Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 54 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-43629 | llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the… | CRITICAL 9.2EPSS 0.62% | 6 August 2026 |
| CVE-2026-3418 | The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. | CRITICAL 9.1EPSS 0.57% | 6 August 2026 |
| CVE-2026-19175 | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.36% | 6 August 2026 |
| CVE-2026-19171 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 6 August 2026 |
| CVE-2026-19170 | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.38% | 6 August 2026 |
| CVE-2026-19166 | Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.42% | 6 August 2026 |
| CVE-2026-19164 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.36% | 6 August 2026 |
| CVE-2026-19157 | Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.38% | 6 August 2026 |
| CVE-2026-19149 | Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 6 August 2026 |
| CVE-2026-18367 | A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6. | CRITICAL 9.3EPSS 0.13% | 6 August 2026 |
| CVE-2026-17032 | Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full… | CRITICAL 9.8EPSS 0.37% | 6 August 2026 |
| CVE-2026-15734 | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. | CRITICAL 9.8EPSS 0.68% | 6 August 2026 |
| CVE-2026-15733 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. | CRITICAL 9.8EPSS 13.5% | 6 August 2026 |
| CVE-2026-15732 | A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. | CRITICAL 9.8EPSS 0.38% | 6 August 2026 |
| CVE-2026-14812 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content… | CRITICAL 10.0EPSS 0.57% | 6 August 2026 |
| CVE-2026-11976 | Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. | CRITICAL 10.0EPSS 0.49% | 6 August 2026 |
| CVE-2025-14561 | This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. | CRITICAL 9.0EPSS 0.39% | 6 August 2026 |
| CVE-2026-67261 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. | CRITICAL 9.8EPSS 1.60% | 6 August 2026 |
| CVE-2026-66709 | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | CRITICAL 9.1EPSS 0.47% | 6 August 2026 |
| CVE-2026-66665 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | CRITICAL 10.0EPSS 0.28% | 6 August 2026 |
| CVE-2026-66662 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | CRITICAL 9.8EPSS 0.26% | 6 August 2026 |
| CVE-2026-66447 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | CRITICAL 9.3EPSS 0.23% | 6 August 2026 |
| CVE-2026-65581 | Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65579 | Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65578 | Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65577 | Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65576 | Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65575 | Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65574 | Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65573 | Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65572 | Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65571 | Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65556 | Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | CRITICAL 9.8EPSS 0.30% | 6 August 2026 |
| CVE-2026-65553 | Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | CRITICAL 10.0EPSS 0.46% | 6 August 2026 |
| CVE-2026-65552 | Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | CRITICAL 9.8EPSS 0.41% | 6 August 2026 |
| CVE-2026-65548 | Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. | CRITICAL 9.9EPSS 0.43% | 6 August 2026 |
| CVE-2026-65546 | Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | CRITICAL 9.3EPSS 0.23% | 6 August 2026 |
| CVE-2026-65520 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | CRITICAL 9.3EPSS 0.29% | 6 August 2026 |
| CVE-2026-65508 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | CRITICAL 9.3EPSS 0.28% | 6 August 2026 |
| CVE-2026-65507 | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | CRITICAL 9.8EPSS 0.32% | 6 August 2026 |
| CVE-2026-54489 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. | CRITICAL 9.8EPSS 0.47% | 6 August 2026 |
| CVE-2026-53976 | OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query… | CRITICAL 9.3EPSS 1.90% | 6 August 2026 |
| CVE-2026-53975 | OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js… | CRITICAL 9.3EPSS 1.08% | 6 August 2026 |
| CVE-2026-34191 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. | CRITICAL 9.1EPSS 0.35% | 6 August 2026 |
| CVE-2026-32327 | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. | CRITICAL 9.1EPSS 0.46% | 6 August 2026 |
| CVE-2026-28139 | Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | CRITICAL 9.8EPSS 0.38% | 6 August 2026 |
| CVE-2026-28005 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | CRITICAL 9.8EPSS 0.32% | 6 August 2026 |
| CVE-2026-64993 | Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. | CRITICAL 9.1EPSS 0.14% | 6 August 2026 |
| CVE-2026-5134 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. | CRITICAL 9.8EPSS 0.27% | 6 August 2026 |
| CVE-2026-12605 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse… | CRITICAL 9.6EPSS 0.29% | 6 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.