Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,244 results · page 30 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-65093 | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. | CRITICAL 9.9EPSS 0.55% | 25 August 2026 |
| CVE-2026-65084 | NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. | CRITICAL 9.8EPSS 0.37% | 25 August 2026 |
| CVE-2026-65083 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. | CRITICAL 9.9EPSS 0.61% | 25 August 2026 |
| CVE-2026-65081 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. | CRITICAL 9.8EPSS 0.30% | 25 August 2026 |
| CVE-2026-51368 | An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint | CRITICAL 9.8EPSS 0.60% | 25 August 2026 |
| CVE-2026-45018 | From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. | CRITICAL 9.8EPSS 0.65% | 25 August 2026 |
| CVE-2026-79787 | Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. | CRITICAL 9.3EPSS 0.35% | 25 August 2026 |
| CVE-2026-78379 | Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted… | CRITICAL 9.2EPSS 0.32% | 25 August 2026 |
| CVE-2026-76197 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 10.0EPSS 1.59% | 25 August 2026 |
| CVE-2026-76195 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 10.0EPSS 1.59% | 25 August 2026 |
| CVE-2026-76193 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 10.0EPSS 0.68% | 25 August 2026 |
| CVE-2026-19912 | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl,… | CRITICAL 9.8EPSS 0.59% | 25 August 2026 |
| CVE-2026-79782 | Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers. | CRITICAL 9.3EPSS 0.13% | 25 August 2026 |
| CVE-2026-79774 | Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. | CRITICAL 9.3EPSS 0.43% | 25 August 2026 |
| CVE-2026-79675 | NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. | CRITICAL 9.3EPSS 0.43% | 25 August 2026 |
| CVE-2026-55640 | The payload["user"]["uid"] field parsed in nextcloud_mcp_server/vector/webhook_parser.py is attacker-controlled and is used without an authenticated-session cross-check for Qdrant operations, allowing a network attacker to delete or trigger re-indexing… | CRITICAL 9.1EPSS 0.48% | 25 August 2026 |
| CVE-2026-55546 | Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to Python exponent syntax, without… | CRITICAL 9.8EPSS 0.41% | 25 August 2026 |
| CVE-2026-55536 | Extra trailing characters pass before websocket.accept(), allowing start_session commands and unauthorized browser automation. | CRITICAL 9.1EPSS 0.29% | 25 August 2026 |
| CVE-2026-16286 | Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. | CRITICAL 9.8EPSS 0.32% | 25 August 2026 |
| CVE-2026-77998 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This… | CRITICAL 10.0EPSS 0.34% | 25 August 2026 |
| CVE-2026-75803 | CWE: CWE-354 (Improper Validation of Integrity Check Value) Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. | CRITICAL 9.1EPSS 0.22% | 25 August 2026 |
| CVE-2026-63073 | Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender. | CRITICAL 9.8EPSS 0.93% | 25 August 2026 |
| CVE-2026-79664 | Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. | CRITICAL 9.1EPSS 0.22% | 25 August 2026 |
| CVE-2026-79657 | NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. | CRITICAL 9.3EPSS 1.21% | 25 August 2026 |
| CVE-2026-57910 | Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges. | CRITICAL 9.3EPSS 0.20% | 25 August 2026 |
| CVE-2026-57909 | A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system. | CRITICAL 9.4EPSS 0.29% | 25 August 2026 |
| CVE-2026-55976 | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the… | CRITICAL 9.1EPSS 0.59% | 25 August 2026 |
| CVE-2026-49845 | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including… | CRITICAL 9.8EPSS 0.52% | 25 August 2026 |
| CVE-2026-77138 | The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). | CRITICAL 9.3EPSS 0.42% | 25 August 2026 |
| CVE-2026-77136 | An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and application source, and potentially remote code execution. | CRITICAL 9.5EPSS 0.55% | 25 August 2026 |
| CVE-2026-63586 | The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. | CRITICAL 9.3EPSS 0.52% | 25 August 2026 |
| CVE-2026-13214 | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). | CRITICAL 9.8EPSS 0.51% | 25 August 2026 |
| CVE-2026-78683 | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). | CRITICAL 9.4EPSS 0.29% | 25 August 2026 |
| CVE-2026-78676 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. | CRITICAL 9.3EPSS 0.43% | 25 August 2026 |
| CVE-2026-72702 | Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing… | CRITICAL 9.3EPSS 0.10% | 25 August 2026 |
| CVE-2026-72699 | The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. | CRITICAL 9.3EPSS 0.21% | 25 August 2026 |
| CVE-2026-56710 | An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions. | CRITICAL 9.3EPSS 0.28% | 25 August 2026 |
| CVE-2026-56705 | Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. | CRITICAL 9.3EPSS 0.50% | 25 August 2026 |
| CVE-2026-78267 | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | CRITICAL 9.8EPSS 0.27% | 24 August 2026 |
| CVE-2026-78265 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | CRITICAL 9.8EPSS 0.31% | 24 August 2026 |
| CVE-2026-78262 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | CRITICAL 9.8EPSS 0.33% | 24 August 2026 |
| CVE-2026-77337 | Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. | CRITICAL 9.1EPSS 0.39% | 24 August 2026 |
| CVE-2026-32563 | Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | CRITICAL 9.8EPSS 0.43% | 24 August 2026 |
| CVE-2026-32559 | Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. | CRITICAL 9.9EPSS 0.36% | 24 August 2026 |
| CVE-2026-32555 | Unauthenticated SQL Injection in Boost <= 2.0.4 versions. | CRITICAL 9.3EPSS 0.24% | 24 August 2026 |
| CVE-2026-32554 | Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. | CRITICAL 9.3EPSS 0.24% | 24 August 2026 |
| CVE-2026-77635 | Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. | CRITICAL 9.2EPSS 0.29% | 24 August 2026 |
| CVE-2026-52490 | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c | CRITICAL 9.8EPSS 0.40% | 24 August 2026 |
| CVE-2026-78555 | RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. | CRITICAL 9.4EPSS 0.36% | 24 August 2026 |
| CVE-2026-39975 | Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. | CRITICAL 9.4EPSS 0.35% | 24 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.