Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 46 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-15341 | The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. | CRITICAL 9.8EPSS 0.33% | 15 August 2026 |
| CVE-2026-15303 | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. | CRITICAL 9.8EPSS 0.44% | 15 August 2026 |
| CVE-2026-14484 | The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. | CRITICAL 9.1EPSS 0.76% | 15 August 2026 |
| CVE-2026-73683 | Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within… | CRITICAL 9.2EPSS 0.44% | 14 August 2026 |
| CVE-2026-67365 | Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account. | CRITICAL 9.2EPSS 0.23% | 14 August 2026 |
| CVE-2026-17186 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command. | CRITICAL 9.8EPSS 0.32% | 14 August 2026 |
| CVE-2026-17184 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path. | CRITICAL 9.8EPSS 0.51% | 14 August 2026 |
| CVE-2026-17182 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments. | CRITICAL 9.8EPSS 0.44% | 14 August 2026 |
| CVE-2026-73678 | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST… | CRITICAL 10.0EPSS 1.14% | 14 August 2026 |
| CVE-2026-50027 | An unauthenticated remote attacker can upload arbitrary content into the memory store (write), retrieve stored document content (read), and permanently delete memories belonging to authenticated users (delete) — all without supplying any credentials. | CRITICAL 9.8EPSS 0.50% | 14 August 2026 |
| CVE-2026-49457 | erlang_quic is a pure Erlang QUIC implementation. | CRITICAL 9.1EPSS 0.15% | 14 August 2026 |
| CVE-2026-19188 | A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. | CRITICAL 10.0EPSS 1.93% | 14 August 2026 |
| CVE-2026-73849 | A remote attacker can submit hostname, dbuser, dbpasswd, dbname, dbprefix, username, password, and email values to cause file_put_contents('config.php', $config) to overwrite the configuration with attacker-controlled database settings and create a new… | CRITICAL 9.8EPSS 0.59% | 14 August 2026 |
| CVE-2026-48528 | Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input that can be passed through to the backend SQL database. | CRITICAL 9.8EPSS 0.40% | 14 August 2026 |
| CVE-2026-19682 | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account. | CRITICAL 9.4EPSS 2.84% | 14 August 2026 |
| CVE-2026-19681 | An authenticated command injection vulnerability exists in Security Center related to file upload processing. | CRITICAL 9.4EPSS 7.80% | 14 August 2026 |
| CVE-2026-19626 | A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. | CRITICAL 9.4EPSS 1.44% | 14 August 2026 |
| CVE-2026-19871 | Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address,… | CRITICAL 9.3EPSS 0.39% | 14 August 2026 |
| CVE-2026-72836 | FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. | CRITICAL 9.2EPSS 0.41% | 14 August 2026 |
| CVE-2026-72811 | SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL… | CRITICAL 9.9EPSS 0.25% | 14 August 2026 |
| CVE-2026-72810 | SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. | CRITICAL 9.2EPSS 0.31% | 14 August 2026 |
| CVE-2026-12949 | The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. | CRITICAL 9.8EPSS 0.34% | 14 August 2026 |
| CVE-2026-73843 | Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations,… | CRITICAL 9.6EPSS 0.29% | 13 August 2026 |
| CVE-2026-73842 | Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant… | CRITICAL 9.0EPSS 0.18% | 13 August 2026 |
| CVE-2026-73665 | An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth in node/lib/auth.js and send crafted event values containing carriage-return or newline characters through the Asterisk Manager Interface action path… | CRITICAL 9.3EPSS 0.29% | 13 August 2026 |
| CVE-2026-73663 | An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. | CRITICAL 9.3EPSS 0.95% | 13 August 2026 |
| CVE-2026-73421 | A provider missing both the issuer and authorization endpoint triggers InvalidEndpoints, and an unset AUTH_SECRET or another server configuration error can produce the same behavior. | CRITICAL 9.1EPSS 0.46% | 13 August 2026 |
| CVE-2026-73420 | The address passes the normalizer's single-at-sign check, but a downstream sendVerificationRequest mail library or delivery service that normalizes the address can then see two at-sign separators and deliver the passwordless sign-in link to an… | CRITICAL 9.1EPSS 0.53% | 13 August 2026 |
| CVE-2026-73302 | An attacker who can authenticate through a configured identity provider that asserts a victim email as unverified can have a fresh provider identity merged into the victim Budibase account and inherit the victim roles. | CRITICAL 9.0EPSS 0.40% | 13 August 2026 |
| CVE-2026-72851 | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. | CRITICAL 9.0EPSS 0.29% | 13 August 2026 |
| CVE-2026-72850 | Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. | CRITICAL 9.4EPSS 0.42% | 13 August 2026 |
| CVE-2026-72842 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. | CRITICAL 9.4EPSS 0.42% | 13 August 2026 |
| CVE-2026-72841 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. | CRITICAL 9.4EPSS 0.53% | 13 August 2026 |
| CVE-2026-72839 | Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files. | CRITICAL 9.3EPSS 0.51% | 13 August 2026 |
| CVE-2026-72776 | AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to… | CRITICAL 9.3EPSS 0.84% | 13 August 2026 |
| CVE-2026-8715 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the… | CRITICAL 9.6EPSS 0.34% | 13 August 2026 |
| CVE-2026-19297 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. | CRITICAL 9.1EPSS 0.42% | 13 August 2026 |
| CVE-2026-18249 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses. | CRITICAL 9.9EPSS 0.28% | 13 August 2026 |
| CVE-2026-18193 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses. | CRITICAL 10.0EPSS 0.33% | 13 August 2026 |
| CVE-2026-17482 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths. | CRITICAL 9.8EPSS 0.61% | 13 August 2026 |
| CVE-2026-17481 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs. | CRITICAL 9.8EPSS 0.57% | 13 August 2026 |
| CVE-2026-17101 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication. | CRITICAL 9.6EPSS 0.41% | 13 August 2026 |
| CVE-2026-73656 | A caller with a valid API key for one project can submit another project's deployment identifier, link an attacker-owned background worker to the victim deployment, and move the victim deployment from BUILDING to DEPLOYING. | CRITICAL 9.9EPSS 0.34% | 13 August 2026 |
| CVE-2026-72676 | Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). | CRITICAL 9.1EPSS 0.39% | 13 August 2026 |
| CVE-2026-17206 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | CRITICAL 9.8EPSS 0.39% | 13 August 2026 |
| CVE-2026-16961 | IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. | CRITICAL 9.8EPSS 0.31% | 13 August 2026 |
| CVE-2026-16867 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation. | CRITICAL 9.8EPSS 0.41% | 13 August 2026 |
| CVE-2026-16815 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow. | CRITICAL 9.1EPSS 0.27% | 13 August 2026 |
| CVE-2026-14525 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. | CRITICAL 9.4EPSS 0.31% | 13 August 2026 |
| CVE-2026-73653 | Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite… | CRITICAL 9.4EPSS 0.64% | 13 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.