Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 53 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-46409 | Any webpage a user visits while OpenYak is running can issue cross-origin requests to this local server — the browser acts as a proxy into loopback, bypassing OS-level network isolation. | CRITICAL 9.6EPSS 0.36% | 7 August 2026 |
| CVE-2026-48170 | Any service that calls `scimPatch()` on attacker-controlled JSON (i.e. any SCIM endpoint accepting `PATCH` from an external IdP) is exploitable on a stock Node runtime. | CRITICAL 9.1EPSS 0.31% | 7 August 2026 |
| CVE-2026-47243 | Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root to host-root escape. | CRITICAL 9.2EPSS 0.35% | 7 August 2026 |
| CVE-2026-50540 | Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. | CRITICAL 9.6EPSS 0.40% | 7 August 2026 |
| CVE-2026-61808 | Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge… | CRITICAL 9.8EPSS 1.98% | 7 August 2026 |
| CVE-2026-48039 | Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any… | CRITICAL 9.1EPSS 0.43% | 7 August 2026 |
| CVE-2026-71851 | Downstream wallet applications that used CryptoJS.lib.WordArray.random() as the entropy source for BIP39 recovery phrases are affected, and an attacker who enumerates the reduced output space can recover the resulting private keys and control the… | CRITICAL 9.0EPSS 0.34% | 7 August 2026 |
| CVE-2026-64637 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account. | CRITICAL 9.9EPSS 0.26% | 7 August 2026 |
| CVE-2026-19264 | Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded only once they reach the handler, restoring the traversal at the filesystem call. | CRITICAL 9.3EPSS 0.77% | 7 August 2026 |
| CVE-2022-4995 | Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to… | CRITICAL 9.3EPSS 0.69% | 7 August 2026 |
| CVE-2026-66914 | Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot. | CRITICAL 9.2EPSS 0.38% | 7 August 2026 |
| CVE-2026-56793 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. | CRITICAL 9.8EPSS 0.31% | 7 August 2026 |
| CVE-2026-71560 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. | CRITICAL 9.1EPSS 0.42% | 7 August 2026 |
| CVE-2026-71558 | Heap type confusion vulnerability in Apache Fory C++ deserialization. | CRITICAL 9.8EPSS 0.53% | 7 August 2026 |
| CVE-2026-54213 | Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. | CRITICAL 9.2EPSS 0.57% | 7 August 2026 |
| CVE-2026-54212 | Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. | CRITICAL 9.5EPSS 0.47% | 7 August 2026 |
| CVE-2026-54211 | Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. | CRITICAL 9.5EPSS 0.41% | 7 August 2026 |
| CVE-2026-54210 | Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. | CRITICAL 9.5EPSS 0.47% | 7 August 2026 |
| CVE-2026-54203 | Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. | CRITICAL 9.2EPSS 0.32% | 7 August 2026 |
| CVE-2026-16258 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. | CRITICAL 9.8EPSS 0.47% | 7 August 2026 |
| CVE-2026-16038 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid… | CRITICAL 9.1EPSS 0.24% | 7 August 2026 |
| CVE-2026-14205 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking… | CRITICAL 9.8EPSS 0.27% | 7 August 2026 |
| CVE-2026-14365 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. | CRITICAL 9.8EPSS 0.31% | 7 August 2026 |
| CVE-2026-14364 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. | CRITICAL 9.8EPSS 0.29% | 7 August 2026 |
| CVE-2026-70332 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | CRITICAL 9.6EPSS 0.63% | 7 August 2026 |
| CVE-2026-68823 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | CRITICAL 9.1EPSS 0.60% | 7 August 2026 |
| CVE-2026-65667 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.62% | 7 August 2026 |
| CVE-2026-63508 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.53% | 7 August 2026 |
| CVE-2026-62896 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.6EPSS 0.47% | 7 August 2026 |
| CVE-2026-62873 | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.8EPSS 0.53% | 7 August 2026 |
| CVE-2026-62836 | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.43% | 7 August 2026 |
| CVE-2026-62830 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.52% | 7 August 2026 |
| CVE-2026-59118 | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.3EPSS 0.48% | 7 August 2026 |
| CVE-2026-59115 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.77% | 7 August 2026 |
| CVE-2026-56162 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.66% | 7 August 2026 |
| CVE-2026-56161 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | CRITICAL 9.6EPSS 0.46% | 7 August 2026 |
| CVE-2026-50515 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | CRITICAL 9.9EPSS 1.10% | 7 August 2026 |
| CVE-2026-50481 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.56% | 7 August 2026 |
| CVE-2026-70558 | The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality check against a dinkyToken value whose default (efda1551-7958-4e0f-80a8-dfd107df3e38) is hardcoded in source and shipped to… | CRITICAL 9.3EPSS 0.60% | 6 August 2026 |
| CVE-2026-67689 | SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints | CRITICAL 9.8EPSS 0.69% | 6 August 2026 |
| CVE-2026-67688 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. | CRITICAL 9.8EPSS 0.59% | 6 August 2026 |
| CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | KEVCRITICAL 9.8EPSS 10.5% | 6 August 2026 |
| CVE-2026-5857 | The 65-byte topic[] destination overruns into adjacent struct fields including the payload_chunk pointer, which subsequent MQTT code dereferences, giving a compromised or attacker-controlled broker an arbitrary-pointer-write primitive. | CRITICAL 9.2EPSS 0.54% | 6 August 2026 |
| CVE-2026-53983 | Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outbound… | CRITICAL 9.2EPSS 0.33% | 6 August 2026 |
| CVE-2026-48088 | Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication. | CRITICAL 9.4EPSS 0.33% | 6 August 2026 |
| CVE-2026-48087 | An unauthenticated attacker requests a challenge for their own email, generates a registration response with their own authenticator, and submits it against any victim user's URL. | CRITICAL 9.8EPSS 0.46% | 6 August 2026 |
| CVE-2026-48086 | On the hosted OpenReception service this is a scope-changed escalation: a single customer-side tenant administrator gains full platform-wide administrative control over all other tenants' configuration, users, staff records, operational metadata, and… | CRITICAL 9.9EPSS 0.33% | 6 August 2026 |
| CVE-2026-48085 | Any unauthenticated network attacker who can submit a same-origin form POST gains full platform-level administrative control. | CRITICAL 9.8EPSS 0.55% | 6 August 2026 |
| CVE-2026-43632 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task… | CRITICAL 9.2EPSS 0.33% | 6 August 2026 |
| CVE-2026-43631 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. | CRITICAL 9.2EPSS 0.42% | 6 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.