Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,914 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,282 results · page 92 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-56258 | Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU) attacks on… | CRITICAL 9.2EPSS 0.91% | 23 June 2026 |
| CVE-2026-44089 | Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. | CRITICAL 9.4EPSS 0.31% | 23 June 2026 |
| CVE-2026-11374 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. | CRITICAL 9.0EPSS 2.52% | 23 June 2026 |
| CVE-2026-9733 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. | CRITICAL 9.1EPSS 0.52% | 23 June 2026 |
| CVE-2026-12866 | All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. | CRITICAL 9.2EPSS 0.87% | 23 June 2026 |
| CVE-2026-48746 | From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. | CRITICAL 9.1EPSS 1.15% | 22 June 2026 |
| CVE-2026-56266 | Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. | CRITICAL 9.2EPSS 0.48% | 22 June 2026 |
| CVE-2026-49468 | Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. | CRITICAL 9.5EPSS 0.82% | 22 June 2026 |
| CVE-2026-45034 | The result is that IOFactory::load($attackerPath) walks past the patch and still touches the phar wrapper. | CRITICAL 9.2EPSS 0.46% | 22 June 2026 |
| CVE-2026-44727 | Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel RCE. | CRITICAL 9.3EPSS 0.44% | 22 June 2026 |
| CVE-2026-12249 | An unauthenticated network attacker positioned between the managed Ubuntu host and the configured AD CS CA hostname can conduct a Man-in-the-Middle (MITM) attack. | CRITICAL 9.0EPSS 0.14% | 22 June 2026 |
| CVE-2026-10789 | A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. | CRITICAL 9.6EPSS 0.70% | 22 June 2026 |
| CVE-2026-9072 | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. | CRITICAL 9.8EPSS 0.72% | 22 June 2026 |
| CVE-2026-9006 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. | CRITICAL 9.1EPSS 0.39% | 22 June 2026 |
| CVE-2026-8646 | IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. | CRITICAL 9.1EPSS 0.59% | 22 June 2026 |
| CVE-2026-7664 | IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. | CRITICAL 9.8EPSS 0.50% | 22 June 2026 |
| CVE-2026-12628 | IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM)… | CRITICAL 9.1EPSS 0.63% | 22 June 2026 |
| CVE-2026-7166 | Vulnerability involving the exposure of sensitive data provided without adequate protection. | CRITICAL 9.2EPSS 0.54% | 22 June 2026 |
| CVE-2026-7165 | The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of other users’ information without requiring prior authorization validation. | CRITICAL 9.4EPSS 0.48% | 22 June 2026 |
| CVE-2026-56447 | MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. | CRITICAL 9.3EPSS 0.61% | 22 June 2026 |
| CVE-2026-56425 | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. | CRITICAL 9.3EPSS 0.46% | 22 June 2026 |
| CVE-2026-56423 | This allowed a sharing-group-capable user to hard-delete sharing groups owned by other organisations, bypassing the per-object ownership gate used by the single-object delete action. | CRITICAL 9.4EPSS 0.47% | 22 June 2026 |
| CVE-2026-10561 | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete… | CRITICAL 10.0EPSS 1.00% | 22 June 2026 |
| CVE-2026-56422 | Depending on the endpoint, this could allow object overwrite, object re-parenting, ownership transfer, unauthorized sharing-group scoping, event/object injection, proposal retargeting, or stored attacker-controlled content appearing in another user’s… | CRITICAL 9.4EPSS 0.60% | 22 June 2026 |
| CVE-2026-11373 | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. | CRITICAL 9.1EPSS 0.57% | 22 June 2026 |
| CVE-2026-11746 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. | CRITICAL 9.4EPSS 0.23% | 22 June 2026 |
| CVE-2026-56397 | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. | CRITICAL 9.4EPSS 0.70% | 21 June 2026 |
| CVE-2026-56265 | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. | CRITICAL 9.3EPSS 2.64% | 21 June 2026 |
| CVE-2026-56345 | AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. | CRITICAL 9.2EPSS 0.45% | 20 June 2026 |
| CVE-2026-5366 | Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. | CRITICAL 9.9EPSS 1.03% | 20 June 2026 |
| CVE-2024-58351 | Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction API. | CRITICAL 9.3EPSS 0.93% | 20 June 2026 |
| CVE-2022-50972 | WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. | CRITICAL 9.3EPSS 1.14% | 20 June 2026 |
| CVE-2019-25763 | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. | CRITICAL 9.3EPSS 0.80% | 20 June 2026 |
| CVE-2026-48939 | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 20.1% | 20 June 2026 |
| CVE-2026-48909 | SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server. | EXPLOITCRITICAL 9.5EPSS 4.94% | 20 June 2026 |
| CVE-2026-48908 | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | KEVCRITICAL 10.0EPSS 15.1% | 20 June 2026 |
| CVE-2026-9265 | Downstream callers run strlen() on the result and pass the inflated length to newSVpvn(), copying attacker-influenced adjacent heap bytes into a Perl scalar. | CRITICAL 9.1EPSS 0.63% | 20 June 2026 |
| CVE-2026-11551 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. | CRITICAL 9.8EPSS 0.62% | 20 June 2026 |
| CVE-2026-56081 | Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. | CRITICAL 9.3EPSS 0.57% | 19 June 2026 |
| CVE-2026-56073 | Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. | CRITICAL 9.3EPSS 0.27% | 19 June 2026 |
| CVE-2026-48582 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.6EPSS 0.69% | 19 June 2026 |
| CVE-2026-45480 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | CRITICAL 10.0EPSS 0.90% | 19 June 2026 |
| CVE-2026-48773 | Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. | CRITICAL 9.8EPSS 0.47% | 19 June 2026 |
| CVE-2026-48772 | With that, any `mysql_query_rules` row pinned to a `client_addr` value is forgeable: the attacker writes the address they want to match into the PP1 line, and ProxySQL routes their query as if it came from that address. | CRITICAL 10.0EPSS 0.21% | 19 June 2026 |
| CVE-2026-51846 | In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution. | CRITICAL 9.8EPSS 0.84% | 19 June 2026 |
| CVE-2026-51845 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter. | CRITICAL 9.8EPSS 0.56% | 19 June 2026 |
| CVE-2026-51844 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. | CRITICAL 9.8EPSS 0.56% | 19 June 2026 |
| CVE-2026-51843 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. | CRITICAL 9.8EPSS 0.56% | 19 June 2026 |
| CVE-2026-9142 | There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. | CRITICAL 9.3EPSS 0.43% | 19 June 2026 |
| CVE-2026-48137 | There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. | CRITICAL 9.3EPSS 0.80% | 19 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.