSS 0.23% | 26 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.