Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,739 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,248 results · page 77 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-15013 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. | EXPLOITCRITICAL 9.8EPSS 1.50% | 16 July 2026 |
| CVE-2026-55652 | Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allowing an unauthenticated attacker to send… | CRITICAL 9.8EPSS 0.62% | 15 July 2026 |
| CVE-2026-55445 | Prior to 2.20.1, the init guard middleware in back/loaders/express.ts checks /api/user/init but not /open/user/init, while rewrite('/open/*', '/api/$1') rewrites the whitelisted /open/* path after JWT authentication and the guard have passed; an… | CRITICAL 9.3EPSS 0.66% | 15 July 2026 |
| CVE-2026-54458 | Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. | CRITICAL 9.6EPSS 0.51% | 15 July 2026 |
| CVE-2026-52893 | An attacker using an OIDC provider account with a victim's email or username can cause Wekan to merge the attacker's OIDC credentials into the victim account and then log in as that account. | CRITICAL 9.2EPSS 0.48% | 15 July 2026 |
| CVE-2026-52891 | Because models/avatars.js and models/fileValidation.js used a shell command with the avatar filename, shell metacharacters such as backticks and $() in the filename could execute commands on the server. | CRITICAL 9.9EPSS 0.78% | 15 July 2026 |
| CVE-2026-30623 | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. | CRITICAL 9.8EPSS 5.00% | 15 July 2026 |
| CVE-2026-30618 | xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. | CRITICAL 9.8EPSS 1.20% | 15 July 2026 |
| CVE-2026-26718 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. | CRITICAL 9.1EPSS 0.22% | 15 July 2026 |
| CVE-2025-65720 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. | CRITICAL 9.8EPSS 0.89% | 15 July 2026 |
| CVE-2026-54052 | Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to… | CRITICAL 9.9EPSS 0.39% | 15 July 2026 |
| CVE-2026-52887 | Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter… | CRITICAL 10.0EPSS 0.89% | 15 July 2026 |
| CVE-2026-51380 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via the /cgi-bin/UploadCfg endpoint | CRITICAL 9.8EPSS 0.70% | 15 July 2026 |
| CVE-2026-49352 | From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession.js, allowing attackers to forge an auth_token cookie… | CRITICAL 9.8EPSS 0.60% | 15 July 2026 |
| CVE-2026-46339 | From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the… | CRITICAL 10.0EPSS 3.35% | 15 July 2026 |
| CVE-2026-46684 | Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and length before userBOByToken(token) uses JWT.decode() without signature… | CRITICAL 9.5EPSS 0.32% | 15 July 2026 |
| CVE-2026-45534 | Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so… | CRITICAL 9.0EPSS 0.64% | 15 July 2026 |
| CVE-2026-46421 | The malicious packages harvested credentials and attempted self-propagation. | CRITICAL 9.3EPSS 0.52% | 15 July 2026 |
| CVE-2026-62948 | Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and statefiles_write_state4() without escaping, allowing newline injection of forged lease lines that LuCI… | CRITICAL 9.6EPSS 0.58% | 15 July 2026 |
| CVE-2026-53513 | Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled oidcConfig.userInfoEndpoint, tokenEndpoint, and jwksEndpoint URLs when skipDiscovery: true is set, store them on the… | CRITICAL 9.6EPSS 0.25% | 15 July 2026 |
| CVE-2026-53512 | Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without verifying the confidential client's… | CRITICAL 9.1EPSS 0.27% | 15 July 2026 |
| CVE-2026-50562 | At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/preview-fastgpt-build.yml can be downloaded by privileged workflow_run… | CRITICAL 9.3EPSS 0.21% | 15 July 2026 |
| CVE-2026-14960 | Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. | CRITICAL 9.8EPSS 0.46% | 15 July 2026 |
| CVE-2026-62378 | From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF preview path can render HTML content uploaded as .pdf, allowing stored cross-site scripting in the management… | CRITICAL 9.0EPSS 0.49% | 15 July 2026 |
| CVE-2026-52843 | Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credentials: omit, credentials: same-origin, credentials: include, and XMLHttpRequest.withCredentials, allowing an… | CRITICAL 9.3EPSS 0.23% | 15 July 2026 |
| CVE-2026-52842 | Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page origin, so a URL such as `http://attacker.com/@victim.com/` was fetched from attacker.com but treated as… | CRITICAL 9.3EPSS 0.25% | 15 July 2026 |
| CVE-2026-20157 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | CRITICAL 9.8EPSS 0.11% | 15 July 2026 |
| CVE-2026-20156 | This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | CRITICAL 9.8EPSS 0.26% | 15 July 2026 |
| CVE-2026-50148 | From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an… | CRITICAL 9.1EPSS 0.43% | 15 July 2026 |
| CVE-2026-44986 | Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile issue a session based on the invitation email… | CRITICAL 9.9EPSS 0.52% | 15 July 2026 |
| CVE-2026-61740 | Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded DEFAULT_TOKEN_SECRET, /auth-status and /login can mint guest JWTs,… | CRITICAL 9.3EPSS 0.66% | 15 July 2026 |
| CVE-2026-61736 | Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist every origin for credentialed cross-origin requests. | CRITICAL 9.3EPSS 1.42% | 15 July 2026 |
| CVE-2026-42533 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. | CRITICAL 9.2EPSS 4.45% | 15 July 2026 |
| CVE-2026-61451 | The sanitizeHttpUrl() function only checks that the URL scheme is http/https and never verifies the host against the server's own origin, so an attacker can supply an arbitrary host. | CRITICAL 9.4EPSS 0.42% | 15 July 2026 |
| CVE-2026-56400 | open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. | CRITICAL 9.0EPSS 0.52% | 15 July 2026 |
| CVE-2026-13385 | An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. | CRITICAL 9.5EPSS 0.14% | 15 July 2026 |
| CVE-2026-5270 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. | CRITICAL 9.8EPSS 0.66% | 14 July 2026 |
| CVE-2026-5269 | While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the… | CRITICAL 9.8EPSS 0.48% | 14 July 2026 |
| CVE-2026-51808 | Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in… | CRITICAL 9.8EPSS 0.85% | 14 July 2026 |
| CVE-2026-51807 | Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to j2k_codeblock::pass_length[128]. | CRITICAL 9.8EPSS 0.67% | 14 July 2026 |
| CVE-2026-48334 | Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. | CRITICAL 9.3EPSS 0.40% | 14 July 2026 |
| CVE-2026-45363 | Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC… | CRITICAL 9.1EPSS 0.26% | 14 July 2026 |
| CVE-2026-38450 | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function | CRITICAL 9.8EPSS 1.14% | 14 July 2026 |
| CVE-2026-53486 | The decompress package for Node.js extracts archives. | CRITICAL 9.1EPSS 0.75% | 14 July 2026 |
| CVE-2026-52101 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go | CRITICAL 9.1EPSS 0.55% | 14 July 2026 |
| CVE-2026-48327 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.0EPSS 0.41% | 14 July 2026 |
| CVE-2026-48325 | ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.3EPSS 0.55% | 14 July 2026 |
| CVE-2026-48324 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.1EPSS 1.44% | 14 July 2026 |
| CVE-2026-48322 | ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.9EPSS 1.17% | 14 July 2026 |
| CVE-2026-48321 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. | CRITICAL 9.3EPSS 0.47% | 14 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.