Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,276 results · page 85 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-54408 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming. | CRITICAL 9.8EPSS 0.57% | 2 July 2026 |
| CVE-2026-54400 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | CRITICAL 9.1EPSS 0.52% | 2 July 2026 |
| CVE-2026-50748 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | CRITICAL 9.9EPSS 1.63% | 2 July 2026 |
| CVE-2026-50747 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. | CRITICAL 9.9EPSS 0.49% | 2 July 2026 |
| CVE-2026-50746 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. | CRITICAL 10.0EPSS 1.69% | 2 July 2026 |
| CVE-2026-4767 | Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. | CRITICAL 9.8EPSS 0.61% | 2 July 2026 |
| CVE-2026-5524 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. | CRITICAL 9.8EPSS 3.48% | 2 July 2026 |
| CVE-2026-57683 | Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. | CRITICAL 9.3EPSS 0.40% | 2 July 2026 |
| CVE-2026-57679 | Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions. | CRITICAL 9.3EPSS 0.40% | 2 July 2026 |
| CVE-2026-57677 | Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. | CRITICAL 9.8EPSS 0.56% | 2 July 2026 |
| CVE-2026-57625 | Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions. | CRITICAL 9.6EPSS 0.45% | 2 July 2026 |
| CVE-2026-57624 | Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. | CRITICAL 10.0EPSS 0.86% | 2 July 2026 |
| CVE-2026-57623 | Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | CRITICAL 9.0EPSS 0.53% | 2 July 2026 |
| CVE-2026-57621 | Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. | CRITICAL 9.8EPSS 0.56% | 2 July 2026 |
| CVE-2026-27436 | Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. | CRITICAL 9.1EPSS 0.66% | 2 July 2026 |
| CVE-2026-27419 | Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. | CRITICAL 9.9EPSS 0.48% | 2 July 2026 |
| CVE-2026-14439 | A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. | CRITICAL 9.4EPSS 0.71% | 1 July 2026 |
| CVE-2026-14425 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14424 | Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14423 | Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.38% | 1 July 2026 |
| CVE-2026-14420 | Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14419 | Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14417 | Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14416 | Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14411 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14405 | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.50% | 1 July 2026 |
| CVE-2026-14398 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14397 | Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14392 | Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14390 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14387 | Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-14382 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 1 July 2026 |
| CVE-2026-52186 | SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc component | CRITICAL 9.8EPSS 0.77% | 1 July 2026 |
| CVE-2026-58457 | Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the… | CRITICAL 9.3EPSS 2.94% | 1 July 2026 |
| CVE-2026-51947 | An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the… | CRITICAL 9.8EPSS 1.07% | 1 July 2026 |
| CVE-2026-50160 | In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment. | CRITICAL 10.0EPSS 1.70% | 1 July 2026 |
| CVE-2026-58453 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin username with an empty password accepted by… | CRITICAL 9.3EPSS 1.90% | 1 July 2026 |
| CVE-2026-34117 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34116 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34115 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34114 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34113 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34112 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34111 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34110 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34109 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34108 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34107 | An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34106 | An unauthenticated remote attacker can append shell metacharacters to the id parameter to execute arbitrary OS commands on the server. | CRITICAL 9.3EPSS 0.93% | 1 July 2026 |
| CVE-2026-34099 | An unauthenticated attacker can perform error-based SQL injection to extract the database version, current user, schema names, and table contents. | CRITICAL 9.3EPSS 0.63% | 1 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.