Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,238 results · page 9 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-91998 | Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. | CRITICAL 9.4EPSS 0.42% | 15 September 2026 |
| CVE-2026-91995 | pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. | CRITICAL 9.3EPSS 0.61% | 15 September 2026 |
| CVE-2026-89308 | An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution. | CRITICAL 9.3EPSS 2.97% | 15 September 2026 |
| CVE-2026-57148 | An unauthenticated attacker can sign a JWT containing an attacker-chosen sub value, and AuthService._verify_token() accepts it as an authenticated identity, enabling user or workspace-owner impersonation when a target identifier is known. | CRITICAL 9.8EPSS 0.37% | 15 September 2026 |
| CVE-2026-57147 | A remote unauthenticated attacker can mint an HS256 token with an arbitrary sub and email, and the platform's AuthService._verify_token() and get_current_user dependency accept the forged identity for protected API routes. | CRITICAL 9.8EPSS 0.77% | 15 September 2026 |
| CVE-2026-57141 | Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklist can be bypassed with Function('return this')() to… | CRITICAL 9.8EPSS 0.53% | 15 September 2026 |
| CVE-2026-57140 | A remote caller who can reach the service can obtain agent names, roles, and instruction prefixes and can invoke a selected agent, potentially reaching its tools, memory, external APIs, credentials, and workflow state. | CRITICAL 9.4EPSS 0.37% | 15 September 2026 |
| CVE-2026-57139 | Any network client that can reach the port can call tools/list, tools/call, resources/read, or prompts/get, causing registered handlers to run with server-side credentials and process privileges or disclose registered data. | CRITICAL 9.8EPSS 0.42% | 15 September 2026 |
| CVE-2026-57138 | From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require properties. | CRITICAL 9.9EPSS 0.39% | 15 September 2026 |
| CVE-2026-52824 | An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge… | CRITICAL 9.1EPSS 2.06% | 15 September 2026 |
| CVE-2026-62379 | Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements… | CRITICAL 9.8EPSS 0.65% | 15 September 2026 |
| CVE-2026-62263 | Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an AuthenticatorImpl root object. | CRITICAL 9.2EPSS 0.55% | 15 September 2026 |
| CVE-2026-48717 | Because that setting is disabled by default, an attacker who intercepts a PKCE-protected authorization code can omit code_verifier and redeem the code, while an explicitly incorrect verifier is rejected. | CRITICAL 9.1EPSS 0.33% | 15 September 2026 |
| CVE-2026-46619 | Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows all traffic. | CRITICAL 9.3EPSS 0.58% | 15 September 2026 |
| CVE-2026-45052 | Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the shared root-realm Discovery branch. | CRITICAL 9.3EPSS 0.33% | 15 September 2026 |
| CVE-2026-45051 | Exploitation requires the WebAuthn flow to be reachable and an attacker to have previously written controlled data to that attribute through delegated administration, provisioning, directory access, legacy REST self-registration, or unsafe configuration. | CRITICAL 9.2EPSS 0.51% | 15 September 2026 |
| CVE-2026-90711 | Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit… | CRITICAL 9.1EPSS 0.19% | 15 September 2026 |
| CVE-2026-12944 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. | CRITICAL 9.6EPSS 0.25% | 14 September 2026 |
| CVE-2026-86881 | An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages. | CRITICAL 9.1EPSS 0.31% | 14 September 2026 |
| CVE-2026-84625 | A permissions issue was addressed with additional sandbox restrictions. | CRITICAL 9.1EPSS 0.35% | 14 September 2026 |
| CVE-2026-84609 | A permissions issue was addressed with improved path validation. | CRITICAL 9.8EPSS 0.61% | 14 September 2026 |
| CVE-2026-84561 | An app may be able to cause unexpected system termination or corrupt kernel memory. | CRITICAL 9.8EPSS 0.65% | 14 September 2026 |
| CVE-2026-84520 | A buffer overflow was addressed with improved size validation. | CRITICAL 9.8EPSS 0.33% | 14 September 2026 |
| CVE-2026-67399 | Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code. | CRITICAL 9.3EPSS 0.69% | 14 September 2026 |
