Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,238 results · page 7 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-83100 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83099 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 10.0EPSS 0.36% | 15 September 2026 |
| CVE-2026-83098 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 9.8EPSS 0.36% | 15 September 2026 |
| CVE-2026-83095 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83094 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83066 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83064 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | CRITICAL 9.1EPSS 0.46% | 15 September 2026 |
| CVE-2026-83062 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83061 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83060 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83059 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 10.0EPSS 0.48% | 15 September 2026 |
| CVE-2026-83058 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 9.9EPSS 0.31% | 15 September 2026 |
| CVE-2026-83057 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 9.9EPSS 0.42% | 15 September 2026 |
| CVE-2026-83056 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 9.9EPSS 0.42% | 15 September 2026 |
| CVE-2026-83055 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 9.9EPSS 0.31% | 15 September 2026 |
| CVE-2026-83054 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). | CRITICAL 9.8EPSS 0.36% | 15 September 2026 |
| CVE-2026-83043 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). | CRITICAL 9.6EPSS 0.40% | 15 September 2026 |
| CVE-2026-83042 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83040 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). | CRITICAL 9.6EPSS 0.40% | 15 September 2026 |
| CVE-2026-83039 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). | CRITICAL 9.9EPSS 0.42% | 15 September 2026 |
| CVE-2026-83038 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink Integration). | CRITICAL 9.9EPSS 0.29% | 15 September 2026 |
| CVE-2026-83037 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83036 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83035 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83031 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | CRITICAL 9.9EPSS 0.42% | 15 September 2026 |
| CVE-2026-83029 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). | CRITICAL 9.6EPSS 0.35% | 15 September 2026 |
| CVE-2026-83027 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.3EPSS 0.25% | 15 September 2026 |
| CVE-2026-83021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). | CRITICAL 10.0EPSS 0.45% | 15 September 2026 |
| CVE-2026-83020 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). | CRITICAL 10.0EPSS 0.45% | 15 September 2026 |
| CVE-2026-83006 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL 9.1EPSS 0.43% | 15 September 2026 |
| CVE-2026-83001 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | CRITICAL 9.1EPSS 0.46% | 15 September 2026 |
| CVE-2026-83000 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-82999 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.9EPSS 0.42% | 15 September 2026 |
| CVE-2026-82998 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.9EPSS 0.42% | 15 September 2026 |
| CVE-2026-82997 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.9EPSS 0.42% | 15 September 2026 |
| CVE-2026-82995 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-82994 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-76675 | A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. | CRITICAL 9.1EPSS 1.34% | 15 September 2026 |
| CVE-2026-76674 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. | CRITICAL 9.8EPSS 1.06% | 15 September 2026 |
| CVE-2026-76673 | Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. | CRITICAL 9.8EPSS 0.45% | 15 September 2026 |
| CVE-2026-76672 | A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. | CRITICAL 9.9EPSS 0.40% | 15 September 2026 |
| CVE-2026-76670 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. | CRITICAL 9.9EPSS 0.45% | 15 September 2026 |
| CVE-2026-76669 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. | CRITICAL 9.9EPSS 0.45% | 15 September 2026 |
| CVE-2026-73963 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). | CRITICAL 9.8EPSS 0.36% | 15 September 2026 |
| CVE-2026-73962 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | CRITICAL 9.6EPSS 0.27% | 15 September 2026 |
| CVE-2026-73961 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-73957 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). | CRITICAL 9.3EPSS 0.28% | 15 September 2026 |
| CVE-2026-73956 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-73953 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). | CRITICAL 9.8EPSS 0.36% | 15 September 2026 |
| CVE-2026-73952 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). | CRITICAL 9.1EPSS 0.31% | 15 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.