Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,914 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,282 results · page 90 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-54843 | Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. | CRITICAL 9.3EPSS 0.40% | 25 June 2026 |
| CVE-2026-54836 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. | CRITICAL 9.3EPSS 1.34% | 25 June 2026 |
| CVE-2026-54823 | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. | CRITICAL 9.9EPSS 0.79% | 25 June 2026 |
| CVE-2026-41120 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. | CRITICAL 9.8EPSS 0.39% | 25 June 2026 |
| CVE-2026-53260 | In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). syzbot reported a weird reqsk->rsk_refcnt underflow in __inet_csk_reqsk_queue_drop(). | CRITICAL 9.8EPSS 0.37% | 25 June 2026 |
| CVE-2026-53247 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown mtk_free_dev() calls metadata_dst_free() which frees the metadata_dst with kfree() immediately, bypassing the RCU… | CRITICAL 9.8EPSS 0.47% | 25 June 2026 |
| CVE-2026-53246 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a listening SCTP server processes a COOKIE_ECHO chunk, the cached peer INIT chunk embedded after the cookie… | CRITICAL 9.8EPSS 0.44% | 25 June 2026 |
| CVE-2026-53228 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function entry and continues using it after iptunnel_handle_offloads(). | CRITICAL 9.8EPSS 0.51% | 25 June 2026 |
| CVE-2026-53225 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header,… | CRITICAL 9.1EPSS 0.51% | 25 June 2026 |
| CVE-2026-53224 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpack_cookie() only checked that the embedded INIT chunk length did not exceed the remaining cookie payload,… | CRITICAL 9.1EPSS 0.52% | 25 June 2026 |
| CVE-2026-53221 | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(), when an exact match for a tunnel fails, the code falls back to searching for wildcard tunnels: -… | CRITICAL 9.8EPSS 0.51% | 25 June 2026 |
| CVE-2026-53216 | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM pools, and short pool buffers can be smaller than PAGE_SIZE. | CRITICAL 9.8EPSS 0.50% | 25 June 2026 |
| CVE-2026-53215 | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns the current descriptor buffer to the hardware BM pool. | CRITICAL 9.8EPSS 0.50% | 25 June 2026 |
| CVE-2026-53186 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() copies sense data from rsp->data + resp_data_len, where resp_data_len is the full 32-bit value supplied by… | CRITICAL 9.1EPSS 0.51% | 25 June 2026 |
| CVE-2026-53176 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length as wc->byte_len… | CRITICAL 9.8EPSS 0.76% | 25 June 2026 |
| CVE-2026-53175 | In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns teardown, fqdir_pre_exit() walks the fqdir rhashtable and flushes every fragment queue that is not yet… | CRITICAL 9.8EPSS 0.31% | 25 June 2026 |
| CVE-2026-53151 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modification of the received skbuff in rxrpc_input_soft_acks() and a potential incorrect access of the buffer in a… | CRITICAL 9.8EPSS 0.46% | 25 June 2026 |
| CVE-2026-53131 | In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslog` access… | CRITICAL 9.4EPSS 0.43% | 25 June 2026 |
| CVE-2026-46752 | Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. | CRITICAL 10.0EPSS 0.48% | 25 June 2026 |
| CVE-2026-41566 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. | CRITICAL 9.4EPSS 0.36% | 25 June 2026 |
| CVE-2026-8666 | OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to… | CRITICAL 9.8EPSS 1.20% | 25 June 2026 |
| CVE-2026-8665 | OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command… | CRITICAL 9.8EPSS 1.20% | 25 June 2026 |
| CVE-2026-8660 | OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands. | CRITICAL 9.8EPSS 1.20% | 25 June 2026 |
| CVE-2026-8592 | OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the… | CRITICAL 9.8EPSS 1.20% | 25 June 2026 |
| CVE-2026-39955 | Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. | CRITICAL 9.8EPSS 0.58% | 24 June 2026 |
| CVE-2026-39948 | Because the unbalanced-quote payload bypasses the regex validation that would otherwise reject it, an unauthenticated attacker can inject arbitrary SQL to compromise the confidentiality, integrity, and availability of the database. | CRITICAL 9.3EPSS 0.85% | 24 June 2026 |
