Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,245 results · page 36 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-49441 | Replacing ossec.conf can configure root-executed commands and lead to code execution after a service reload. | CRITICAL 9.1EPSS 0.52% | 19 August 2026 |
| CVE-2026-48162 | From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file value to WAZUH_PATH without canonicalization or confinement. | CRITICAL 9.1EPSS 0.57% | 19 August 2026 |
| CVE-2026-48024 | A cluster peer holding the shared Fernet key can use traversal in files_metadata.json or a merged-file header to write files such as /var/ossec/etc/ossec.conf. | CRITICAL 9.1EPSS 0.72% | 19 August 2026 |
| CVE-2026-20359 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | CRITICAL 9.9EPSS 0.36% | 19 August 2026 |
| CVE-2026-20358 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | CRITICAL 10.0EPSS 0.46% | 19 August 2026 |
| CVE-2026-20357 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | CRITICAL 10.0EPSS 0.55% | 19 August 2026 |
| CVE-2026-20318 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | CRITICAL 9.6EPSS 0.35% | 19 August 2026 |
| CVE-2026-20317 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | CRITICAL 10.0EPSS 0.44% | 19 August 2026 |
| CVE-2026-20315 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | CRITICAL 10.0EPSS 0.41% | 19 August 2026 |
| CVE-2026-20231 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20231 are related to improper neutralization of special elements issues that are grouped… | CRITICAL 9.9EPSS 0.50% | 19 August 2026 |
| CVE-2026-20030 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | CRITICAL 10.0EPSS 0.55% | 19 August 2026 |
| CVE-2026-62668 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. | CRITICAL 9.4EPSS 0.42% | 19 August 2026 |
| CVE-2026-75954 | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. | CRITICAL 9.3EPSS 0.28% | 19 August 2026 |
| CVE-2026-75949 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path… | CRITICAL 10.0EPSS 0.31% | 19 August 2026 |
| CVE-2026-71960 | Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from… | CRITICAL 9.3EPSS 0.54% | 19 August 2026 |
| CVE-2026-53451 | Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits an absolute path or… | CRITICAL 9.8EPSS 0.86% | 19 August 2026 |
| CVE-2026-52889 | An unauthenticated attacker can place Twig syntax in one of these request-controlled inputs when a public form contains an affected Hidden field. | CRITICAL 9.8EPSS 0.68% | 19 August 2026 |
| CVE-2026-47187 | A victim or victim-side tool that follows such a link through ordinary operations such as cp, rsync, backup tooling, or an editor can disclose readable local files back to the server or write server-controlled content to writable local files,… | CRITICAL 9.3EPSS 0.41% | 19 August 2026 |
| CVE-2026-45272 | An administrator can submit a crafted SOCIAL_AUTH key name that closes the settings dictionary and injects arbitrary Python statements. | CRITICAL 9.4EPSS 0.37% | 19 August 2026 |
| CVE-2026-16816 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | CRITICAL 9.9EPSS 0.49% | 19 August 2026 |
| CVE-2026-16656 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication. | CRITICAL 9.8EPSS 0.42% | 19 August 2026 |
| CVE-2026-15068 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | CRITICAL 9.9EPSS 1.05% | 19 August 2026 |
| CVE-2026-15065 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file. | CRITICAL 9.1EPSS 0.48% | 19 August 2026 |
| CVE-2026-76244 | stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. | CRITICAL 9.1EPSS 0.22% | 19 August 2026 |
| CVE-2026-76243 | stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. | CRITICAL 9.2EPSS 0.40% | 19 August 2026 |
| CVE-2026-76242 | On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirected, an attacker can register a malicious peer and gain access to or tamper with federation traffic. | CRITICAL 9.1EPSS 0.27% | 19 August 2026 |
| CVE-2026-76214 | At login the anti-replay comparison is skipped by its own null guard, allowing an attacker who captures a successful WebAuthn assertion to replay it indefinitely and authenticate as the user without any interaction or hardware key. | CRITICAL 9.1EPSS 0.29% | 19 August 2026 |
| CVE-2026-76213 | phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. | CRITICAL 9.1EPSS 0.33% | 19 August 2026 |
| CVE-2026-75917 | SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getLeaf()/movePathTo()) used by the 'move/link to' path-selection dialogs, where document metadata fields… | CRITICAL 9.3EPSS 0.16% | 19 August 2026 |
| CVE-2026-75916 | SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. | CRITICAL 9.3EPSS 0.16% | 19 August 2026 |
| CVE-2026-74804 | Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting… | CRITICAL 9.3EPSS 0.28% | 19 August 2026 |
| CVE-2026-74803 | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group. | CRITICAL 10.0EPSS 0.31% | 19 August 2026 |
| CVE-2026-51366 | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter | CRITICAL 9.9EPSS 0.55% | 19 August 2026 |
| CVE-2026-16019 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. | CRITICAL 9.8EPSS 0.32% | 19 August 2026 |
| CVE-2024-58376 | Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. | CRITICAL 9.3EPSS 1.67% | 19 August 2026 |
| CVE-2026-73391 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | CRITICAL 9.3EPSS 0.24% | 19 August 2026 |
| CVE-2026-73390 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | CRITICAL 9.8EPSS 0.27% | 19 August 2026 |
| CVE-2026-73389 | Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | CRITICAL 9.8EPSS 0.32% | 19 August 2026 |
| CVE-2026-73388 | Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | CRITICAL 9.3EPSS 0.24% | 19 August 2026 |
| CVE-2026-73364 | Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | CRITICAL 9.8EPSS 0.31% | 19 August 2026 |
| CVE-2026-73347 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | CRITICAL 9.8EPSS 0.27% | 19 August 2026 |
| CVE-2026-73185 | Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | CRITICAL 9.3EPSS 0.24% | 19 August 2026 |
| CVE-2026-73183 | Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | CRITICAL 9.3EPSS 0.24% | 19 August 2026 |
| CVE-2026-67364 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). | CRITICAL 10.0EPSS 0.29% | 19 August 2026 |
| CVE-2026-66613 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. | CRITICAL 9.8EPSS 0.48% | 19 August 2026 |
| CVE-2026-19490 | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEVCRITICAL 9.3EPSS 5.60% | 19 August 2026 |
| CVE-2026-72889 | Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request,… | CRITICAL 9.8EPSS 0.35% | 19 August 2026 |
| CVE-2026-58082 | Some ISO-2022 variants can require up to 10 bytes per character, in which case conversions can trigger a stack buffer overflow of up to four bytes. | CRITICAL 9.8EPSS 0.36% | 19 August 2026 |
| CVE-2026-58081 | An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules. | CRITICAL 9.8EPSS 0.36% | 19 August 2026 |
| CVE-2026-18937 | The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary… | CRITICAL 9.0EPSS 0.40% | 19 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.