Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,255 results · page 79 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-49798 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | CRITICAL 9.3EPSS 0.36% | 14 July 2026 |
| CVE-2026-49181 | Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 9.8EPSS 1.17% | 14 July 2026 |
| CVE-2026-49172 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.97% | 14 July 2026 |
| CVE-2026-49164 | Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.79% | 14 July 2026 |
| CVE-2026-48561 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | CRITICAL 9.6EPSS 0.86% | 14 July 2026 |
| CVE-2026-42990 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.97% | 14 July 2026 |
| CVE-2026-62644 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover. | CRITICAL 9.8EPSS 0.50% | 14 July 2026 |
| CVE-2026-62643 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. | CRITICAL 10.0EPSS 0.25% | 14 July 2026 |
| CVE-2026-60082 | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. | CRITICAL 9.1EPSS 0.39% | 14 July 2026 |
| CVE-2026-59836 | A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here> | CRITICAL 9.8EPSS 0.22% | 14 July 2026 |
| CVE-2026-55954 | Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. | CRITICAL 9.1EPSS 0.70% | 14 July 2026 |
| CVE-2025-11698 | A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. | CRITICAL 9.2EPSS 0.43% | 14 July 2026 |
| CVE-2026-58479 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands… | CRITICAL 9.2EPSS 4.40% | 14 July 2026 |
| CVE-2026-15265 | A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution. | CRITICAL 9.4EPSS 0.56% | 14 July 2026 |
| CVE-2026-10672 | The Firmware-Update object stores the server-supplied Package URI (/5/0/1) in a 255-byte buffer, so a LwM2M management server (or an on-path attacker on a session lacking strong DTLS) can WRITE a URI of 128-254 characters; only the first 128 bytes are… | CRITICAL 9.1EPSS 0.40% | 14 July 2026 |
| CVE-2025-12012 | A denial-of-service issue exists in 5380/5480/5580 controllers. | CRITICAL 9.2EPSS 0.43% | 14 July 2026 |
| CVE-2025-12011 | A denial-of-service issue exists in 5370/5570 controllers. | CRITICAL 9.2EPSS 0.43% | 14 July 2026 |
| CVE-2026-62392 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. | CRITICAL 9.8EPSS 2.48% | 14 July 2026 |
| CVE-2026-62390 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. | CRITICAL 9.8EPSS 0.69% | 14 July 2026 |
| CVE-2026-10577 | The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. | CRITICAL 10.0EPSS 0.41% | 14 July 2026 |
| CVE-2026-62422 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | CRITICAL 9.8EPSS 0.33% | 14 July 2026 |
| CVE-2026-58319 | An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. | CRITICAL 9.1EPSS 0.75% | 14 July 2026 |
| CVE-2026-56451 | A vulnerability has been identified in Opcenter X (All versions < V2604). | CRITICAL 10.0EPSS 0.50% | 14 July 2026 |
| CVE-2026-15043 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. | CRITICAL 9.8EPSS 0.39% | 14 July 2026 |
| CVE-2026-59084 | Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. | CRITICAL 9.1EPSS 0.51% | 14 July 2026 |
| CVE-2026-59083 | Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. | CRITICAL 9.1EPSS 0.37% | 14 July 2026 |
| CVE-2026-57898 | In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. | CRITICAL 9.0EPSS 0.68% | 14 July 2026 |
| CVE-2026-15183 | Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY… | CRITICAL 9.2EPSS 0.31% | 14 July 2026 |
| CVE-2026-11563 | The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary… | CRITICAL 9.6EPSS 0.25% | 14 July 2026 |
| CVE-2026-44761 | If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. | CRITICAL 9.1EPSS 0.50% | 14 July 2026 |
| CVE-2026-44747 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. | CRITICAL 9.9EPSS 0.56% | 14 July 2026 |
| CVE-2026-27690 | Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. | CRITICAL 9.1EPSS 0.68% | 14 July 2026 |
| CVE-2026-58102 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. | CRITICAL 9.1EPSS 0.34% | 13 July 2026 |
| CVE-2026-62327 | 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the… | CRITICAL 9.3EPSS 0.64% | 13 July 2026 |
| CVE-2026-59801 | 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the… | CRITICAL 9.3EPSS 2.91% | 13 July 2026 |
| CVE-2026-52533 | An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file | CRITICAL 9.8EPSS 0.60% | 13 July 2026 |
| CVE-2026-51821 | SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint | CRITICAL 9.8EPSS 0.77% | 13 July 2026 |
| CVE-2026-51541 | OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. | CRITICAL 9.1EPSS 0.42% | 13 July 2026 |
| CVE-2026-51540 | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData). | CRITICAL 9.8EPSS 0.42% | 13 July 2026 |
| CVE-2026-51538 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. | CRITICAL 9.1EPSS 0.39% | 13 July 2026 |
| CVE-2026-51537 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. | CRITICAL 9.1EPSS 0.48% | 13 July 2026 |
| CVE-2026-51536 | If a maliciously crafted packet with specific length fields is processed, the length parameter can overflow or be truncated into a negative value. | CRITICAL 9.1EPSS 0.49% | 13 July 2026 |
| CVE-2026-58409 | Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a malicious plugin ZIP archive containing a PHP webshell. | CRITICAL 9.1EPSS 0.76% | 13 July 2026 |
| CVE-2026-6875 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. | CRITICAL 9.5EPSS 77.6% | 13 July 2026 |
| CVE-2026-61500 | Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. | CRITICAL 9.3EPSS 0.86% | 13 July 2026 |
| CVE-2026-61462 | mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. | CRITICAL 9.2EPSS 0.51% | 13 July 2026 |
| CVE-2026-57433 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. | CRITICAL 9.8EPSS 0.36% | 13 July 2026 |
| CVE-2026-13221 | A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. | CRITICAL 9.1EPSS 0.43% | 13 July 2026 |
| CVE-2026-6847 | Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. | CRITICAL 9.3EPSS 0.88% | 13 July 2026 |
| CVE-2026-61498 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start,… | CRITICAL 9.3EPSS 4.09% | 13 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.