Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,662 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 43 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-19714 | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an… | CRITICAL 9.1EPSS 0.32% | 16 August 2026 |
| CVE-2026-18316 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. | CRITICAL 9.1EPSS 0.32% | 16 August 2026 |
| CVE-2026-18432 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. | CRITICAL 9.8EPSS 0.51% | 16 August 2026 |
| CVE-2026-16098 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. | CRITICAL 9.8EPSS 0.64% | 16 August 2026 |
| CVE-2026-14524 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. | CRITICAL 9.1EPSS 0.70% | 16 August 2026 |
| CVE-2026-74764 | Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. | CRITICAL 10.0EPSS 0.40% | 15 August 2026 |
| CVE-2026-73053 | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. | CRITICAL 9.4EPSS 0.28% | 15 August 2026 |
| CVE-2026-73052 | Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution. | CRITICAL 9.4EPSS 0.30% | 15 August 2026 |
| CVE-2026-73050 | SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. | CRITICAL 9.4EPSS 0.25% | 15 August 2026 |
| CVE-2026-73046 | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. | CRITICAL 9.3EPSS 0.43% | 15 August 2026 |
| CVE-2026-73044 | SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. | CRITICAL 9.4EPSS 0.25% | 15 August 2026 |
| CVE-2026-73043 | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. | CRITICAL 9.4EPSS 0.37% | 15 August 2026 |
| CVE-2026-73042 | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. | CRITICAL 9.4EPSS 0.30% | 15 August 2026 |
| CVE-2026-73041 | Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF. | CRITICAL 9.4EPSS 0.23% | 15 August 2026 |
| CVE-2026-18855 | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated… | CRITICAL 9.1EPSS 1.21% | 15 August 2026 |
| CVE-2026-19598 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. | CRITICAL 9.8EPSS 2.79% | 15 August 2026 |
| CVE-2026-15689 | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. | CRITICAL 9.8EPSS 0.61% | 15 August 2026 |
| CVE-2026-74573 | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE arm_vsmmu_vsid_to_sid() maps a guest's vSID to a single physical Stream ID taken from master->streams[0], assuming… | CRITICAL 9.3EPSS 0.13% | 15 August 2026 |
| CVE-2026-74570 | In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc size calculations Add a shared helper to safely convert runlist element counts to byte sizes using overflow checks, and use it in both ntfs_rl_realloc() and… | CRITICAL 9.8EPSS 0.31% | 15 August 2026 |
| CVE-2026-74569 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() sip_help_tcp() stores the size change of each NAT-rewritten SIP message in s16 diff and accumulates it in… | CRITICAL 9.8EPSS 0.39% | 15 August 2026 |
| CVE-2026-74568 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race between LPI release and re-registration Fix a potential race between decrementing an LPI's reference count and evicting that structure from the LPI xarray. | CRITICAL 9.3EPSS 0.12% | 15 August 2026 |
| CVE-2026-74556 | In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer iscsi_tcp_hdr_dissect() receives the data segment of several PDU types into the fixed-size conn->data… | CRITICAL 9.8EPSS 0.40% | 15 August 2026 |
| CVE-2026-74545 | In the Linux kernel, the following vulnerability has been resolved: rtase: fix double free of multi-frag skb on DMA map failure In rtase_start_xmit(), when the head buffer DMA mapping fails after rtase_xmit_frags() has mapped all fragments, the error… | CRITICAL 9.8EPSS 0.46% | 15 August 2026 |
| CVE-2026-74521 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use memcmp() to compare ClientGUIDs ClientGUID is a fixed-size binary value and can contain embedded NUL bytes. strncmp() stops comparing at the first NUL byte, so different… | CRITICAL 9.1EPSS 0.32% | 15 August 2026 |
| CVE-2026-74517 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs Cancel (and flush) the I/O APIC's delayed EOI handling work during the "pre VM destroy" phase, before vCPUs are… | CRITICAL 9.3EPSS 0.14% | 15 August 2026 |
| CVE-2026-74495 | In the Linux kernel, the following vulnerability has been resolved: igbvf: Fix leak in TX DMA error cleanup If an error is encountered while mapping TX buffers, the driver should unmap any buffers already mapped for that skb. | CRITICAL 9.8EPSS 0.51% | 15 August 2026 |
| CVE-2026-74493 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-free during link group termination __smc_lgr_terminate() drops conns_lock after finding a connection in lgr->conns_all, but before taking a reference on… | CRITICAL 9.8EPSS 0.50% | 15 August 2026 |
| CVE-2026-74480 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port group br_multicast_leave_group() iterates mp->ports with pp = &p->next in its fast-leave path. | CRITICAL 9.8EPSS 0.56% | 15 August 2026 |
| CVE-2026-74478 | In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-after-free in vector_mmsg_rx() When vector_mmsg_rx() discards a packet whose overlay header fails verify_header(), it frees the skb and continues the loop: if… | CRITICAL 9.8EPSS 0.57% | 15 August 2026 |
