Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,248 results · page 72 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-28321 | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. | CRITICAL 9.1EPSS 0.58% | 21 July 2026 |
| CVE-2026-28317 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. | CRITICAL 9.1EPSS 0.50% | 21 July 2026 |
| CVE-2026-28316 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. | CRITICAL 9.1EPSS 2.13% | 21 July 2026 |
| CVE-2026-28314 | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. | CRITICAL 9.1EPSS 0.62% | 21 July 2026 |
| CVE-2026-28313 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. | CRITICAL 9.1EPSS 0.50% | 21 July 2026 |
| CVE-2026-28312 | SolarWinds Serv-U is affected by a privilege escalation vulnerability. | CRITICAL 9.1EPSS 0.58% | 21 July 2026 |
| CVE-2026-28310 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. | CRITICAL 9.1EPSS 0.50% | 21 July 2026 |
| CVE-2026-28309 | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. | CRITICAL 9.1EPSS 0.50% | 21 July 2026 |
| CVE-2026-28308 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. | CRITICAL 9.1EPSS 0.79% | 21 July 2026 |
| CVE-2026-28307 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. | CRITICAL 9.1EPSS 0.50% | 21 July 2026 |
| CVE-2026-28306 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. | CRITICAL 9.1EPSS 0.50% | 21 July 2026 |
| CVE-2026-28305 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. | CRITICAL 9.1EPSS 0.79% | 21 July 2026 |
| CVE-2026-28304 | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. | CRITICAL 9.1EPSS 0.79% | 21 July 2026 |
| CVE-2026-28302 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. | CRITICAL 9.1EPSS 0.72% | 21 July 2026 |
| CVE-2026-65048 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without… | CRITICAL 9.3EPSS 0.54% | 21 July 2026 |
| CVE-2025-66390 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even… | CRITICAL 9.8EPSS 0.64% | 21 July 2026 |
| CVE-2026-16412 | Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. | CRITICAL 9.8EPSS 0.52% | 21 July 2026 |
| CVE-2026-16411 | Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. | CRITICAL 9.8EPSS 0.49% | 21 July 2026 |
| CVE-2026-16410 | This vulnerability was fixed in Firefox 153 and Thunderbird 153. | CRITICAL 9.8EPSS 0.30% | 21 July 2026 |
| CVE-2026-16408 | Integer overflow in the Audio/Video: Playback component. | CRITICAL 9.8EPSS 0.43% | 21 July 2026 |
| CVE-2026-16407 | Mitigation bypass in the DOM: Service Workers component. | CRITICAL 9.8EPSS 0.28% | 21 July 2026 |
| CVE-2026-16406 | Mitigation bypass in the Networking component. | CRITICAL 9.1EPSS 0.25% | 21 July 2026 |
| CVE-2026-16402 | Integer overflow in the Graphics: ImageLib component. | CRITICAL 9.8EPSS 0.34% | 21 July 2026 |
| CVE-2026-16395 | Integer overflow in the Audio/Video component. | CRITICAL 9.8EPSS 0.34% | 21 July 2026 |
| CVE-2026-16394 | Mitigation bypass in the DOM: Security component. | CRITICAL 9.1EPSS 0.25% | 21 July 2026 |
| CVE-2026-16393 | This vulnerability was fixed in Firefox 153 and Thunderbird 153. | CRITICAL 9.1EPSS 0.30% | 21 July 2026 |
| CVE-2026-16392 | This vulnerability was fixed in Firefox 153 and Thunderbird 153. | CRITICAL 9.1EPSS 0.36% | 21 July 2026 |
| CVE-2026-16390 | Mitigation bypass in the Enterprise Policies component. | CRITICAL 9.1EPSS 0.32% | 21 July 2026 |
| CVE-2026-16389 | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. | CRITICAL 9.8EPSS 0.56% | 21 July 2026 |
| CVE-2026-16388 | This vulnerability was fixed in Firefox 153 and Thunderbird 153. | CRITICAL 9.8EPSS 0.38% | 21 July 2026 |
| CVE-2026-16387 | This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.8EPSS 0.20% | 21 July 2026 |
| CVE-2026-16383 | Mitigation bypass in the DOM: Networking component. | CRITICAL 9.8EPSS 0.39% | 21 July 2026 |
| CVE-2026-16382 | Mitigation bypass in the DOM: Service Workers component. | CRITICAL 9.8EPSS 0.38% | 21 July 2026 |
| CVE-2026-16381 | Same-origin policy bypass in the Networking: DNS component. | CRITICAL 9.1EPSS 0.17% | 21 July 2026 |
| CVE-2026-16380 | Mitigation bypass in the Networking component. | CRITICAL 9.1EPSS 0.31% | 21 July 2026 |
| CVE-2026-16377 | Mitigation bypass in the PDF Viewer component. | CRITICAL 9.8EPSS 0.39% | 21 July 2026 |
| CVE-2026-16375 | This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.8EPSS 0.21% | 21 July 2026 |
| CVE-2026-16370 | Mitigation bypass in the DOM: Networking component. | CRITICAL 9.1EPSS 0.31% | 21 July 2026 |
| CVE-2026-16369 | Integer overflow in the JavaScript: WebAssembly component. | CRITICAL 9.8EPSS 0.44% | 21 July 2026 |
| CVE-2026-16368 | This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.8EPSS 0.39% | 21 July 2026 |
| CVE-2026-16367 | This vulnerability was fixed in Firefox 153 and Thunderbird 153. | CRITICAL 10.0EPSS 0.38% | 21 July 2026 |
| CVE-2026-16364 | This vulnerability was fixed in Firefox 153 and Thunderbird 153. | CRITICAL 9.1EPSS 0.31% | 21 July 2026 |
| CVE-2026-16363 | This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.8EPSS 0.44% | 21 July 2026 |
| CVE-2026-16361 | Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. | CRITICAL 9.8EPSS 0.32% | 21 July 2026 |
| CVE-2026-16360 | Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. | CRITICAL 9.8EPSS 0.47% | 21 July 2026 |
| CVE-2026-16359 | This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.1EPSS 0.26% | 21 July 2026 |
| CVE-2026-16358 | This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.8EPSS 0.22% | 21 July 2026 |
| CVE-2026-16357 | This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.8EPSS 0.40% | 21 July 2026 |
| CVE-2026-16356 | Sandbox escape due to use-after-free in the Disability Access APIs component. | CRITICAL 9.8EPSS 0.39% | 21 July 2026 |
| CVE-2026-16355 | This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.8EPSS 0.40% | 21 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.