Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 40 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-60591 | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). | CRITICAL 9.1EPSS 0.42% | 18 August 2026 |
| CVE-2026-67443 | In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. | CRITICAL 9.2EPSS 0.62% | 18 August 2026 |
| CVE-2026-52735 | The zcashd reference implementation continues static signature-operation counting through disabled opcodes, so an attacker can broadcast P2SH spends that Zebra counts below MAX_BLOCK_SIGOPS while zcashd counts above the 20,000-operation limit. | CRITICAL 9.3EPSS 0.29% | 18 August 2026 |
| CVE-2026-55166 | An attacker could target cloud instance metadata or internal services from Lemur network context, potentially obtaining credentials available to the host. | CRITICAL 9.9EPSS 0.28% | 18 August 2026 |
| CVE-2026-47627 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. | CRITICAL 9.8EPSS 0.50% | 18 August 2026 |
| CVE-2026-47606 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. | CRITICAL 9.1EPSS 0.50% | 18 August 2026 |
| CVE-2026-75625 | Attackers on the agent-to-agent path or malicious peers can supply substituted content with forged CRC32 corrections that passes per-piece checks, poisoning the cache with attacker-chosen container image layers or manifests that are re-seeded and… | CRITICAL 9.1EPSS 0.20% | 18 August 2026 |
| CVE-2026-71879 | Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass | CRITICAL 9.1EPSS 0.48% | 18 August 2026 |
| CVE-2026-71878 | Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass | CRITICAL 9.2EPSS 0.48% | 18 August 2026 |
| CVE-2026-67921 | Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. | CRITICAL 9.3EPSS 0.20% | 18 August 2026 |
| CVE-2026-52610 | An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate"… | CRITICAL 9.1EPSS 0.82% | 18 August 2026 |
| CVE-2026-52608 | An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. | CRITICAL 9.8EPSS 0.61% | 18 August 2026 |
| CVE-2026-50161 | Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket frame that uses the 64-bit extended length encoding. | CRITICAL 9.3EPSS 0.38% | 18 August 2026 |
| CVE-2021-43717 | If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously. | CRITICAL 9.8EPSS 0.40% | 18 August 2026 |
| CVE-2021-43716 | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. | CRITICAL 9.8EPSS 0.30% | 18 August 2026 |
| CVE-2026-67271 | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. | CRITICAL 9.8EPSS 0.46% | 18 August 2026 |
| CVE-2026-57580 | An attacker with an account on the source identity provider who can set the account's NameID can inject an XML comment that truncates the value used by authentik to the text before the comment while the signed assertion remains valid. | CRITICAL 9.4EPSS 0.44% | 18 August 2026 |
| CVE-2026-52723 | A network-positioned attacker between the DiGA backend and the ePA system can intercept the VAU handshake, supply attacker-controlled certificate and key material, and satisfy the circular trust relationship. | CRITICAL 9.1EPSS 0.22% | 18 August 2026 |
| CVE-2026-18963 | The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. | CRITICAL 9.1EPSS 3.18% | 18 August 2026 |
| CVE-2026-75926 | Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes nodePermissionArgs in common/hexec/exec.go append --allow-child-process whenever the tool being launched is named tailwindcss. | CRITICAL 9.3EPSS 0.14% | 18 August 2026 |
| CVE-2026-75856 | CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. | CRITICAL 9.2EPSS 0.46% | 18 August 2026 |
| CVE-2026-45118 | Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in… | CRITICAL 9.3EPSS 0.38% | 18 August 2026 |
| CVE-2026-45117 | From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is available.… | CRITICAL 9.8EPSS 0.79% | 18 August 2026 |
| CVE-2026-12564 | The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role… | CRITICAL 9.6EPSS 0.28% | 18 August 2026 |
| CVE-2026-75784 | A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. | CRITICAL 9.3EPSS 1.02% | 18 August 2026 |
| CVE-2026-74015 | Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | CRITICAL 9.3EPSS 0.29% | 18 August 2026 |
| CVE-2026-73996 | Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | CRITICAL 9.8EPSS 0.36% | 18 August 2026 |
| CVE-2026-73397 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | CRITICAL 9.8EPSS 0.39% | 18 August 2026 |
| CVE-2026-73381 | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | CRITICAL 9.1EPSS 0.51% | 18 August 2026 |
| CVE-2026-73380 | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | CRITICAL 9.8EPSS 0.53% | 18 August 2026 |
| CVE-2026-73376 | Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. | CRITICAL 9.8EPSS 0.39% | 18 August 2026 |
| CVE-2026-73366 | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. | CRITICAL 9.8EPSS 0.53% | 18 August 2026 |
| CVE-2026-73365 | Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | CRITICAL 9.3EPSS 0.38% | 18 August 2026 |
| CVE-2026-73355 | Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. | CRITICAL 9.3EPSS 0.38% | 18 August 2026 |
| CVE-2026-73343 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | CRITICAL 10.0EPSS 0.80% | 18 August 2026 |
| CVE-2026-73341 | Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. | CRITICAL 9.8EPSS 0.39% | 18 August 2026 |
| CVE-2026-73339 | Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | CRITICAL 9.3EPSS 0.38% | 18 August 2026 |
| CVE-2026-73187 | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | CRITICAL 9.3EPSS 0.38% | 18 August 2026 |
| CVE-2026-66627 | Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. | CRITICAL 9.9EPSS 0.45% | 18 August 2026 |
| CVE-2026-59940 | Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side… | CRITICAL 9.8EPSS 0.61% | 18 August 2026 |
| CVE-2026-32474 | Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | CRITICAL 9.9EPSS 0.45% | 18 August 2026 |
| CVE-2026-32470 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | CRITICAL 9.8EPSS 0.38% | 18 August 2026 |
| CVE-2026-32463 | Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. | CRITICAL 9.9EPSS 0.27% | 18 August 2026 |
| CVE-2026-32444 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | CRITICAL 9.9EPSS 0.44% | 18 August 2026 |
| CVE-2026-28192 | Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | CRITICAL 9.6EPSS 0.23% | 18 August 2026 |
| CVE-2026-75874 | Sandbox escape in the Remote Settings Client component. | CRITICAL 10.0EPSS 0.46% | 18 August 2026 |
| CVE-2026-74990 | Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. | CRITICAL 9.8EPSS 0.53% | 18 August 2026 |
| CVE-2026-74989 | Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. | CRITICAL 9.8EPSS 0.33% | 18 August 2026 |
| CVE-2026-74988 | Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. | CRITICAL 9.8EPSS 0.35% | 18 August 2026 |
| CVE-2026-74987 | Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. | CRITICAL 9.8EPSS 0.52% | 18 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.