| CVE-2026-65414 | An out-of-bounds write issue was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.99% | 14 September 2026 |
| CVE-2026-65381 | A malicious app may be able to break out of its sandbox. | CRITICAL 10.0EPSS 0.34% | 14 September 2026 |
| CVE-2026-53713 | Linux resolves a double-slash absolute path as the corresponding single-slash path, but the validator does not match the redundant-separator form, allowing submitted Lua to read arbitrary files from the gateway controller pod. | CRITICAL 9.1EPSS 0.41% | 14 September 2026 |
| CVE-2026-43790 | A remote attacker may be able to cause unexpected system termination or corrupt kernel memory. | CRITICAL 9.1EPSS 0.69% | 14 September 2026 |
| CVE-2026-55209 | In a network service that accepts untrusted GRDECL files, these conditions can cause a classic buffer overflow, out-of-bounds reads, invalid array access, NULL pointer dereference, memory corruption, or service termination. | CRITICAL 9.8EPSS 0.42% | 14 September 2026 |
| CVE-2026-54334 | The normal CompressedSection.process() to efi_compressor.TianoDecompress() to TianoDecompress() to DecodeC() to ReadCLen() parsing path therefore permits crafted Tiano or EFI compressed firmware to corrupt heap memory, deterministically crash the… | CRITICAL 9.8EPSS 0.43% | 14 September 2026 |
| CVE-2026-54333 | The resulting stack corruption deterministically crashes the parsing process and may permit code execution depending on build and runtime details. | CRITICAL 9.8EPSS 0.43% | 14 September 2026 |
| CVE-2026-50006 | A remote attacker can select any path writable by the Anyquery server process, cause SQLite to create a database file there, and place attacker-controlled table content in that file. | CRITICAL 9.1EPSS 0.77% | 14 September 2026 |
| CVE-2026-16338 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths. | CRITICAL 9.9EPSS 0.61% | 14 September 2026 |
| CVE-2026-59178 | Alternatively, do not expose the dashboard port to untrusted networks, and check the startup logs for the `WITHOUT AUTHENTICATION` banner to confirm whether a given instance is currently open. | CRITICAL 9.8EPSS 0.42% | 14 September 2026 |
| CVE-2026-90945 | Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. | CRITICAL 9.3EPSS 0.53% | 14 September 2026 |
| CVE-2026-90942 | Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. | CRITICAL 9.3EPSS 0.21% | 14 September 2026 |
| CVE-2026-57578 | Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewModelActionFilter.OnViewModelCreatedAsync, and… | CRITICAL 9.2EPSS 0.44% | 14 September 2026 |
| CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 2.01% | 14 September 2026 |
| CVE-2026-76443 | This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | CRITICAL 9.8EPSS 0.39% | 14 September 2026 |
| CVE-2026-76441 | This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | CRITICAL 9.8EPSS 0.49% | 14 September 2026 |
| CVE-2026-76440 | This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | CRITICAL 9.8EPSS 0.45% | 14 September 2026 |
| CVE-2026-20353 | This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | CRITICAL 9.8EPSS 0.40% | 14 September 2026 |
| CVE-2026-90943 | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. | CRITICAL 9.3EPSS 0.24% | 14 September 2026 |
| CVE-2026-61534 | Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-object lookup tables in src/yayson/store.ts and src/yayson/legacy-store.ts. | CRITICAL 9.1EPSS 0.78% | 14 September 2026 |
| CVE-2026-57145 | Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. | CRITICAL 9.1EPSS 0.36% | 14 September 2026 |
| CVE-2026-57131 | Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool capabilities to unauthorized agent execution. | CRITICAL 9.8EPSS 0.97% | 14 September 2026 |
| CVE-2026-57127 | Unauthenticated clients can then reach recipe execution, input, and output surfaces and may trigger connected tools despite the operator explicitly enabling authentication. | CRITICAL 9.8EPSS 0.90% | 14 September 2026 |
| CVE-2026-57124 | Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to StdioMCPClient to start a local process. | CRITICAL 9.8EPSS 0.64% | 14 September 2026 |
| CVE-2026-82435 | The attacker needs only TCP reachability to a worker port. | CRITICAL 9.8EPSS 0.61% | 14 September 2026 |
| CVE-2026-82434 | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. | CRITICAL 10.0EPSS 0.48% | 14 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.