Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 41 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-74986 | This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | CRITICAL 9.1EPSS 0.32% | 18 August 2026 |
| CVE-2026-74985 | Privilege escalation in the Enterprise Policies component. | CRITICAL 9.8EPSS 0.31% | 18 August 2026 |
| CVE-2026-74979 | Mitigation bypass in the Add-ons Manager component. | CRITICAL 9.8EPSS 0.31% | 18 August 2026 |
| CVE-2026-74964 | Integer overflow in the Graphics component. | CRITICAL 9.8EPSS 0.47% | 18 August 2026 |
| CVE-2026-74961 | This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | CRITICAL 9.1EPSS 0.25% | 18 August 2026 |
| CVE-2026-74959 | Mitigation bypass in the Storage: Cache API component. | CRITICAL 9.1EPSS 0.34% | 18 August 2026 |
| CVE-2026-74956 | Same-origin policy bypass in the DOM: Service Workers component. | CRITICAL 9.1EPSS 0.28% | 18 August 2026 |
| CVE-2026-74944 | Use-after-free in the DOM: Core & HTML component. | CRITICAL 9.8EPSS 0.40% | 18 August 2026 |
| CVE-2026-74943 | Use-after-free in the Graphics: ImageLib component. | CRITICAL 9.8EPSS 0.57% | 18 August 2026 |
| CVE-2026-74940 | Use-after-free in the Graphics: Text component. | CRITICAL 9.8EPSS 0.41% | 18 August 2026 |
| CVE-2026-74938 | Mitigation bypass in the JavaScript: GC component. | CRITICAL 9.1EPSS 0.32% | 18 August 2026 |
| CVE-2026-74936 | Use-after-free in the JavaScript: WebAssembly component. | CRITICAL 9.8EPSS 0.40% | 18 August 2026 |
| CVE-2026-75854 | ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. | CRITICAL 9.3EPSS 1.07% | 18 August 2026 |
| CVE-2026-75852 | Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials. | CRITICAL 9.3EPSS 0.45% | 18 August 2026 |
| CVE-2026-75851 | When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext has no bound user, causing the scripting authorization gate to become a no-op. | CRITICAL 9.4EPSS 0.32% | 18 August 2026 |
| CVE-2026-75843 | ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. | CRITICAL 9.4EPSS 0.30% | 18 August 2026 |
| CVE-2026-75837 | A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities. | CRITICAL 9.3EPSS 0.34% | 18 August 2026 |
| CVE-2026-75835 | Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). | CRITICAL 9.3EPSS 0.22% | 18 August 2026 |
| CVE-2026-75832 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). | CRITICAL 9.3EPSS 0.22% | 18 August 2026 |
| CVE-2026-75828 | Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. | CRITICAL 9.3EPSS 0.34% | 18 August 2026 |
| CVE-2026-75827 | Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. | CRITICAL 9.3EPSS 0.78% | 18 August 2026 |
| CVE-2026-74902 | SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. | CRITICAL 9.3EPSS 0.15% | 18 August 2026 |
| CVE-2026-75627 | Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. | CRITICAL 9.3EPSS 0.58% | 18 August 2026 |
| CVE-2026-75626 | Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys. | CRITICAL 9.3EPSS 0.26% | 18 August 2026 |
| CVE-2026-34884 | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. | CRITICAL 9.8EPSS 0.68% | 18 August 2026 |
| CVE-2026-15748 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. | CRITICAL 9.8EPSS 4.61% | 18 August 2026 |
| CVE-2026-67919 | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components | CRITICAL 9.8EPSS 0.83% | 17 August 2026 |
| CVE-2026-42164 | Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section. | CRITICAL 9.8EPSS 0.31% | 17 August 2026 |
| CVE-2026-42162 | Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated. | CRITICAL 9.1EPSS 0.35% | 17 August 2026 |
| CVE-2026-38165 | A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression. | CRITICAL 9.8EPSS 0.60% | 17 August 2026 |
| CVE-2026-71424 | Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info in… | CRITICAL 9.6EPSS 0.29% | 17 August 2026 |
| CVE-2026-67960 | An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components | CRITICAL 9.8EPSS 0.40% | 17 August 2026 |
| CVE-2026-67868 | A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. | CRITICAL 9.8EPSS 0.76% | 17 August 2026 |
| CVE-2026-67854 | SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code | CRITICAL 9.8EPSS 0.40% | 17 August 2026 |
| CVE-2026-64849 | MLflow Server-Side Request Forgery Vulnerability | KEVCRITICAL 9.3EPSS 16.4% | 17 August 2026 |
| CVE-2026-51977 | An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component | CRITICAL 9.1EPSS 0.29% | 17 August 2026 |
| CVE-2026-42163 | Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. | CRITICAL 9.8EPSS 0.33% | 17 August 2026 |
| CVE-2026-75110 | As a result, an unauthenticated remote attacker can reach the admin API-key management endpoints to mint API keys for any user, enumerate keys, revoke keys, and generate a master key for persistent privileged access, as well as all data endpoints. | CRITICAL 9.3EPSS 0.52% | 17 August 2026 |
| CVE-2026-75106 | OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. | CRITICAL 9.3EPSS 0.30% | 17 August 2026 |
| CVE-2026-67967 | Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. | CRITICAL 9.8EPSS 0.55% | 17 August 2026 |
| CVE-2026-67966 | Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access. | CRITICAL 9.8EPSS 0.41% | 17 August 2026 |
| CVE-2026-67965 | An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function | CRITICAL 9.8EPSS 0.59% | 17 August 2026 |
| CVE-2026-67926 | An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module | CRITICAL 9.8EPSS 0.59% | 17 August 2026 |
| CVE-2026-67917 | zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. | CRITICAL 9.8EPSS 0.50% | 17 August 2026 |
| CVE-2026-66795 | The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. | CRITICAL 9.9EPSS 0.32% | 17 August 2026 |
| CVE-2026-65974 | Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code… | CRITICAL 9.9EPSS 0.56% | 17 August 2026 |
| CVE-2026-47698 | Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and… | CRITICAL 9.8EPSS 0.70% | 17 August 2026 |
| CVE-2026-47686 | Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host object such as process… | CRITICAL 9.9EPSS 0.38% | 17 August 2026 |
| CVE-2026-39255 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components | CRITICAL 9.8EPSS 0.56% | 17 August 2026 |
| CVE-2026-39254 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components | CRITICAL 9.8EPSS 0.56% | 17 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.