Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,245 results · page 34 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-17040 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | CRITICAL 9.8EPSS 0.46% | 20 August 2026 |
| CVE-2026-17024 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper certificate validation. | CRITICAL 9.8EPSS 0.25% | 20 August 2026 |
| CVE-2026-17006 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. | CRITICAL 9.8EPSS 0.40% | 20 August 2026 |
| CVE-2026-17003 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write. | CRITICAL 9.1EPSS 0.32% | 20 August 2026 |
| CVE-2026-17000 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication. | CRITICAL 9.8EPSS 0.42% | 20 August 2026 |
| CVE-2026-77638 | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach. | CRITICAL 9.0EPSS 0.19% | 20 August 2026 |
| CVE-2026-71485 | The requestHeaders path in internal/proxy/http.go, the requestMetadata path in internal/proxy/grpc.go, and the Consume path in internal/unigrpc/grpc.go can forward an allowlisted value as a trusted backend header or metadata value. | CRITICAL 9.1EPSS 0.42% | 20 August 2026 |
| CVE-2026-67567 | This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. | CRITICAL 9.9EPSS 0.43% | 20 August 2026 |
| CVE-2026-43798 | A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. | CRITICAL 9.8EPSS 0.34% | 20 August 2026 |
| CVE-2026-19586 | A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. | CRITICAL 9.3EPSS 5.70% | 20 August 2026 |
| CVE-2026-73257 | Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. | CRITICAL 9.1EPSS 0.48% | 20 August 2026 |
| CVE-2026-73256 | Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. | CRITICAL 9.1EPSS 0.40% | 20 August 2026 |
| CVE-2026-73253 | Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. | CRITICAL 9.1EPSS 0.21% | 20 August 2026 |
| CVE-2026-73251 | Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. | CRITICAL 9.3EPSS 0.19% | 20 August 2026 |
| CVE-2026-63385 | Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass… | CRITICAL 9.2EPSS 0.40% | 20 August 2026 |
| CVE-2026-63382 | When libevent is deployed behind a proxy that frames the same request differently, an unauthenticated remote attacker can desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches. | CRITICAL 9.2EPSS 0.59% | 20 August 2026 |
| CVE-2026-53424 | Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. | CRITICAL 9.1EPSS 0.34% | 20 August 2026 |
| CVE-2026-2334 | An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. | CRITICAL 9.4EPSS 0.52% | 20 August 2026 |
| CVE-2026-71428 | An attacker who controls that URL can make a server-side ingestion service request loopback addresses, internal HTTP services, or cloud metadata endpoints through direct targets, redirects, or DNS rebinding. | CRITICAL 9.3EPSS 0.25% | 20 August 2026 |
| CVE-2026-55642 | An unauthenticated network attacker can call the /api/connection/connect and /api/query/execute routes to use configured database credentials and execute arbitrary SQL, allowing disclosure, modification, or destruction of data in connected databases. | CRITICAL 9.8EPSS 0.47% | 20 August 2026 |
| CVE-2026-18265 | OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. | CRITICAL 9.8EPSS 0.69% | 20 August 2026 |
| CVE-2026-63039 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. | CRITICAL 9.8EPSS 0.58% | 20 August 2026 |
| CVE-2026-63038 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. | CRITICAL 9.8EPSS 0.57% | 20 August 2026 |
| CVE-2026-63037 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. | CRITICAL 9.8EPSS 0.53% | 20 August 2026 |
| CVE-2026-16926 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input. | CRITICAL 9.1EPSS 0.31% | 20 August 2026 |
| CVE-2026-15706 | Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. | CRITICAL 9.8EPSS 0.35% | 20 August 2026 |
| CVE-2026-28164 | Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. | CRITICAL 9.6EPSS 0.15% | 20 August 2026 |
| CVE-2026-18482 | Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath… | CRITICAL 9.8EPSS 1.65% | 20 August 2026 |
| CVE-2026-74018 | Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. | CRITICAL 9.9EPSS 0.45% | 20 August 2026 |
| CVE-2026-74016 | Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. | CRITICAL 9.9EPSS 0.45% | 20 August 2026 |
| CVE-2026-74014 | Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. | CRITICAL 9.9EPSS 0.45% | 20 August 2026 |
| CVE-2026-74001 | Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | CRITICAL 9.8EPSS 0.40% | 20 August 2026 |
| CVE-2026-73993 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | CRITICAL 9.8EPSS 0.39% | 20 August 2026 |
| CVE-2026-73992 | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | CRITICAL 9.9EPSS 0.74% | 20 August 2026 |
| CVE-2026-68566 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | CRITICAL 9.3EPSS 0.29% | 20 August 2026 |
| CVE-2026-66682 | Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | CRITICAL 9.8EPSS 0.33% | 20 August 2026 |
| CVE-2026-66680 | Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. | CRITICAL 9.3EPSS 0.29% | 20 August 2026 |
| CVE-2026-66672 | Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | CRITICAL 9.8EPSS 0.39% | 20 August 2026 |
| CVE-2026-66649 | Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | CRITICAL 9.3EPSS 0.29% | 20 August 2026 |
| CVE-2026-66609 | Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | CRITICAL 9.3EPSS 0.29% | 20 August 2026 |
| CVE-2026-66600 | Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | CRITICAL 9.1EPSS 0.34% | 20 August 2026 |
| CVE-2026-66593 | Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | CRITICAL 9.3EPSS 0.29% | 20 August 2026 |
| CVE-2026-66592 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | CRITICAL 9.3EPSS 0.29% | 20 August 2026 |
| CVE-2026-66583 | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | CRITICAL 9.8EPSS 0.39% | 20 August 2026 |
| CVE-2025-15689 | Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. | CRITICAL 9.8EPSS 0.33% | 20 August 2026 |
| CVE-2025-15688 | Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | CRITICAL 9.3EPSS 0.29% | 20 August 2026 |
| CVE-2026-14950 | An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. | CRITICAL 9.2EPSS 0.60% | 20 August 2026 |
| CVE-2026-75860 | The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. | CRITICAL 9.8EPSS 0.34% | 20 August 2026 |
| CVE-2026-76886 | C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | CRITICAL 9.8EPSS 0.32% | 19 August 2026 |
| CVE-2026-76850 | LMDeploy deserializes disaggregated-serving peer messages with pickle. | CRITICAL 9.3EPSS 0.98% | 19 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.