Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 42 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-71472 | This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. | CRITICAL 9.1EPSS 0.56% | 17 August 2026 |
| CVE-2026-68004 | An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp,… | CRITICAL 9.8EPSS 0.72% | 17 August 2026 |
| CVE-2026-67678 | File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code | CRITICAL 9.8EPSS 0.59% | 17 August 2026 |
| CVE-2026-19478 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or… | CRITICAL 9.1EPSS 5.81% | 17 August 2026 |
| CVE-2026-66792 | This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. | CRITICAL 9.9EPSS 0.43% | 17 August 2026 |
| CVE-2026-50775 | A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly. | CRITICAL 9.8EPSS 0.58% | 17 August 2026 |
| CVE-2026-50774 | An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role. | CRITICAL 9.8EPSS 0.42% | 17 August 2026 |
| CVE-2026-74254 | Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. | CRITICAL 9.3EPSS 0.28% | 17 August 2026 |
| CVE-2026-74253 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining… | CRITICAL 10.0EPSS 0.32% | 17 August 2026 |
| CVE-2026-51346 | SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions. | CRITICAL 9.1EPSS 0.52% | 17 August 2026 |
| CVE-2026-50772 | An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function. | CRITICAL 9.8EPSS 0.52% | 17 August 2026 |
| CVE-2026-50770 | An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request. | CRITICAL 9.8EPSS 0.34% | 17 August 2026 |
| CVE-2026-50769 | The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. | CRITICAL 9.8EPSS 0.42% | 17 August 2026 |
| CVE-2026-75045 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature | CRITICAL 9.1EPSS 0.30% | 17 August 2026 |
| CVE-2026-71479 | Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in common/quota_math.go and related settlement… | CRITICAL 9.1EPSS 0.52% | 17 August 2026 |
| CVE-2026-64859 | Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omit("password"), allowing an authenticated administrator to… | CRITICAL 9.1EPSS 0.46% | 17 August 2026 |
| CVE-2026-55674 | Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Discourse page. | CRITICAL 9.3EPSS 0.38% | 17 August 2026 |
| CVE-2026-71566 | This allows any user of the cluster to control VMs of the user that created fakefish, power them on and off, and mount arbitrary CD images to them. | CRITICAL 9.3EPSS 0.21% | 17 August 2026 |
| CVE-2026-75003 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. | CRITICAL 9.8EPSS 0.39% | 17 August 2026 |
| CVE-2026-14564 | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. | CRITICAL 9.0EPSS 0.24% | 17 August 2026 |
| CVE-2026-74843 | A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. | CRITICAL 9.3EPSS 0.58% | 17 August 2026 |
| CVE-2026-74901 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. | CRITICAL 9.3EPSS 0.23% | 17 August 2026 |
| CVE-2026-74900 | openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly… | CRITICAL 9.3EPSS 0.34% | 17 August 2026 |
| CVE-2026-74899 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. | CRITICAL 9.3EPSS 0.49% | 17 August 2026 |
| CVE-2026-74896 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. | CRITICAL 9.3EPSS 0.34% | 17 August 2026 |
| CVE-2026-74895 | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. | CRITICAL 9.3EPSS 0.41% | 17 August 2026 |
| CVE-2026-74894 | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. | CRITICAL 9.3EPSS 0.37% | 17 August 2026 |
| CVE-2026-74890 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. | CRITICAL 9.3EPSS 0.15% | 17 August 2026 |
| CVE-2026-74889 | Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks. | CRITICAL 9.3EPSS 0.20% | 17 August 2026 |
| CVE-2026-74886 | openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. | CRITICAL 9.3EPSS 0.38% | 17 August 2026 |
| CVE-2026-74885 | openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. | CRITICAL 9.3EPSS 0.12% | 17 August 2026 |
| CVE-2026-74880 | Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access. | CRITICAL 9.3EPSS 0.31% | 17 August 2026 |
| CVE-2026-74878 | Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections. | CRITICAL 9.3EPSS 0.40% | 17 August 2026 |
| CVE-2026-74876 | openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. | CRITICAL 9.3EPSS 0.20% | 17 August 2026 |
| CVE-2026-74875 | openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. | CRITICAL 9.3EPSS 0.18% | 17 August 2026 |
| CVE-2026-74872 | openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. | CRITICAL 9.3EPSS 0.46% | 17 August 2026 |
| CVE-2026-74800 | SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. | CRITICAL 9.4EPSS 0.29% | 17 August 2026 |
| CVE-2026-74799 | Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys. | CRITICAL 9.2EPSS 0.39% | 17 August 2026 |
| CVE-2026-74798 | SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. | CRITICAL 9.3EPSS 0.37% | 17 August 2026 |
| CVE-2026-15623 | A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request… | CRITICAL 9.4EPSS 0.22% | 17 August 2026 |
| CVE-2026-19977 | A vulnerability was detected in EFM ipTIME A3004T 14.19.0. | CRITICAL 9.3EPSS 0.73% | 17 August 2026 |
| CVE-2026-74791 | Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. | CRITICAL 9.2EPSS 0.27% | 16 August 2026 |
| CVE-2026-74790 | Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. | CRITICAL 9.3EPSS 0.29% | 16 August 2026 |
| CVE-2026-73061 | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. | CRITICAL 9.3EPSS 0.30% | 16 August 2026 |
| CVE-2026-73056 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. | CRITICAL 9.3EPSS 0.45% | 16 August 2026 |
| CVE-2026-72887 | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. | CRITICAL 9.8EPSS 0.55% | 16 August 2026 |
| CVE-2026-19349 | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. | CRITICAL 9.8EPSS 0.46% | 16 August 2026 |
| CVE-2026-74251 | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE… | CRITICAL 9.3EPSS 0.37% | 16 August 2026 |
| CVE-2024-13784 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. | CRITICAL 9.8EPSS 0.52% | 16 August 2026 |
| CVE-2026-19725 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log… | CRITICAL 9.1EPSS 0.37% | 16 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.