Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,247 results · page 67 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-16232 | Check Point SmartConsole Improper Authentication Vulnerability | KEVCRITICAL 9.3EPSS 72.1% | 22 July 2026 |
| CVE-2026-8152 | Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. | CRITICAL 9.3EPSS 0.41% | 22 July 2026 |
| CVE-2026-63048 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE. | CRITICAL 9.4EPSS 0.38% | 22 July 2026 |
| CVE-2026-56820 | In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse`… | CRITICAL 9.1EPSS 0.22% | 21 July 2026 |
| CVE-2026-16424 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.28% | 21 July 2026 |
| CVE-2026-16419 | Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.26% | 21 July 2026 |
| CVE-2026-16416 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. | CRITICAL 9.3EPSS 0.14% | 21 July 2026 |
| CVE-2026-8987 | Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. | CRITICAL 9.4EPSS 0.51% | 21 July 2026 |
| CVE-2026-8986 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. | CRITICAL 9.5EPSS 2.29% | 21 July 2026 |
| CVE-2026-8985 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. | CRITICAL 10.0EPSS 6.60% | 21 July 2026 |
| CVE-2026-8984 | Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. | CRITICAL 10.0EPSS 0.77% | 21 July 2026 |
| CVE-2026-65318 | Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the… | CRITICAL 9.2EPSS 0.60% | 21 July 2026 |
| CVE-2026-65317 | Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted… | CRITICAL 9.2EPSS 0.64% | 21 July 2026 |
| CVE-2026-62549 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). | CRITICAL 9.6EPSS 0.28% | 21 July 2026 |
| CVE-2026-62546 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). | CRITICAL 9.1EPSS 0.49% | 21 July 2026 |
| CVE-2026-61245 | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61244 | Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). | CRITICAL 9.1EPSS 0.43% | 21 July 2026 |
| CVE-2026-61242 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). | CRITICAL 9.9EPSS 0.43% | 21 July 2026 |
| CVE-2026-61239 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). | CRITICAL 9.9EPSS 0.37% | 21 July 2026 |
| CVE-2026-61238 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). | CRITICAL 9.1EPSS 0.43% | 21 July 2026 |
| CVE-2026-61237 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). | CRITICAL 9.9EPSS 0.38% | 21 July 2026 |
| CVE-2026-61235 | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). | CRITICAL 9.1EPSS 0.49% | 21 July 2026 |
| CVE-2026-61233 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61223 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). | CRITICAL 9.0EPSS 0.39% | 21 July 2026 |
| CVE-2026-61211 | Vulnerability in the RDBMS component of Oracle Database Server. | CRITICAL 9.9EPSS 0.44% | 21 July 2026 |
| CVE-2026-61209 | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). | CRITICAL 9.9EPSS 0.43% | 21 July 2026 |
| CVE-2026-61207 | Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). | CRITICAL 9.3EPSS 0.35% | 21 July 2026 |
| CVE-2026-61204 | Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). | CRITICAL 9.0EPSS 0.18% | 21 July 2026 |
| CVE-2026-61203 | Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). | CRITICAL 9.4EPSS 0.46% | 21 July 2026 |
| CVE-2026-61201 | Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). | CRITICAL 9.0EPSS 0.39% | 21 July 2026 |
| CVE-2026-61197 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | CRITICAL 9.1EPSS 0.43% | 21 July 2026 |
| CVE-2026-61196 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61186 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). | CRITICAL 9.4EPSS 0.41% | 21 July 2026 |
| CVE-2026-61184 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). | CRITICAL 9.1EPSS 0.43% | 21 July 2026 |
| CVE-2026-61183 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61178 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61175 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). | CRITICAL 9.3EPSS 0.44% | 21 July 2026 |
| CVE-2026-61174 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). | CRITICAL 9.0EPSS 0.19% | 21 July 2026 |
| CVE-2026-61171 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). | CRITICAL 9.1EPSS 0.43% | 21 July 2026 |
| CVE-2026-61167 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61161 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61156 | Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). | CRITICAL 9.1EPSS 0.43% | 21 July 2026 |
| CVE-2026-61155 | Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). | CRITICAL 9.1EPSS 0.49% | 21 July 2026 |
| CVE-2026-61154 | Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61153 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). | CRITICAL 9.1EPSS 0.43% | 21 July 2026 |
| CVE-2026-61146 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). | CRITICAL 9.9EPSS 0.43% | 21 July 2026 |
| CVE-2026-61145 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61140 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | CRITICAL 9.8EPSS 0.48% | 21 July 2026 |
| CVE-2026-61131 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). | CRITICAL 9.8EPSS 0.51% | 21 July 2026 |
| CVE-2026-61130 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). | CRITICAL 9.1EPSS 0.49% | 21 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.