Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 52 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-72590 | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /crontab with URL-encoded newlines in the env_vars parameter. | CRITICAL 9.8EPSS 1.28% | 10 August 2026 |
| CVE-2026-72589 | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a crafted crontab database file. | CRITICAL 9.8EPSS 1.22% | 10 August 2026 |
| CVE-2026-72580 | An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on Xiaomi smart speakers running the patch. | CRITICAL 9.8EPSS 0.93% | 10 August 2026 |
| CVE-2026-72577 | Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. | CRITICAL 9.8EPSS 0.85% | 10 August 2026 |
| CVE-2026-72575 | An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, create, update, and delete usergroup records. | CRITICAL 9.1EPSS 0.38% | 10 August 2026 |
| CVE-2026-72569 | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option. | CRITICAL 9.1EPSS 0.51% | 10 August 2026 |
| CVE-2026-72567 | An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. | CRITICAL 9.8EPSS 0.55% | 10 August 2026 |
| CVE-2026-72565 | A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator. | CRITICAL 9.8EPSS 0.47% | 10 August 2026 |
| CVE-2026-72564 | An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource. | CRITICAL 9.6EPSS 0.31% | 10 August 2026 |
| CVE-2026-55799 | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | CRITICAL 9.8EPSS 0.65% | 10 August 2026 |
| CVE-2026-44416 | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. | CRITICAL 9.8EPSS 0.66% | 10 August 2026 |
| CVE-2026-42537 | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | CRITICAL 9.8EPSS 0.69% | 10 August 2026 |
| CVE-2026-40920 | Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. | CRITICAL 9.8EPSS 0.39% | 10 August 2026 |
| CVE-2026-32227 | SQL Injection vulnerability vulnerability in Apache Ranger. | CRITICAL 9.8EPSS 0.36% | 10 August 2026 |
| CVE-2026-28672 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. | CRITICAL 9.8EPSS 1.31% | 10 August 2026 |
| CVE-2026-66915 | Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin. | CRITICAL 10.0EPSS 0.61% | 10 August 2026 |
| CVE-2026-19089 | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers… | CRITICAL 9.8EPSS 0.46% | 10 August 2026 |
| CVE-2026-19053 | The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection. | CRITICAL 9.1EPSS 0.23% | 10 August 2026 |
| CVE-2026-16299 | The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. | CRITICAL 9.8EPSS 0.34% | 10 August 2026 |
| CVE-2026-16298 | The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. | CRITICAL 9.8EPSS 0.34% | 10 August 2026 |
| CVE-2026-18473 | The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | CRITICAL 9.1EPSS 0.28% | 9 August 2026 |
| CVE-2026-15038 | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind… | CRITICAL 9.8EPSS 0.59% | 9 August 2026 |
| CVE-2026-71993 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71992 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71991 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71990 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71989 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71988 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71987 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71986 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71985 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71984 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. | CRITICAL 9.3EPSS 1.35% | 9 August 2026 |
| CVE-2026-71983 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. | CRITICAL 9.3EPSS 1.62% | 8 August 2026 |
| CVE-2026-71958 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. | CRITICAL 9.3EPSS 0.56% | 8 August 2026 |
| CVE-2026-71957 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. | CRITICAL 9.3EPSS 0.59% | 8 August 2026 |
| CVE-2026-71956 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. | CRITICAL 9.3EPSS 1.70% | 8 August 2026 |
| CVE-2026-71955 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-71954 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-71953 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. | CRITICAL 9.3EPSS 2.04% | 8 August 2026 |
| CVE-2026-71952 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. | CRITICAL 9.3EPSS 2.04% | 8 August 2026 |
| CVE-2026-71951 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-71950 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-71949 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-71948 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-71947 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-71946 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-71945 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-71944 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. | CRITICAL 9.3EPSS 2.08% | 8 August 2026 |
| CVE-2026-68082 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cls_lock_client.c contains two bare decode operations that allow a malicious or compromised OSD to trigger… | CRITICAL 9.8EPSS 0.40% | 8 August 2026 |
| CVE-2026-14526 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. | CRITICAL 9.8EPSS 0.67% | 8 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.