| CVE-2026-39938 | Cacti is an open source performance and fault management framework. | CRITICAL 9.8EPSS 0.69% | 24 June 2026 |
| CVE-2026-55666 | If the JWT does not contain an email address, the application falls back to accepting an arbitrary email value supplied directly in the request. | CRITICAL 9.3EPSS 0.41% | 24 June 2026 |
| CVE-2026-55570 | Because the attribute is single-quoted and the value is produced with JSON.stringify() (which does not escape ', <, or >), a package whose name contains a single quote breaks out of the attribute and injects arbitrary HTML. | CRITICAL 9.0EPSS 0.62% | 24 June 2026 |
| CVE-2026-55454 | While this listener is not directly published to the host by docker-compose.yml, it is reachable from the Appsmith server process itself or a SSRF vulnerability. | CRITICAL 9.9EPSS 0.60% | 24 June 2026 |
| CVE-2026-54158 | A cell value like </textarea><img src=x onerror="..."> or "><img src=x onerror="..."> breaks out of its surrounding tag and runs arbitrary JavaScript in the renderer when the victim opens the block-attribute panel. | CRITICAL 9.9EPSS 0.51% | 24 June 2026 |
| CVE-2026-54069 | Combined with the default empty AccessAuthCode on desktop installs, any Chrome/Chromium extension -- including a compromised legitimate extension via supply chain attack -- can make fully authenticated admin API calls to the SiYuan kernel at… | CRITICAL 9.2EPSS 0.58% | 24 June 2026 |
| CVE-2026-54067 | A payload like runs arbitrary JavaScript in the renderer. | CRITICAL 9.9EPSS 0.54% | 24 June 2026 |
| CVE-2026-50551 | Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. | CRITICAL 9.9EPSS 0.78% | 24 June 2026 |
| CVE-2026-39893 | Cacti is an open source performance and fault management framework. | CRITICAL 9.8EPSS 0.67% | 24 June 2026 |
| CVE-2026-52813 | Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. | CRITICAL 10.0EPSS 1.11% | 24 June 2026 |
| CVE-2026-52811 | An attacker with repo-write access plus a multipart upload whose filename contains a literal backslash (preserved by filepath.Base on Linux, then converted to / by pathx.Clean) redirects the write through a previously-committed directory symlink.… | CRITICAL 9.0EPSS 0.47% | 24 June 2026 |
| CVE-2026-52806 | Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before… | CRITICAL 9.9EPSS 7.93% | 24 June 2026 |
| CVE-2026-46423 | Because provider registration only gates on the SAML "enabled" toggle and not on the presence of a certificate, an administrator who enables SAML without pasting an IdP certificate obtains a fully wired, publicly reachable SAML login endpoint that… | CRITICAL 9.3EPSS 0.22% | 24 June 2026 |
| CVE-2026-45689 | Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbitrary user by sending a single HTTP POST with MongoDB query operators to /oauth/token. | CRITICAL 9.1EPSS 0.53% | 24 June 2026 |
| CVE-2026-45688 | TypeScript's string parameter annotation is erased at runtime, so an unauthenticated attacker can substitute a MongoDB query operator ({"$gt": ""}, {"$ne": null}, etc.) for what the server expects to be an opaque ticket string. | CRITICAL 9.1EPSS 0.49% | 24 June 2026 |
| CVE-2026-33543 | Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial administrator bootstrap. | CRITICAL 9.3EPSS 0.45% | 24 June 2026 |
| CVE-2026-53943 | In affected cache configurations, that response could be stored and served to subsequent visitors requesting the same page, allowing cache poisoning of request-specific preview output. | CRITICAL 9.6EPSS 0.45% | 24 June 2026 |
| CVE-2026-49980 | From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. | CRITICAL 9.8EPSS 0.74% | 24 June 2026 |
| CVE-2026-13032 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 24 June 2026 |
| CVE-2026-13028 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 24 June 2026 |
| CVE-2026-53088 | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the next open tx_cb. | CRITICAL 9.8EPSS 0.40% | 24 June 2026 |
| CVE-2026-53086 | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler tries to take down all tx queues when a single queue times out. | CRITICAL 9.8EPSS 0.30% | 24 June 2026 |
| CVE-2026-53055 | In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-free for sec During packet transmission, if the system is under heavy load, the hardware might complete processing the packet and free… | CRITICAL 9.8EPSS 0.43% | 24 June 2026 |
| CVE-2026-53049 | In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding… | CRITICAL 9.8EPSS 0.39% | 24 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.