Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,248 results · page 73 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-16353 | This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.8EPSS 0.52% | 21 July 2026 |
| CVE-2026-16352 | Sandbox escape due to use-after-free in the Disability Access APIs component. | CRITICAL 9.8EPSS 0.39% | 21 July 2026 |
| CVE-2026-16351 | Sandbox escape due to use-after-free in the DOM: Navigation component. | CRITICAL 9.8EPSS 0.39% | 21 July 2026 |
| CVE-2026-16350 | This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | CRITICAL 9.8EPSS 0.40% | 21 July 2026 |
| CVE-2026-16349 | Same-origin policy bypass in the DOM: Navigation component. | CRITICAL 9.8EPSS 0.21% | 21 July 2026 |
| CVE-2026-65008 | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without… | EXPLOITCRITICAL 9.3EPSS 2.02% | 21 July 2026 |
| CVE-2026-1617 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. | CRITICAL 9.8EPSS 0.47% | 21 July 2026 |
| CVE-2026-64606 | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. | CRITICAL 9.8EPSS 0.72% | 21 July 2026 |
| CVE-2026-64609 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. | CRITICAL 9.1EPSS 0.78% | 21 July 2026 |
| CVE-2026-64608 | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. | CRITICAL 9.8EPSS 0.81% | 21 July 2026 |
| CVE-2026-62415 | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets. | CRITICAL 9.1EPSS 0.45% | 21 July 2026 |
| CVE-2026-13439 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session… | CRITICAL 9.8EPSS 0.40% | 21 July 2026 |
| CVE-2026-15901 | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | CRITICAL 9.6EPSS 0.44% | 20 July 2026 |
| CVE-2026-15900 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 20 July 2026 |
| CVE-2026-15899 | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 20 July 2026 |
| CVE-2026-64625 | AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. | CRITICAL 9.3EPSS 0.60% | 20 July 2026 |
| CVE-2026-52656 | An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file | CRITICAL 9.8EPSS 0.73% | 20 July 2026 |
| CVE-2024-51315 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName | CRITICAL 9.8EPSS 0.60% | 20 July 2026 |
| CVE-2024-51314 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg. | CRITICAL 9.8EPSS 0.60% | 20 July 2026 |
| CVE-2024-51312 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg. | CRITICAL 9.8EPSS 0.60% | 20 July 2026 |
| CVE-2026-53595 | The result is that an anonymous attacker sets the email and password of the lowest-id activated FreeScout account (a support agent, or an administrator if one was added by invitation) and authenticates as that account. | CRITICAL 9.4EPSS 1.94% | 20 July 2026 |
| CVE-2026-13380 | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. | CRITICAL 9.0EPSS 0.24% | 20 July 2026 |
| CVE-2024-51313 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. | CRITICAL 9.8EPSS 0.60% | 20 July 2026 |
| CVE-2024-51311 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. | CRITICAL 9.8EPSS 0.60% | 20 July 2026 |
| CVE-2026-63767 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket… | CRITICAL 9.3EPSS 1.12% | 20 July 2026 |
| CVE-2026-63766 | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. | CRITICAL 9.3EPSS 1.75% | 20 July 2026 |
| CVE-2026-44231 | Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. | CRITICAL 9.1EPSS 0.41% | 20 July 2026 |
| CVE-2026-16337 | Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the… | CRITICAL 9.4EPSS 0.55% | 20 July 2026 |
| CVE-2026-64193 | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. | CRITICAL 9.8EPSS 0.79% | 20 July 2026 |
| CVE-2026-62414 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. | CRITICAL 9.1EPSS 0.40% | 20 July 2026 |
| CVE-2026-61900 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE. | CRITICAL 10.0EPSS 0.45% | 20 July 2026 |
| CVE-2026-61425 | Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access. | CRITICAL 9.4EPSS 0.57% | 20 July 2026 |
| CVE-2026-61424 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. | CRITICAL 10.0EPSS 0.45% | 20 July 2026 |
| CVE-2026-60034 | Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. | CRITICAL 9.4EPSS 0.42% | 20 July 2026 |
| CVE-2026-60032 | Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. | CRITICAL 9.4EPSS 0.41% | 20 July 2026 |
| CVE-2026-12341 | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens. | CRITICAL 9.8EPSS 0.22% | 20 July 2026 |
| CVE-2026-39878 | Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full… | CRITICAL 9.3EPSS 0.43% | 20 July 2026 |
| CVE-2026-54051 | Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md calls the main control against a compromised agent (Adversary 3.2). | CRITICAL 9.9EPSS 0.67% | 20 July 2026 |
| CVE-2026-41521 | Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. | CRITICAL 9.1EPSS 0.39% | 20 July 2026 |
| CVE-2026-41252 | Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. | CRITICAL 9.8EPSS 0.61% | 20 July 2026 |
| CVE-2026-35048 | On PHP 8+, the `addslashes()` protection is bypassed because it checks for `get_magic_quotes_gpc()`, a function removed in PHP 8.0. | CRITICAL 9.8EPSS 0.58% | 20 July 2026 |
| CVE-2026-51027 | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. | CRITICAL 9.9EPSS 0.62% | 20 July 2026 |
| CVE-2026-46428 | An on-path attacker presenting any chain-valid certificate for any domain can intercept SMTP submission, including PLAIN/LOGIN credentials and message contents, against any lettre user built with the `boring-tls` feature. | CRITICAL 9.1EPSS 0.32% | 20 July 2026 |
| CVE-2026-46412 | Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). | CRITICAL 10.0EPSS 0.77% | 20 July 2026 |
| CVE-2026-35198 | Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover… | CRITICAL 9.0EPSS 0.49% | 20 July 2026 |
| CVE-2026-28220 | Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channel using the shared cluster key, to make the master node deserialize an attacker-controlled… | CRITICAL 9.1EPSS 0.40% | 20 July 2026 |
| CVE-2026-63071 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | CRITICAL 9.8EPSS 0.75% | 20 July 2026 |
| CVE-2026-62183 | Improper Privilege Management vulnerability in Apache Syncope. | CRITICAL 9.8EPSS 0.69% | 20 July 2026 |
| CVE-2026-57308 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. | CRITICAL 9.8EPSS 0.83% | 20 July 2026 |
| CVE-2026-53421 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. | CRITICAL 9.8EPSS 0.68% | 20 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.