Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,276 results · page 88 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-48281 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 10.0EPSS 1.42% | 30 June 2026 |
| CVE-2026-48277 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 10.0EPSS 1.29% | 30 June 2026 |
| CVE-2026-48276 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 10.0EPSS 1.26% | 30 June 2026 |
| CVE-2026-14241 | Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. | CRITICAL 9.8EPSS 0.43% | 30 June 2026 |
| CVE-2026-6556 | Applications that use path-scoped middleware for authentication, authorization, rate limiting, or auditing on routes inside a prefixed scope can be bypassed by sending a request to the prefixed route, because Fastify still matches the route but the… | CRITICAL 9.1EPSS 0.52% | 30 June 2026 |
| CVE-2026-58116 | LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. | CRITICAL 9.3EPSS 0.90% | 30 June 2026 |
| CVE-2026-58016 | This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service. | CRITICAL 9.1EPSS 0.55% | 30 June 2026 |
| CVE-2026-44946 | A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3, | CRITICAL 9.5EPSS 0.39% | 30 June 2026 |
| CVE-2026-8402 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. | CRITICAL 9.8EPSS 0.47% | 30 June 2026 |
| CVE-2026-53690 | An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. | CRITICAL 9.3EPSS 0.51% | 30 June 2026 |
| CVE-2026-14162 | Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation. | CRITICAL 9.3EPSS 0.63% | 30 June 2026 |
| CVE-2026-13766 | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. | CRITICAL 9.8EPSS 0.55% | 30 June 2026 |
| CVE-2026-9711 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter… | CRITICAL 9.8EPSS 0.54% | 30 June 2026 |
| CVE-2026-12076 | Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline. | CRITICAL 9.3EPSS 0.53% | 30 June 2026 |
| CVE-2026-12819 | Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated interaction with security-sensitive PLC functions. | CRITICAL 9.3EPSS 0.54% | 30 June 2026 |
| CVE-2026-12818 | Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service. | CRITICAL 9.3EPSS 0.43% | 30 June 2026 |
| CVE-2026-12073 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. | CRITICAL 9.8EPSS 0.53% | 30 June 2026 |
| CVE-2026-55276 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. | CRITICAL 9.1EPSS 0.56% | 29 June 2026 |
| CVE-2026-53434 | Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. | CRITICAL 9.1EPSS 0.59% | 29 June 2026 |
| CVE-2026-57498 | However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parameters without any team ownership validation, allowing cross-team resource deployment. | CRITICAL 9.6EPSS 0.38% | 29 June 2026 |
| CVE-2026-39868 | An app may be able to cause unexpected system termination or corrupt kernel memory. | CRITICAL 9.1EPSS 1.21% | 29 June 2026 |
| CVE-2026-37637 | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component | CRITICAL 9.1EPSS 0.66% | 29 June 2026 |
| CVE-2026-56782 | Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. | CRITICAL 9.3EPSS 3.56% | 29 June 2026 |
| CVE-2026-11720 | A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. | CRITICAL 9.3EPSS 0.53% | 29 June 2026 |
| CVE-2026-13751 | Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. | CRITICAL 9.6EPSS 0.20% | 29 June 2026 |
| CVE-2026-41052 | Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10. | CRITICAL 9.4EPSS 0.42% | 29 June 2026 |
| CVE-2026-57331 | Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. | CRITICAL 9.9EPSS 0.55% | 29 June 2026 |
| CVE-2026-56290 | Joomlack Page Builder Improper Access Control Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 30.9% | 29 June 2026 |
| CVE-2026-58053 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options… | CRITICAL 9.4EPSS 0.44% | 28 June 2026 |
| CVE-2026-12415 | The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. | CRITICAL 9.8EPSS 0.80% | 27 June 2026 |
| CVE-2026-31928 | The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. | CRITICAL 9.3EPSS 0.57% | 26 June 2026 |
| CVE-2026-28701 | Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths. | CRITICAL 9.3EPSS 0.68% | 26 June 2026 |
| CVE-2026-53576 | Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addresses its… | CRITICAL 10.0EPSS 3.19% | 26 June 2026 |
| CVE-2026-49869 | Kestra OSS OS Command Injection Vulnerability | KEVCRITICAL 10.0EPSS 1.92% | 26 June 2026 |
| CVE-2026-54352 | This vulnerability is fixed in 3.39.9. | CRITICAL 9.6EPSS 0.49% | 26 June 2026 |
| CVE-2026-54351 | Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters. | CRITICAL 9.6EPSS 0.46% | 26 June 2026 |
| CVE-2026-54350 | A parameter value containing a closing quote and additional keys lifts attacker-controlled fields into the parsed filter object. | CRITICAL 9.8EPSS 0.54% | 26 June 2026 |
| CVE-2026-53309 | In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs-remote region comparison loop uses '<=' instead of '<', causing it to read one entry past the valid range… | CRITICAL 9.8EPSS 0.40% | 26 June 2026 |
| CVE-2026-52785 | Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. | CRITICAL 9.9EPSS 0.38% | 26 June 2026 |
| CVE-2026-52782 | Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources. | CRITICAL 9.9EPSS 0.45% | 26 June 2026 |
| CVE-2026-52780 | Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (RCE). | CRITICAL 9.6EPSS 0.39% | 26 June 2026 |
| CVE-2026-46386 | Combined with cookies_serializer = :marshal, this gives any logged-in user a deterministic Marshal-deserialization path reachable via the /my/two_factor_devices cookie reader This vulnerability is fixed in . | CRITICAL 9.9EPSS 0.49% | 26 June 2026 |
| CVE-2026-33646 | Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. | CRITICAL 9.6EPSS 0.69% | 26 June 2026 |
| CVE-2026-54636 | An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. | CRITICAL 9.9EPSS 0.53% | 26 June 2026 |
| CVE-2026-45408 | When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an unquoted heredoc (<<EOF instead of <<'EOF') in fn-git-create-hook() at plugins/git/internal-functions:378. | CRITICAL 9.0EPSS 0.42% | 26 June 2026 |
| CVE-2026-12411 | Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when… | CRITICAL 9.6EPSS 0.29% | 26 June 2026 |
| CVE-2026-0685 | Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions. | CRITICAL 9.8EPSS 0.93% | 26 June 2026 |
| CVE-2025-11919 | The `-init` file for the the JVM initialization exists in the vulnerable directory during the startup of the JVM. | CRITICAL 9.6EPSS 0.41% | 26 June 2026 |
| CVE-2026-57658 | Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. | CRITICAL 9.1EPSS 0.50% | 26 June 2026 |
| CVE-2026-56070 | Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. | CRITICAL 9.3EPSS 0.40% | 26 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.