Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,247 results · page 64 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-48030 | From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely… | CRITICAL 9.9EPSS 5.85% | 27 July 2026 |
| CVE-2026-45623 | In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. | CRITICAL 9.1EPSS 0.59% | 27 July 2026 |
| CVE-2026-17552 | Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. | CRITICAL 9.1EPSS 0.35% | 27 July 2026 |
| CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | KEVCRITICAL 9.8EPSS 86.5% | 27 July 2026 |
| CVE-2026-66398 | phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files by manipulating the… | CRITICAL 9.4EPSS 0.33% | 27 July 2026 |
| CVE-2026-66396 | SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. | CRITICAL 9.3EPSS 0.37% | 27 July 2026 |
| CVE-2026-66395 | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. | CRITICAL 9.4EPSS 0.40% | 27 July 2026 |
| CVE-2026-66394 | SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. | CRITICAL 9.3EPSS 0.27% | 27 July 2026 |
| CVE-2026-55953 | An on-path attacker between the client and the intended server can respond with a ServerHello selecting an anonymous key exchange suite such as TLS_DH_anon_* or TLS_ECDH_anon_* that the client never offered. | CRITICAL 9.1EPSS 0.23% | 27 July 2026 |
| CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | KEVCRITICAL 10.0EPSS 1.57% | 27 July 2026 |
| CVE-2025-50455 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. | EXPLOITCRITICAL 9.1EPSS 0.95% | 27 July 2026 |
| CVE-2026-59550 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | CRITICAL 9.3EPSS 0.23% | 27 July 2026 |
| CVE-2026-59549 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | CRITICAL 9.3EPSS 0.23% | 27 July 2026 |
| CVE-2026-59538 | Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | CRITICAL 9.3EPSS 0.23% | 27 July 2026 |
| CVE-2026-59533 | Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | CRITICAL 9.3EPSS 0.23% | 27 July 2026 |
| CVE-2026-59527 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | CRITICAL 9.3EPSS 0.23% | 27 July 2026 |
| CVE-2026-65879 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms. | CRITICAL 9.8EPSS 0.28% | 27 July 2026 |
| CVE-2026-65876 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. | CRITICAL 9.2EPSS 0.23% | 27 July 2026 |
| CVE-2026-65766 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector. | CRITICAL 9.2EPSS 0.24% | 27 July 2026 |
| CVE-2026-61511 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying… | CRITICAL 9.3EPSS 70.8% | 27 July 2026 |
| CVE-2026-55971 | Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. | CRITICAL 9.3EPSS 0.55% | 27 July 2026 |
| CVE-2026-48144 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. | CRITICAL 9.1EPSS 0.25% | 27 July 2026 |
| CVE-2026-64535 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a… | CRITICAL 9.8EPSS 0.55% | 27 July 2026 |
| CVE-2026-64534 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called… | CRITICAL 9.8EPSS 0.42% | 27 July 2026 |
| CVE-2026-14289 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing… | CRITICAL 9.0EPSS 0.40% | 27 July 2026 |
| CVE-2026-13714 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded… | CRITICAL 9.8EPSS 0.72% | 27 July 2026 |
| CVE-2026-13597 | The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. | CRITICAL 9.1EPSS 0.32% | 27 July 2026 |
| CVE-2026-13332 | The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the… | CRITICAL 9.1EPSS 0.24% | 27 July 2026 |
| CVE-2026-12394 | The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise. | CRITICAL 9.8EPSS 1.49% | 27 July 2026 |
| CVE-2026-64530 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on… | CRITICAL 9.8EPSS 0.54% | 26 July 2026 |
| CVE-2026-66013 | OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. | CRITICAL 9.3EPSS 0.43% | 25 July 2026 |
| CVE-2026-66012 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. | CRITICAL 10.0EPSS 0.55% | 25 July 2026 |
| CVE-2026-64523 | In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at submit handshake_nl_accept_doit() needs the file pointer backing req->hr_sk->sk_socket to survive the window between… | CRITICAL 9.8EPSS 0.36% | 25 July 2026 |
| CVE-2026-64459 | In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_sock Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU") removed the call_rcu() callback from tcp_ao_destroy_sock(),… | CRITICAL 9.8EPSS 0.47% | 25 July 2026 |
| CVE-2026-64450 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap ACK blocks A broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its data area. tipc_get_gap_ack_blks() only verifies that… | CRITICAL 9.1EPSS 0.54% | 25 July 2026 |
| CVE-2026-64439 | In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implementations at alloc krb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and rfc8009_encrypt(), rfc8009_decrypt() in rfc8009_aes2.c… | CRITICAL 9.8EPSS 0.43% | 25 July 2026 |
| CVE-2026-64410 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: IPIP tunnel hardware offload is not yet support No driver supports for IPIP tunnels yet, give up early on setting up the hardware offload for this scenario. | CRITICAL 9.8EPSS 0.38% | 25 July 2026 |
| CVE-2026-64399 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the destination file's data via… | CRITICAL 9.8EPSS 0.49% | 25 July 2026 |
| CVE-2026-64397 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. | CRITICAL 9.8EPSS 0.48% | 25 July 2026 |
| CVE-2026-64393 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 SET_INFO handlers call path-based VFS helpers after checking the access mask granted to the SMB handle. | CRITICAL 9.1EPSS 0.48% | 25 July 2026 |
| CVE-2026-64392 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be completed by deferred or durable handle teardown, where no request work is available. | CRITICAL 9.1EPSS 0.47% | 25 July 2026 |
| CVE-2026-64391 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. | CRITICAL 9.8EPSS 0.46% | 25 July 2026 |
| CVE-2026-64387 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error and free its response buffer. | CRITICAL 9.8EPSS 0.46% | 25 July 2026 |
| CVE-2026-64386 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and free its response buffer. | CRITICAL 9.8EPSS 0.46% | 25 July 2026 |
| CVE-2026-64385 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. | CRITICAL 9.8EPSS 0.46% | 25 July 2026 |
| CVE-2026-64384 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. | CRITICAL 9.8EPSS 0.46% | 25 July 2026 |
| CVE-2026-64383 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. | CRITICAL 9.8EPSS 0.46% | 25 July 2026 |
| CVE-2026-64355 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. | CRITICAL 9.8EPSS 0.51% | 25 July 2026 |
| CVE-2026-64320 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). | CRITICAL 9.1EPSS 0.75% | 25 July 2026 |
| CVE-2026-64319 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and… | CRITICAL 9.1EPSS 0.52% | 25 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.