Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,245 results · page 37 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-18776 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their… | CRITICAL 9.8EPSS 0.34% | 19 August 2026 |
| CVE-2026-18051 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web… | CRITICAL 10.0EPSS 0.44% | 19 August 2026 |
| CVE-2026-18031 | The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including… | CRITICAL 9.8EPSS 0.34% | 19 August 2026 |
| CVE-2026-76008 | This manipulation of the argument width/height causes stack-based buffer overflow. | CRITICAL 10.0EPSS 0.57% | 19 August 2026 |
| CVE-2026-11751 | A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections. | CRITICAL 9.1EPSS 0.24% | 19 August 2026 |
| CVE-2026-21580 | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0… | CRITICAL 9.3EPSS 0.40% | 18 August 2026 |
| CVE-2026-76036 | Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.81% | 18 August 2026 |
| CVE-2026-76035 | Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.39% | 18 August 2026 |
| CVE-2026-73930 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.9EPSS 0.38% | 18 August 2026 |
| CVE-2026-73924 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.1EPSS 0.31% | 18 August 2026 |
| CVE-2026-73922 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.1EPSS 0.31% | 18 August 2026 |
| CVE-2026-73921 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.8EPSS 0.35% | 18 August 2026 |
| CVE-2026-73920 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.4EPSS 0.33% | 18 August 2026 |
| CVE-2026-73917 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.1EPSS 0.40% | 18 August 2026 |
| CVE-2026-73916 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.1EPSS 0.40% | 18 August 2026 |
| CVE-2026-73912 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.8EPSS 0.36% | 18 August 2026 |
| CVE-2026-73905 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.8EPSS 0.35% | 18 August 2026 |
| CVE-2026-73866 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.1EPSS 0.40% | 18 August 2026 |
| CVE-2026-73865 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.1EPSS 0.31% | 18 August 2026 |
| CVE-2026-71167 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.4EPSS 0.33% | 18 August 2026 |
| CVE-2026-71166 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.4EPSS 0.42% | 18 August 2026 |
| CVE-2026-71164 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.8EPSS 0.47% | 18 August 2026 |
| CVE-2026-71152 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.8EPSS 0.47% | 18 August 2026 |
| CVE-2026-71102 | Vulnerability in the Portable Clusterware component of Oracle Database Server. | CRITICAL 9.1EPSS 0.42% | 18 August 2026 |
| CVE-2026-71074 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.8EPSS 0.47% | 18 August 2026 |
| CVE-2026-71065 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | CRITICAL 9.3EPSS 0.26% | 18 August 2026 |
| CVE-2026-71064 | Vulnerability in the Portable Clusterware component of Oracle Database Server. | CRITICAL 9.6EPSS 0.34% | 18 August 2026 |
| CVE-2026-71063 | Vulnerability in the Portable Clusterware component of Oracle Database Server. | CRITICAL 9.6EPSS 0.34% | 18 August 2026 |
| CVE-2026-71059 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). | CRITICAL 9.9EPSS 0.30% | 18 August 2026 |
| CVE-2026-71040 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). | CRITICAL 9.8EPSS 0.47% | 18 August 2026 |
| CVE-2026-71037 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). | CRITICAL 9.3EPSS 0.33% | 18 August 2026 |
| CVE-2026-71036 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). | CRITICAL 9.1EPSS 0.29% | 18 August 2026 |
| CVE-2026-71026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). | CRITICAL 9.1EPSS 0.40% | 18 August 2026 |
| CVE-2026-71015 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). | CRITICAL 9.1EPSS 0.40% | 18 August 2026 |
| CVE-2026-71014 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). | CRITICAL 9.1EPSS 0.31% | 18 August 2026 |
| CVE-2026-70998 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). | CRITICAL 9.3EPSS 0.26% | 18 August 2026 |
| CVE-2026-70997 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). | CRITICAL 9.1EPSS 0.35% | 18 August 2026 |
| CVE-2026-70995 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). | CRITICAL 9.8EPSS 0.35% | 18 August 2026 |
| CVE-2026-70994 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). | CRITICAL 9.1EPSS 0.35% | 18 August 2026 |
| CVE-2026-70984 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). | CRITICAL 9.1EPSS 0.42% | 18 August 2026 |
| CVE-2026-70981 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). | CRITICAL 9.1EPSS 0.42% | 18 August 2026 |
| CVE-2026-70980 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). | CRITICAL 9.0EPSS 0.37% | 18 August 2026 |
| CVE-2026-70979 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). | CRITICAL 9.1EPSS 0.31% | 18 August 2026 |
| CVE-2026-70978 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). | CRITICAL 9.1EPSS 0.40% | 18 August 2026 |
| CVE-2026-70977 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). | CRITICAL 9.1EPSS 0.42% | 18 August 2026 |
| CVE-2026-70976 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). | CRITICAL 9.1EPSS 0.31% | 18 August 2026 |
| CVE-2026-70970 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | CRITICAL 9.8EPSS 0.47% | 18 August 2026 |
| CVE-2026-70958 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). | CRITICAL 9.6EPSS 0.38% | 18 August 2026 |
| CVE-2026-70954 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). | CRITICAL 9.8EPSS 0.35% | 18 August 2026 |
| CVE-2026-70953 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). | CRITICAL 9.8EPSS 0.35% | 18 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.