Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 59 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-16503 | Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration. | CRITICAL 9.1EPSS 0.32% | 31 July 2026 |
| CVE-2026-17561 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. | CRITICAL 9.8EPSS 0.31% | 31 July 2026 |
| CVE-2025-67649 | A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . | CRITICAL 9.3EPSS 0.27% | 31 July 2026 |
| CVE-2026-18452 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. | CRITICAL 10.0EPSS 0.43% | 31 July 2026 |
| CVE-2026-14919 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect… | CRITICAL 9.8EPSS 0.28% | 31 July 2026 |
| CVE-2026-14483 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. | CRITICAL 9.8EPSS 3.64% | 31 July 2026 |
| CVE-2026-63223 | Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads… | CRITICAL 9.8EPSS 0.76% | 31 July 2026 |
| CVE-2026-63221 | From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. | CRITICAL 9.4EPSS 0.37% | 31 July 2026 |
| CVE-2026-43830 | Full details and mitigation steps are currently restricted and will be published at a later date. | CRITICAL 9.8EPSS 0.33% | 31 July 2026 |
| CVE-2026-38709 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. | CRITICAL 9.8EPSS 2.67% | 30 July 2026 |
| CVE-2026-68503 | Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to… | CRITICAL 9.8EPSS 0.50% | 30 July 2026 |
| CVE-2026-68502 | Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and subprocess.call(command, shell=True), allowing unauthenticated… | CRITICAL 9.8EPSS 0.70% | 30 July 2026 |
| CVE-2026-66803 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | CRITICAL 10.0EPSS 0.55% | 30 July 2026 |
| CVE-2026-66418 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded… | CRITICAL 9.3EPSS 0.51% | 30 July 2026 |
| CVE-2026-52539 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. | CRITICAL 9.1EPSS 0.30% | 30 July 2026 |
| CVE-2026-35847 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file | CRITICAL 9.8EPSS 0.37% | 30 July 2026 |
| CVE-2025-69947 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-69941 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-69938 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-69937 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-69936 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-69935 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-69934 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-69933 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-69931 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-69930 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2025-65336 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. | CRITICAL 9.8EPSS 0.32% | 30 July 2026 |
| CVE-2026-67594 | Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in… | CRITICAL 9.3EPSS 0.48% | 30 July 2026 |
| CVE-2026-67208 | Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. | CRITICAL 9.3EPSS 5.29% | 30 July 2026 |
| CVE-2026-12946 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. | CRITICAL 9.9EPSS 0.35% | 30 July 2026 |
| CVE-2026-66066 | In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. | CRITICAL 9.5EPSS 27.9% | 30 July 2026 |
| CVE-2026-48499 | Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach read-write cached flow and code files belonging to other tenants on the same worker, exposing embedded data and allowing modified code to… | CRITICAL 9.3EPSS 0.24% | 30 July 2026 |
| CVE-2026-15976 | SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files. | CRITICAL 9.8EPSS 0.49% | 30 July 2026 |
| CVE-2026-15971 | SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests. | CRITICAL 9.8EPSS 0.57% | 30 July 2026 |
| CVE-2026-15969 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads. | CRITICAL 9.8EPSS 1.38% | 30 July 2026 |
| CVE-2026-13435 | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. | CRITICAL 9.9EPSS 0.29% | 30 July 2026 |
| CVE-2026-12943 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the… | CRITICAL 9.8EPSS 1.01% | 30 July 2026 |
| CVE-2026-12118 | IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | CRITICAL 9.8EPSS 0.57% | 30 July 2026 |
| CVE-2026-12940 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. | CRITICAL 9.8EPSS 0.68% | 30 July 2026 |
| CVE-2026-52680 | A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. | CRITICAL 9.8EPSS 0.83% | 30 July 2026 |
| CVE-2026-4978 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. | CRITICAL 9.8EPSS 0.26% | 30 July 2026 |
| CVE-2026-28812 | UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. | CRITICAL 9.8EPSS 0.40% | 30 July 2026 |
| CVE-2026-28323 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. | CRITICAL 9.8EPSS 0.68% | 30 July 2026 |
| CVE-2026-53431 | Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after the assertion has expired. | CRITICAL 9.1EPSS 0.41% | 30 July 2026 |
| CVE-2026-15435 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. | CRITICAL 9.8EPSS 0.50% | 30 July 2026 |
| CVE-2026-14522 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters. | CRITICAL 9.8EPSS 0.90% | 30 July 2026 |
| CVE-2026-11707 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | CRITICAL 9.3EPSS 0.22% | 30 July 2026 |
| CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability | KEVCRITICAL 9.8EPSS 50.4% | 30 July 2026 |
| CVE-2026-59309 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. | CRITICAL 9.8EPSS 7.94% | 30 July 2026 |
| CVE-2026-54363 | CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and… | CRITICAL 9.3EPSS 0.39% | 30 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.