Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,247 results · page 62 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-14900 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. | CRITICAL 9.8EPSS 0.69% | 29 July 2026 |
| CVE-2026-14488 | The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. | CRITICAL 9.1EPSS 0.31% | 29 July 2026 |
| CVE-2026-59243 | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an… | CRITICAL 9.8EPSS 0.45% | 29 July 2026 |
| CVE-2026-58179 | The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. | CRITICAL 9.2EPSS 0.37% | 29 July 2026 |
| CVE-2026-58161 | Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. | CRITICAL 9.2EPSS 0.44% | 29 July 2026 |
| CVE-2025-10656 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. | CRITICAL 9.8EPSS 0.36% | 29 July 2026 |
| CVE-2026-58155 | Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. | CRITICAL 9.2EPSS 0.40% | 29 July 2026 |
| CVE-2026-58154 | Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. | CRITICAL 9.2EPSS 0.40% | 29 July 2026 |
| CVE-2026-18191 | VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device. | CRITICAL 9.3EPSS 0.38% | 29 July 2026 |
| CVE-2026-63234 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location,… | CRITICAL 9.9EPSS 0.29% | 29 July 2026 |
| CVE-2026-63233 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location,… | CRITICAL 9.9EPSS 0.29% | 29 July 2026 |
| CVE-2026-63232 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location,… | CRITICAL 9.9EPSS 0.29% | 29 July 2026 |
| CVE-2026-63230 | A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account… | CRITICAL 9.1EPSS 0.30% | 29 July 2026 |
| CVE-2026-63229 | A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information,… | CRITICAL 9.1EPSS 0.30% | 29 July 2026 |
| CVE-2026-63227 | An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server. | CRITICAL 9.9EPSS 0.33% | 29 July 2026 |
| CVE-2026-13423 | The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing… | CRITICAL 9.8EPSS 0.54% | 29 July 2026 |
| CVE-2026-18072 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. | CRITICAL 9.8EPSS 3.23% | 29 July 2026 |
| CVE-2026-64863 | Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. | CRITICAL 9.1EPSS 0.36% | 28 July 2026 |
| CVE-2026-62325 | From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. | CRITICAL 9.1EPSS 0.34% | 28 July 2026 |
| CVE-2026-54658 | Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and… | CRITICAL 9.8EPSS 0.46% | 28 July 2026 |
| CVE-2026-6881 | A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. | CRITICAL 9.4EPSS 0.20% | 28 July 2026 |
| CVE-2026-14976 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled. | CRITICAL 9.8EPSS 0.30% | 28 July 2026 |
| CVE-2026-14974 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. | CRITICAL 9.8EPSS 0.38% | 28 July 2026 |
| CVE-2026-14973 | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. | CRITICAL 9.3EPSS 0.30% | 28 July 2026 |
| CVE-2026-14512 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code. | CRITICAL 9.8EPSS 0.57% | 28 July 2026 |
| CVE-2026-14446 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. | CRITICAL 9.8EPSS 0.33% | 28 July 2026 |
| CVE-2026-16184 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. | CRITICAL 9.8EPSS 0.32% | 28 July 2026 |
| CVE-2026-50737 | When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. | CRITICAL 9.0EPSS 0.24% | 28 July 2026 |
| CVE-2026-50736 | The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL… | CRITICAL 9.0EPSS 0.24% | 28 July 2026 |
| CVE-2026-16498 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. | CRITICAL 10.0EPSS 0.46% | 28 July 2026 |
| CVE-2026-67174 | Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities. | CRITICAL 9.2EPSS 0.39% | 28 July 2026 |
| CVE-2026-66713 | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) allows an… | CRITICAL 9.8EPSS 1.03% | 28 July 2026 |
| CVE-2026-65880 | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type. | CRITICAL 10.0EPSS 0.46% | 28 July 2026 |
| CVE-2026-16462 | This allows a remote unauthenticated attacker to execute arbitrary SQL commands. | CRITICAL 9.3EPSS 0.48% | 28 July 2026 |
| CVE-2026-11841 | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. | CRITICAL 9.4EPSS 0.49% | 28 July 2026 |
| CVE-2026-15014 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. | CRITICAL 9.8EPSS 0.46% | 28 July 2026 |
| CVE-2026-11756 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution. | CRITICAL 10.0EPSS 0.45% | 28 July 2026 |
| CVE-2026-14545 | The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an… | CRITICAL 9.8EPSS 0.29% | 28 July 2026 |
| CVE-2021-32088 | This protection can be bypassed by removing the kboxid cookie. | CRITICAL 9.8EPSS 0.29% | 27 July 2026 |
| CVE-2021-32086 | It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. | CRITICAL 9.8EPSS 0.19% | 27 July 2026 |
| CVE-2021-32084 | If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE. | CRITICAL 9.8EPSS 0.33% | 27 July 2026 |
| CVE-2026-66824 | A stored cross-site scripting vulnerability existed in the capture tree visualization page. | CRITICAL 9.2EPSS 0.28% | 27 July 2026 |
| CVE-2026-64775 | A memory initialization issue was addressed with improved memory handling. | CRITICAL 9.8EPSS 0.56% | 27 July 2026 |
| CVE-2026-64774 | An integer overflow was addressed with improved input validation. | CRITICAL 9.8EPSS 0.65% | 27 July 2026 |
| CVE-2026-64772 | An out-of-bounds write issue was addressed with improved input validation. | CRITICAL 9.8EPSS 0.63% | 27 July 2026 |
| CVE-2026-64771 | A buffer overflow was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.70% | 27 July 2026 |
| CVE-2026-64770 | An out-of-bounds write issue was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.65% | 27 July 2026 |
| CVE-2026-64769 | An out-of-bounds write issue was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.65% | 27 July 2026 |
| CVE-2026-64767 | A buffer overflow was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.68% | 27 July 2026 |
| CVE-2026-64762 | An out-of-bounds read was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.53% | 27 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.