Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 48 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-59506 | : Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). | CRITICAL 9.3EPSS 0.29% | 13 August 2026 |
| CVE-2026-59504 | : Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). | CRITICAL 9.1EPSS 0.30% | 13 August 2026 |
| CVE-2026-59503 | : Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). | CRITICAL 9.1EPSS 0.30% | 13 August 2026 |
| CVE-2026-59500 | : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). | CRITICAL 10.0EPSS 0.30% | 13 August 2026 |
| CVE-2026-15413 | Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check). | CRITICAL 10.0EPSS 0.29% | 13 August 2026 |
| CVE-2026-14182 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing… | CRITICAL 9.8EPSS 0.30% | 13 August 2026 |
| CVE-2026-49819 | Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. | CRITICAL 9.8EPSS 0.79% | 13 August 2026 |
| CVE-2026-16770 | PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. | CRITICAL 9.8EPSS 0.43% | 13 August 2026 |
| CVE-2026-71193 | An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. | CRITICAL 9.6EPSS 0.37% | 12 August 2026 |
| CVE-2026-49481 | Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. | CRITICAL 9.6EPSS 0.88% | 12 August 2026 |
| CVE-2026-73519 | WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the… | CRITICAL 9.3EPSS 0.79% | 12 August 2026 |
| CVE-2026-73501 | The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. | CRITICAL 9.1EPSS 0.43% | 12 August 2026 |
| CVE-2026-71471 | An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. | CRITICAL 9.0EPSS 1.02% | 12 August 2026 |
| CVE-2026-18749 | A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released coordinator material to vendors on the case. | CRITICAL 9.8EPSS 0.35% | 12 August 2026 |
| CVE-2026-10534 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser. | CRITICAL 9.8EPSS 0.22% | 12 August 2026 |
| CVE-2024-27253 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. | CRITICAL 10.0EPSS 0.32% | 12 August 2026 |
| CVE-2026-66898 | A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. | CRITICAL 9.9EPSS 0.43% | 12 August 2026 |
| CVE-2026-19001 | This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution. | CRITICAL 9.5EPSS 0.40% | 12 August 2026 |
| CVE-2026-17616 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic… | CRITICAL 9.8EPSS 0.27% | 12 August 2026 |
| CVE-2026-13433 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. | CRITICAL 9.6EPSS 0.11% | 12 August 2026 |
| CVE-2026-10543 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query. | CRITICAL 9.8EPSS 0.27% | 12 August 2026 |
| CVE-2026-73414 | An attacker-controlled argument can break out of a parenthesized CMD construct and inject shell syntax depending on the original command, resulting in arbitrary command execution. | CRITICAL 9.2EPSS 0.52% | 12 August 2026 |
| CVE-2026-73407 | An unauthenticated caller of a PUBLIC POST /api/v2/queries/:queryId query could supply an absolute or parameterized path to an attacker-controlled host and receive the stored bearer, basic, or static-header credentials. | CRITICAL 9.0EPSS 0.52% | 12 August 2026 |
| CVE-2026-73332 | CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact… | CRITICAL 9.2EPSS 0.23% | 12 August 2026 |
| CVE-2026-73329 | CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during… | CRITICAL 9.2EPSS 0.23% | 12 August 2026 |
| CVE-2026-73269 | This allows the user to escalate their privileges from namespace-local access to cluster-wide control. | CRITICAL 9.9EPSS 0.33% | 12 August 2026 |
| CVE-2026-73268 | A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. | CRITICAL 9.9EPSS 0.47% | 12 August 2026 |
| CVE-2026-72804 | SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. | CRITICAL 9.2EPSS 0.26% | 12 August 2026 |
| CVE-2026-72798 | SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. | CRITICAL 9.2EPSS 0.26% | 12 August 2026 |
| CVE-2026-72795 | Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization. | CRITICAL 9.2EPSS 0.24% | 12 August 2026 |
| CVE-2026-72794 | siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. | CRITICAL 9.2EPSS 0.25% | 12 August 2026 |
| CVE-2026-72793 | SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key… | CRITICAL 9.2EPSS 0.24% | 12 August 2026 |
| CVE-2026-72789 | SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. | CRITICAL 9.2EPSS 0.29% | 12 August 2026 |
| CVE-2026-72508 | This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). | CRITICAL 9.9EPSS 0.48% | 12 August 2026 |
| CVE-2026-63300 | An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. | CRITICAL 9.9EPSS 0.36% | 12 August 2026 |
| CVE-2026-63299 | An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. | CRITICAL 9.9EPSS 0.40% | 12 August 2026 |
| CVE-2026-63298 | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. | CRITICAL 9.9EPSS 0.47% | 12 August 2026 |
| CVE-2026-63297 | An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. | CRITICAL 9.9EPSS 0.24% | 12 August 2026 |
| CVE-2026-63296 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. | CRITICAL 9.9EPSS 0.30% | 12 August 2026 |
| CVE-2026-63294 | A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. | CRITICAL 9.9EPSS 1.21% | 12 August 2026 |
| CVE-2026-63293 | A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. | CRITICAL 9.9EPSS 0.48% | 12 August 2026 |
| CVE-2026-62420 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. | CRITICAL 9.9EPSS 0.37% | 12 August 2026 |
| CVE-2026-19656 | ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. | CRITICAL 9.9EPSS 0.29% | 12 August 2026 |
| CVE-2026-17111 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. | CRITICAL 9.8EPSS 0.25% | 12 August 2026 |
| CVE-2026-17083 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. | CRITICAL 9.8EPSS 0.46% | 12 August 2026 |
| CVE-2026-73300 | Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. | CRITICAL 9.6EPSS 0.48% | 12 August 2026 |
| CVE-2026-73299 | An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. | CRITICAL 10.0EPSS 1.21% | 12 August 2026 |
| CVE-2026-17276 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads. | CRITICAL 9.9EPSS 0.26% | 12 August 2026 |
| CVE-2026-17218 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. | CRITICAL 9.8EPSS 0.56% | 12 August 2026 |
| CVE-2026-16956 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | CRITICAL 9.8EPSS 1.04% | 12 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.