Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,739 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,248 results · page 75 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-63940 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O requests of length '0' (or count '0'), so that setting up the software scratch area (and other code) doesn't… | CRITICAL 9.3EPSS 0.18% | 19 July 2026 |
| CVE-2026-63939 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-GHCB scratch area When setting the length of the GHCB scratch area, and the area is in the GHCB shared buffer, set the effective… | CRITICAL 9.3EPSS 0.19% | 19 July 2026 |
| CVE-2026-63938 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the actual size of the buffer When processing Page State Change (PSC) requests, validate the PSC buffer against the effective size of the… | CRITICAL 9.3EPSS 0.18% | 19 July 2026 |
| CVE-2026-63924 | In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers. | CRITICAL 9.8EPSS 0.71% | 19 July 2026 |
| CVE-2026-63922 | In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs. ipv6_dest_hao() may call pskb_expand_head() for a… | CRITICAL 9.8EPSS 0.71% | 19 July 2026 |
| CVE-2026-63912 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. | CRITICAL 9.8EPSS 0.71% | 19 July 2026 |
| CVE-2026-63888 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit… | CRITICAL 9.8EPSS 0.78% | 19 July 2026 |
| CVE-2026-63887 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an 8192-byte… | CRITICAL 9.8EPSS 0.78% | 19 July 2026 |
| CVE-2026-63886 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and then, for BASE64-encoded responses,… | CRITICAL 9.8EPSS 0.71% | 19 July 2026 |
| CVE-2026-63857 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() The transmit loop in airoha_dev_xmit() reads fragment address and length during its final iteration, when… | CRITICAL 9.8EPSS 0.38% | 19 July 2026 |
| CVE-2026-63830 | In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the scatterlist entry ownership state. | CRITICAL 9.4EPSS 0.37% | 19 July 2026 |
| CVE-2026-63825 | In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent access crashes GCC's GCOV instrumentation can merge global branch counters with loop induction variables as an optimization. | CRITICAL 9.8EPSS 0.78% | 19 July 2026 |
| CVE-2026-63808 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the… | CRITICAL 9.8EPSS 0.53% | 19 July 2026 |
| CVE-2026-63800 | In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls pnfs_prepare_to_retry_layoutget(lo). | CRITICAL 9.8EPSS 0.53% | 19 July 2026 |
| CVE-2026-63795 | In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set to false, fid aliases oldfid. | CRITICAL 10.0EPSS 0.50% | 19 July 2026 |
| CVE-2026-53399 | In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to… | CRITICAL 9.8EPSS 0.54% | 19 July 2026 |
| CVE-2026-53398 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. | CRITICAL 9.8EPSS 0.54% | 19 July 2026 |
| CVE-2026-53384 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port via serial8250_register_8250_port() and then, if the device has a clock,… | CRITICAL 9.8EPSS 0.52% | 19 July 2026 |
| CVE-2026-9323 | Each call consumes approximately 30 bits of PRNG state, and the Mersenne Twister internal state is approximately 19,937 bits, so an attacker who observes approximately 334 session IDs (for example via the X-Urwid-ID HTTP response header) can fully… | CRITICAL 9.2EPSS 0.43% | 18 July 2026 |
| CVE-2026-16117 | The upstream then decodes the path and serves it, letting an attacker reach upstream paths that the proxy was configured to hide via rewritePrefix, including internal or administrative endpoints. | CRITICAL 10.0EPSS 0.44% | 18 July 2026 |
| CVE-2025-71392 | An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL. | CRITICAL 9.4EPSS 0.24% | 18 July 2026 |
| CVE-2024-58366 | SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. | CRITICAL 9.0EPSS 0.32% | 18 July 2026 |
| CVE-2026-16158 | Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. | CRITICAL 10.0EPSS 0.23% | 18 July 2026 |
