Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,255 results · page 83 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-4375 | The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org… | CRITICAL 9.0EPSS 0.42% | 7 July 2026 |
| CVE-2026-14345 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. | CRITICAL 9.8EPSS 1.39% | 7 July 2026 |
| CVE-2026-12375 | The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants… | CRITICAL 9.8EPSS 0.55% | 7 July 2026 |
| CVE-2026-34048 | Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. | CRITICAL 9.9EPSS 0.80% | 7 July 2026 |
| CVE-2026-34047 | Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware, allowing an authenticated user to access terminal functionality for resources outside the authorized scope and potentially execute… | CRITICAL 9.9EPSS 0.71% | 7 July 2026 |
| CVE-2026-34037 | Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups, allowing an authenticated user to clone resources into destinations owned… | CRITICAL 9.9EPSS 0.44% | 7 July 2026 |
| CVE-2026-57572 | An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's runtime user. | CRITICAL 10.0EPSS 0.94% | 6 July 2026 |
| CVE-2026-57571 | Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. | CRITICAL 9.6EPSS 0.81% | 6 July 2026 |
| CVE-2026-42341 | Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. | CRITICAL 9.2EPSS 0.27% | 6 July 2026 |
| CVE-2026-34038 | Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through… | CRITICAL 9.9EPSS 2.54% | 6 July 2026 |
| CVE-2026-11405 | The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification… | CRITICAL 9.8EPSS 0.77% | 6 July 2026 |
| CVE-2026-9182 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. | CRITICAL 9.8EPSS 0.62% | 6 July 2026 |
| CVE-2026-48614 | An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server. | CRITICAL 9.9EPSS 0.58% | 6 July 2026 |
| CVE-2026-48316 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 10.0EPSS 1.13% | 6 July 2026 |
| CVE-2026-40139 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. | CRITICAL 9.2EPSS 0.75% | 6 July 2026 |
| CVE-2026-40138 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. | CRITICAL 9.2EPSS 0.46% | 6 July 2026 |
| CVE-2026-5268 | An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. | CRITICAL 9.1EPSS 0.66% | 6 July 2026 |
| CVE-2025-53830 | Versions of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSRF). | CRITICAL 9.1EPSS 0.46% | 6 July 2026 |
| CVE-2025-53827 | In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. | CRITICAL 9.1EPSS 0.61% | 6 July 2026 |
| CVE-2026-6900 | Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. | CRITICAL 9.1EPSS 0.22% | 6 July 2026 |
| CVE-2026-12686 | An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted within the same subdomain environment. | CRITICAL 9.3EPSS 0.37% | 6 July 2026 |
| CVE-2026-56140 | Improper Input Validation vulnerability in Apache Camel AWS SNS component. | CRITICAL 9.8EPSS 0.74% | 6 July 2026 |
| CVE-2026-53913 | Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. | CRITICAL 9.8EPSS 1.08% | 6 July 2026 |
| CVE-2026-48205 | Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. | CRITICAL 9.1EPSS 0.60% | 6 July 2026 |
| CVE-2026-48204 | Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. | CRITICAL 9.8EPSS 0.73% | 6 July 2026 |
| CVE-2026-48203 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel Solr component. | CRITICAL 9.1EPSS 0.60% | 6 July 2026 |
| CVE-2026-46456 | Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. | CRITICAL 9.8EPSS 0.79% | 6 July 2026 |
| CVE-2026-46455 | Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. | CRITICAL 9.8EPSS 0.69% | 6 July 2026 |
| CVE-2026-46454 | Improper Input Validation vulnerability in Apache Camel Cometd Component. | CRITICAL 9.8EPSS 0.83% | 6 July 2026 |
| CVE-2026-43867 | Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. | CRITICAL 9.8EPSS 0.93% | 6 July 2026 |
| CVE-2026-40047 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. | CRITICAL 9.1EPSS 2.43% | 6 July 2026 |
| CVE-2026-24014 | If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. | CRITICAL 9.8EPSS 0.69% | 6 July 2026 |
| CVE-2026-24013 | Authentication Bypass by Spoofing vulnerability in Apache IoTDB. | CRITICAL 9.1EPSS 0.64% | 6 July 2026 |
| CVE-2026-6382 | The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a… | CRITICAL 9.1EPSS 1.40% | 6 July 2026 |
| CVE-2026-14808 | Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password. | CRITICAL 9.3EPSS 0.69% | 6 July 2026 |
| CVE-2026-14807 | ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password. | CRITICAL 9.3EPSS 0.63% | 6 July 2026 |
| CVE-2026-59509 | An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. | CRITICAL 9.2EPSS 1.43% | 5 July 2026 |
| CVE-2026-14535 | In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. | CRITICAL 9.8EPSS 0.56% | 4 July 2026 |
| CVE-2026-58426 | Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write | CRITICAL 9.6EPSS 0.30% | 3 July 2026 |
| CVE-2026-58422 | Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts | CRITICAL 9.8EPSS 0.62% | 3 July 2026 |
| CVE-2026-57983 | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | CRITICAL 10.0EPSS 0.65% | 3 July 2026 |
| CVE-2026-27780 | Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks. | CRITICAL 9.8EPSS 0.64% | 3 July 2026 |
| CVE-2026-26292 | Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests. | CRITICAL 9.8EPSS 0.65% | 3 July 2026 |
| CVE-2026-26247 | Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check. | CRITICAL 9.1EPSS 0.50% | 3 July 2026 |
| CVE-2026-26232 | Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange. | CRITICAL 9.1EPSS 0.50% | 3 July 2026 |
| CVE-2026-25718 | Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths. | CRITICAL 9.1EPSS 0.56% | 3 July 2026 |
| CVE-2026-22874 | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. | CRITICAL 9.6EPSS 0.46% | 3 July 2026 |
| CVE-2026-22547 | Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values. | CRITICAL 9.1EPSS 0.52% | 3 July 2026 |
| CVE-2026-20896 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. | CRITICAL 9.8EPSS 2.76% | 3 July 2026 |
| CVE-2026-20706 | Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint. | CRITICAL 9.1EPSS 0.56% | 3 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.