Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,244 results · page 28 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-74752 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use When cookie authentication is disabled, COOKIE_ECHO restores fixed-size AUTH fields directly from peer-controlled cookie bytes. | CRITICAL 9.8EPSS 0.43% | 26 August 2026 |
| CVE-2026-74751 | In the Linux kernel, the following vulnerability has been resolved: riscv: lib: Fix ZBB strnlen reading past count boundary The ZBB-optimized strnlen loop loads one word ahead before checking the aligned boundary: REG_L t1, SZREG(t0) // load next word… | CRITICAL 9.4EPSS 0.34% | 26 August 2026 |
| CVE-2026-74746 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. | CRITICAL 9.8EPSS 0.54% | 26 August 2026 |
| CVE-2026-74744 | In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(), but leave needed_headroom and needed_tailroom… | CRITICAL 9.8EPSS 0.52% | 26 August 2026 |
| CVE-2026-74743 | In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroom from lowerdev macvlan devices inherit hard_header_len from lowerdev during macvlan_init(), but leave needed_headroom and… | CRITICAL 9.8EPSS 0.52% | 26 August 2026 |
| CVE-2026-74737 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG On the packet reception path, the ID of the MAC Port on which the packet was received, is embedded in the RX DMA… | CRITICAL 9.8EPSS 0.56% | 26 August 2026 |
| CVE-2026-54523 | From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke generator.apply(namespace, resources) with an arbitrary target namespace. | CRITICAL 9.6EPSS 0.40% | 26 August 2026 |
| CVE-2026-75896 | Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords. | CRITICAL 9.1EPSS 0.23% | 26 August 2026 |
| CVE-2026-12717 | An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the… | CRITICAL 9.4EPSS 0.45% | 26 August 2026 |
| CVE-2026-80204 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's security/permissions blueprint section is editable. | CRITICAL 9.3EPSS 0.15% | 26 August 2026 |
| CVE-2026-80203 | The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. | CRITICAL 9.3EPSS 0.39% | 26 August 2026 |
| CVE-2026-77557 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device. | CRITICAL 9.8EPSS 0.33% | 26 August 2026 |
| CVE-2026-77554 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device. | CRITICAL 10.0EPSS 0.99% | 26 August 2026 |
| CVE-2026-77553 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | CRITICAL 9.9EPSS 0.23% | 26 August 2026 |
| CVE-2026-77552 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device. | CRITICAL 9.8EPSS 0.89% | 26 August 2026 |
| CVE-2026-77551 | A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device. | CRITICAL 9.0EPSS 0.22% | 26 August 2026 |
| CVE-2026-77550 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. | CRITICAL 10.0EPSS 0.49% | 26 August 2026 |
| CVE-2026-77549 | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. | CRITICAL 9.0EPSS 0.30% | 26 August 2026 |
| CVE-2026-77548 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | CRITICAL 9.9EPSS 0.80% | 26 August 2026 |
| CVE-2026-77547 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | CRITICAL 9.9EPSS 0.80% | 26 August 2026 |
| CVE-2026-77546 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | CRITICAL 9.9EPSS 0.80% | 26 August 2026 |
| CVE-2026-77532 | A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device. | CRITICAL 9.6EPSS 0.27% | 26 August 2026 |
| CVE-2026-18080 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. | CRITICAL 9.8EPSS 0.67% | 26 August 2026 |
| CVE-2026-80349 | In midware/ssoMidware.js a single branch covers both the ignored-path list and the ignoreIps allowlist from config/loginConf.js, which contains the loopback address, and that branch assigns the effective account identity from the uid query parameter… | CRITICAL 9.3EPSS 0.45% | 26 August 2026 |
| CVE-2026-77545 | A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | CRITICAL 9.0EPSS 0.21% | 26 August 2026 |
| CVE-2026-77543 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | CRITICAL 9.9EPSS 0.80% | 26 August 2026 |
| CVE-2026-77542 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device. | CRITICAL 9.1EPSS 0.81% | 26 August 2026 |
| CVE-2026-77541 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. | CRITICAL 9.1EPSS 0.26% | 26 August 2026 |
| CVE-2026-77540 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. | CRITICAL 9.1EPSS 0.81% | 26 August 2026 |
| CVE-2026-77539 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. | CRITICAL 9.1EPSS 0.81% | 26 August 2026 |
| CVE-2026-77537 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | CRITICAL 10.0EPSS 0.94% | 26 August 2026 |
| CVE-2026-77536 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | CRITICAL 9.9EPSS 0.23% | 26 August 2026 |
| CVE-2026-77535 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device. | CRITICAL 9.1EPSS 0.81% | 26 August 2026 |
| CVE-2026-77534 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | CRITICAL 9.9EPSS 0.23% | 26 August 2026 |
| CVE-2026-59683 | The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). | CRITICAL 9.3EPSS 0.58% | 26 August 2026 |
| CVE-2026-80235 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. | CRITICAL 9.3EPSS 0.68% | 26 August 2026 |
| CVE-2026-77533 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | CRITICAL 9.9EPSS 1.01% | 26 August 2026 |
| CVE-2026-18431 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. | CRITICAL 9.8EPSS 0.64% | 26 August 2026 |
| CVE-2026-15203 | Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM… | CRITICAL 9.3EPSS 0.36% | 26 August 2026 |
| CVE-2026-80202 | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. | CRITICAL 9.3EPSS 0.34% | 26 August 2026 |
| CVE-2026-19632 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. | CRITICAL 9.8EPSS 2.49% | 26 August 2026 |
| CVE-2026-80138 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. | CRITICAL 9.2EPSS 0.80% | 25 August 2026 |
| CVE-2026-79911 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. | CRITICAL 9.3EPSS 0.64% | 25 August 2026 |
| CVE-2026-16645 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. | CRITICAL 9.1EPSS 0.23% | 25 August 2026 |
| CVE-2026-16644 | Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. | CRITICAL 9.1EPSS 0.31% | 25 August 2026 |
| CVE-2026-16641 | Vulnerability in Drupal Commerce Elavon. | CRITICAL 9.8EPSS 0.29% | 25 August 2026 |
| CVE-2026-16639 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. | CRITICAL 9.8EPSS 0.35% | 25 August 2026 |
| CVE-2026-78655 | Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session. | CRITICAL 9.1EPSS 0.50% | 25 August 2026 |
| CVE-2026-78619 | The challenge route feeds a submitted value to the helper once TOTP verification fails, so an attacker who knows a victim's password and holds a recovery code of their own passes the victim's second factor. | CRITICAL 9.8EPSS 0.62% | 25 August 2026 |
| CVE-2026-68525 | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. | CRITICAL 9.1EPSS 0.63% | 25 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.