| CVE-2026-15631 | The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so a crafted upgrade request with path traversal sequences can escape the rewrite prefix and reach upstream… | CRITICAL 10.0EPSS 0.33% | 18 July 2026 |
| CVE-2026-47865 | VMware Avi Load Balancer contains an authentication bypass vulnerability. | CRITICAL 9.8EPSS 0.83% | 18 July 2026 |
| CVE-2026-55518 | An authenticated low-privileged Avo user can bypass hidden or disabled attach controls and directly attach related records to a parent record by sending a crafted POST request, which can lead to privilege escalation and cross-tenant data exposure where… | CRITICAL 9.6EPSS 0.45% | 17 July 2026 |
| CVE-2026-54466 | Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. | CRITICAL 9.2EPSS 0.22% | 17 July 2026 |
| CVE-2026-54159 | By crafting that value, an unauthenticated attacker can smuggle a malicious serialized PHP object into the cache, and when it is deserialized, a gadget chain writes an arbitrary PHP file inside the modules/ps_facetedsearch/ directory, which is then used… | CRITICAL 10.0EPSS 0.75% | 17 July 2026 |
| CVE-2026-52348 | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. | CRITICAL 9.8EPSS 0.47% | 17 July 2026 |
| CVE-2026-48062 | Applications are impacted if they accept user-controlled uploads, rely on ext_in to validate the uploaded filename extension, save uploaded files using the original client filename with $file->move($path), store uploads in a web-accessible directory,… | CRITICAL 9.8EPSS 0.78% | 17 July 2026 |
| CVE-2026-13446 | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | CRITICAL 9.8EPSS 0.38% | 17 July 2026 |
| CVE-2026-8859 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. | CRITICAL 9.9EPSS 0.56% | 17 July 2026 |
| CVE-2026-8635 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions. | CRITICAL 9.9EPSS 0.53% | 17 July 2026 |
| CVE-2026-8505 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. | CRITICAL 9.8EPSS 0.57% | 17 July 2026 |
| CVE-2026-8481 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. | CRITICAL 9.9EPSS 0.81% | 17 July 2026 |
| CVE-2026-8476 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. | CRITICAL 9.9EPSS 0.97% | 17 July 2026 |
| CVE-2026-63030 | WordPress Core Interpretation Conflict Vulnerability | KEVCRITICAL 9.8EPSS 97.3% | 17 July 2026 |
| CVE-2026-52199 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component | CRITICAL 9.1EPSS 0.66% | 17 July 2026 |
| CVE-2026-46420 | From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the PHP version from repository-controlled files such as .php-version, composer.lock through platform-overrides.php, and composer.json through config.platform.php, and insufficiently… | CRITICAL 9.8EPSS 1.54% | 17 July 2026 |
| CVE-2026-42168 | django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. | CRITICAL 9.1EPSS 2.05% | 17 July 2026 |
| CVE-2026-36669 | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory. | CRITICAL 9.8EPSS 0.56% | 17 July 2026 |
| CVE-2026-15091 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation. | CRITICAL 9.3EPSS 0.57% | 17 July 2026 |
| CVE-2026-14501 | IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions. | CRITICAL 9.8EPSS 0.32% | 17 July 2026 |
| CVE-2026-13473 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. | CRITICAL 9.8EPSS 0.47% | 17 July 2026 |
| CVE-2026-13448 | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). | CRITICAL 9.8EPSS 0.67% | 17 July 2026 |
| CVE-2025-51677 | An issue was discovered in openRISC OR1200 commit 83ac6b. | CRITICAL 9.1EPSS 0.63% | 17 July 2026 |
| CVE-2026-9135 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the… | CRITICAL 9.9EPSS 0.84% | 17 July 2026 |
| CVE-2026-9103 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. | CRITICAL 9.8EPSS 2.83% | 17 July 2026 |
| CVE-2026-9202 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can… | CRITICAL 9.8EPSS 0.50% | 17 July 2026 |
| CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 60.6% | 17 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.