| CVE-2026-74476 | In the Linux kernel, the following vulnerability has been resolved: veth: convert frag_list skbs before running XDP A frag_list skb can reach veth with data_len set but nr_frags zero. veth_convert_skb_to_xdp_buff() only converts skbs that are shared,… | CRITICAL 9.1EPSS 0.49% | 15 August 2026 |
| CVE-2026-74475 | In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircuit() The neighbour hardware address n->ha can be updated asynchronously by the neighbour subsystem, protected by n->ha_lock seqlock. | CRITICAL 10.0EPSS 0.45% | 15 August 2026 |
| CVE-2026-74474 | In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmit path header pulls In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was being called to verify the… | CRITICAL 9.8EPSS 0.49% | 15 August 2026 |
| CVE-2026-74473 | In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() in route_shortcircuit() route_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr)) (or ipv6hdr), which checks if bytes are… | CRITICAL 9.8EPSS 0.53% | 15 August 2026 |
| CVE-2026-73194 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. | CRITICAL 9.1EPSS 0.49% | 15 August 2026 |
| CVE-2026-73193 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with `newSV(strlen(statement) * 7 + 16)`, budgeting seven… | CRITICAL 9.8EPSS 0.48% | 15 August 2026 |
| CVE-2026-16142 | The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. | CRITICAL 9.8EPSS 0.38% | 15 August 2026 |
| CVE-2026-15826 | The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. | CRITICAL 9.8EPSS 3.91% | 15 August 2026 |
| CVE-2026-74439 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry device_pasid_table_teardown() zeroes the 128-bit scalable-mode context entry with context_clear_entry()… | CRITICAL 9.3EPSS 0.13% | 15 August 2026 |
| CVE-2026-74436 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept preallocation with socket teardown rxrpc_kernel_charge_accept() reads rx->backlog without any socket/backlog synchronization and passes that raw pointer… | CRITICAL 9.8EPSS 0.40% | 15 August 2026 |
| CVE-2026-74434 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Don't move a peeked OOB message onto the pending queue rxrpc_recvmsg_oob() takes a received oob message off recvmsg_oobq and, if a response is needed, moves it onto the… | CRITICAL 9.8EPSS 0.34% | 15 August 2026 |
| CVE-2026-74433 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix UAF in rxgk_issue_challenge() Fix rxgk_issue_challenge() to free the page containing the challenge content after invoking the tracepoint as the whdr passed to the tracepoint… | CRITICAL 9.8EPSS 0.35% | 15 August 2026 |
| CVE-2026-74428 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix double unlock in rxrpc_recvmsg() Fix a double unlock in rxrpc_recvmsg() when dealing with OOB messages. | CRITICAL 9.8EPSS 0.35% | 15 August 2026 |
| CVE-2026-74427 | In the Linux kernel, the following vulnerability has been resolved: afs: Fix netns teardown to cancel the preallocation charger Fix the teardown of an afs network namespace to make sure it cancels the work item that keeps the preallocated rxrpc… | CRITICAL 9.8EPSS 0.40% | 15 August 2026 |
| CVE-2026-74406 | In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). udp_tunnel_sock_release() could set sk->sk_user_data to NULL while vxlan_gro_prepare_receive() is running. | CRITICAL 9.8EPSS 0.49% | 15 August 2026 |
| CVE-2026-74401 | In the Linux kernel, the following vulnerability has been resolved: dlm: fix add msg handle in send_queue ordered In a benchmark scenario triggering a lot of requests that triggers a lot of DLM messages on the network it can be that the mh->seq is not… | CRITICAL 9.8EPSS 0.44% | 15 August 2026 |
| CVE-2026-74398 | In the Linux kernel, the following vulnerability has been resolved: ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD addrconf_dad_failure() transitions ifp->state from DAD to POSTDAD via addrconf_dad_end(), which drops ifp->lock… | CRITICAL 9.8EPSS 0.51% | 15 August 2026 |
| CVE-2026-74394 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: fix integer overflow in immediate data length check imm_buf->len is a user-controlled uint32_t received from the network. | CRITICAL 9.8EPSS 0.54% | 15 August 2026 |
| CVE-2026-74384 | In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix flex array size in struct nvme_ns_head struct nvme_ns_head contains a flexible array member, current_path[], which is indexed using the NUMA node ID:… | CRITICAL 9.8EPSS 0.51% | 15 August 2026 |
| CVE-2026-74376 | In the Linux kernel, the following vulnerability has been resolved: md/raid10: reset read_slot when reusing r10bio for discard put_all_bios() always drops devs[i].bio, but it only drops devs[i].repl_bio when r10_bio->read_slot < 0. | CRITICAL 9.8EPSS 0.50% | 15 August 2026 |
| CVE-2026-74361 | In the Linux kernel, the following vulnerability has been resolved: nvme: fix FDP fdpcidx bounds check The fdpcidx bounds check sets n = NUMFDPC + 1 but used > instead of >=, incorrectly accepting fdp_idx when it equals n (i.e. | CRITICAL 9.8EPSS 0.44% | 15 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.