Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,276 results · page 86 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-58127 | PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. | CRITICAL 9.3EPSS 1.88% | 1 July 2026 |
| CVE-2026-58126 | PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any… | CRITICAL 9.3EPSS 1.84% | 1 July 2026 |
| CVE-2026-57517 | Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. | CRITICAL 9.3EPSS 0.96% | 1 July 2026 |
| CVE-2026-24270 | NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. | CRITICAL 9.8EPSS 0.81% | 1 July 2026 |
| CVE-2025-23351 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. | CRITICAL 9.0EPSS 0.37% | 1 July 2026 |
| CVE-2025-23350 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. | CRITICAL 9.0EPSS 0.37% | 1 July 2026 |
| CVE-2025-15646 | HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. | CRITICAL 9.8EPSS 0.67% | 1 July 2026 |
| CVE-2026-23537 | A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. | CRITICAL 9.1EPSS 1.05% | 1 July 2026 |
| CVE-2026-57692 | Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. | CRITICAL 9.8EPSS 0.53% | 1 July 2026 |
| CVE-2026-53355 | In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts. | CRITICAL 9.8EPSS 0.42% | 1 July 2026 |
| CVE-2026-13603 | Our plugin pretix-oppwa did so insecurely by concatenating the parameter form the URL to the base domain of the API without further validation and, critically, without a / at the end of the baseUrl. | CRITICAL 9.0EPSS 0.41% | 1 July 2026 |
| CVE-2026-14198 | When middleware is used for authentication, authorization, rate limiting, or auditing on parameterized paths, an attacker can reach the protected handler by sending a single crafted URL with an encoded slash in the parameter position. | CRITICAL 9.1EPSS 0.52% | 1 July 2026 |
| CVE-2026-11387 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. | CRITICAL 9.8EPSS 2.21% | 1 July 2026 |
| CVE-2026-10539 | Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server. | CRITICAL 9.5EPSS 0.42% | 1 July 2026 |
| CVE-2026-7840 | UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. | CRITICAL 9.3EPSS 2.63% | 1 July 2026 |
| CVE-2026-7839 | UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. | CRITICAL 9.1EPSS 0.66% | 1 July 2026 |
| CVE-2026-6070 | The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. | CRITICAL 9.1EPSS 0.76% | 1 July 2026 |
| CVE-2026-53488 | This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. | CRITICAL 9.4EPSS 0.18% | 1 July 2026 |
| CVE-2026-56700 | Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. | CRITICAL 9.3EPSS 2.53% | 30 June 2026 |
| CVE-2026-56415 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. | CRITICAL 10.0EPSS 4.36% | 30 June 2026 |
| CVE-2026-56413 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. | CRITICAL 10.0EPSS 4.19% | 30 June 2026 |
| CVE-2026-56278 | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set… | CRITICAL 9.3EPSS 0.53% | 30 June 2026 |
| CVE-2026-56264 | Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security… | CRITICAL 9.2EPSS 0.49% | 30 June 2026 |
| CVE-2026-55721 | Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. | CRITICAL 9.2EPSS 0.55% | 30 June 2026 |
| CVE-2026-50110 | Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. | CRITICAL 9.3EPSS 0.18% | 30 June 2026 |
| CVE-2026-14152 | Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-14121 | Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. | CRITICAL 9.8EPSS 0.46% | 30 June 2026 |
| CVE-2026-14120 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-14113 | Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.31% | 30 June 2026 |
| CVE-2026-14109 | Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-14106 | Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-14104 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | CRITICAL 9.8EPSS 0.52% | 30 June 2026 |
| CVE-2026-14101 | Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 30 June 2026 |
| CVE-2026-14097 | Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 30 June 2026 |
| CVE-2026-14095 | Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 30 June 2026 |
| CVE-2026-14093 | Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 30 June 2026 |
| CVE-2026-14056 | Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. | CRITICAL 9.6EPSS 0.32% | 30 June 2026 |
| CVE-2026-14055 | Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-14044 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-14043 | Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-14038 | Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.3EPSS 0.33% | 30 June 2026 |
| CVE-2026-14037 | Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-14017 | Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-13934 | Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-13920 | Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-13909 | Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-13901 | Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 30 June 2026 |
| CVE-2026-13883 | Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 30 June 2026 |
| CVE-2026-13882 | Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.24% | 30 June 2026 |
| CVE-2026-13880 | Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.31% | 30 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.