Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,247 results · page 66 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-15616 | Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access. | CRITICAL 9.1EPSS 0.33% | 23 July 2026 |
| CVE-2026-15612 | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. | CRITICAL 9.1EPSS 0.18% | 23 July 2026 |
| CVE-2026-15611 | Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account. | CRITICAL 9.1EPSS 0.40% | 23 July 2026 |
| CVE-2026-65689 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted… | CRITICAL 9.3EPSS 0.87% | 23 July 2026 |
| CVE-2026-65688 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted… | CRITICAL 9.3EPSS 0.87% | 23 July 2026 |
| CVE-2026-65687 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted… | CRITICAL 9.3EPSS 0.87% | 23 July 2026 |
| CVE-2026-65907 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | CRITICAL 9.1EPSS 0.42% | 23 July 2026 |
| CVE-2026-65906 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | CRITICAL 10.0EPSS 0.54% | 23 July 2026 |
| CVE-2026-65606 | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. | CRITICAL 9.4EPSS 0.65% | 23 July 2026 |
| CVE-2026-65605 | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. | CRITICAL 9.4EPSS 0.65% | 23 July 2026 |
| CVE-2026-65471 | Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | CRITICAL 9.6EPSS 0.20% | 23 July 2026 |
| CVE-2026-65461 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | CRITICAL 9.1EPSS 0.50% | 23 July 2026 |
| CVE-2026-65455 | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | CRITICAL 9.1EPSS 0.50% | 23 July 2026 |
| CVE-2026-64815 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | CRITICAL 9.8EPSS 0.33% | 23 July 2026 |
| CVE-2026-64813 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | CRITICAL 10.0EPSS 0.51% | 23 July 2026 |
| CVE-2026-64812 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | CRITICAL 10.0EPSS 0.47% | 23 July 2026 |
| CVE-2026-61951 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | CRITICAL 9.8EPSS 0.48% | 23 July 2026 |
| CVE-2026-61950 | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | CRITICAL 9.3EPSS 0.40% | 23 July 2026 |
| CVE-2026-61949 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | CRITICAL 9.3EPSS 0.40% | 23 July 2026 |
| CVE-2026-61948 | Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | CRITICAL 9.3EPSS 0.28% | 23 July 2026 |
| CVE-2026-59555 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | CRITICAL 10.0EPSS 0.60% | 23 July 2026 |
| CVE-2026-59544 | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | CRITICAL 9.8EPSS 0.56% | 23 July 2026 |
| CVE-2026-59543 | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | CRITICAL 9.9EPSS 0.79% | 23 July 2026 |
| CVE-2026-59540 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | CRITICAL 9.8EPSS 0.48% | 23 July 2026 |
| CVE-2026-59526 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | CRITICAL 9.3EPSS 0.40% | 23 July 2026 |
| CVE-2026-59525 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | CRITICAL 9.3EPSS 0.40% | 23 July 2026 |
| CVE-2026-59514 | Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. | CRITICAL 9.3EPSS 0.23% | 23 July 2026 |
| CVE-2026-57784 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | CRITICAL 9.6EPSS 0.20% | 23 July 2026 |
| CVE-2026-27064 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | CRITICAL 9.1EPSS 0.50% | 23 July 2026 |
| CVE-2026-65431 | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions. | CRITICAL 9.8EPSS 0.38% | 23 July 2026 |
| CVE-2026-64874 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. | CRITICAL 9.8EPSS 0.29% | 23 July 2026 |
| CVE-2026-64873 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. | CRITICAL 9.8EPSS 0.27% | 23 July 2026 |
| CVE-2026-15015 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. | CRITICAL 9.8EPSS 0.71% | 23 July 2026 |
| CVE-2026-15011 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with… | CRITICAL 9.8EPSS 0.49% | 23 July 2026 |
| CVE-2026-14282 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. | CRITICAL 9.8EPSS 0.67% | 23 July 2026 |
| CVE-2026-16723 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. | CRITICAL 9.0EPSS 16.0% | 23 July 2026 |
| CVE-2026-60372 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). | CRITICAL 9.8EPSS 0.55% | 22 July 2026 |
| CVE-2026-60369 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). | CRITICAL 9.9EPSS 0.47% | 22 July 2026 |
| CVE-2026-60367 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). | CRITICAL 9.8EPSS 0.55% | 22 July 2026 |
| CVE-2026-60366 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). | CRITICAL 10.0EPSS 0.55% | 22 July 2026 |
| CVE-2026-64798 | Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy. | CRITICAL 9.1EPSS 0.24% | 22 July 2026 |
| CVE-2026-64796 | Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. | CRITICAL 9.8EPSS 0.29% | 22 July 2026 |
| CVE-2026-64793 | Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. | CRITICAL 9.1EPSS 0.25% | 22 July 2026 |
| CVE-2025-50329 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | CRITICAL 9.8EPSS 0.57% | 22 July 2026 |
| CVE-2026-64829 | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the… | CRITICAL 9.1EPSS 0.42% | 22 July 2026 |
| CVE-2026-13072 | When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended… | CRITICAL 9.2EPSS 0.40% | 22 July 2026 |
| CVE-2026-16624 | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom… | CRITICAL 9.6EPSS 0.28% | 22 July 2026 |
| CVE-2026-16606 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. | CRITICAL 9.3EPSS 0.65% | 22 July 2026 |
| CVE-2026-2395 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. | CRITICAL 9.8EPSS 0.47% | 22 July 2026 |
| CVE-2026-62144 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. | CRITICAL 9.1EPSS 20.8% | 22 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.