Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,914 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,282 results · page 93 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-62821 | Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. | CRITICAL 9.1EPSS 1.05% | 19 June 2026 |
| CVE-2026-56141 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible | CRITICAL 9.8EPSS 0.52% | 19 June 2026 |
| CVE-2026-50242 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | CRITICAL 9.8EPSS 0.61% | 19 June 2026 |
| CVE-2026-44939 | A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious… | CRITICAL 9.4EPSS 1.31% | 19 June 2026 |
| CVE-2026-8713 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. | CRITICAL 9.1EPSS 2.67% | 19 June 2026 |
| CVE-2026-7515 | The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. | CRITICAL 9.8EPSS 0.94% | 19 June 2026 |
| CVE-2026-54414 | FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. | CRITICAL 9.3EPSS 0.66% | 19 June 2026 |
| CVE-2026-40624 | Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request. | CRITICAL 9.3EPSS 0.83% | 19 June 2026 |
| CVE-2026-12048 | Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. | CRITICAL 9.3EPSS 0.27% | 19 June 2026 |
| CVE-2026-12046 | Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module missing the @pga_login_required… | CRITICAL 9.5EPSS 1.04% | 19 June 2026 |
| CVE-2026-12045 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. | CRITICAL 9.4EPSS 0.66% | 19 June 2026 |
| CVE-2026-47647 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | CRITICAL 9.9EPSS 0.78% | 18 June 2026 |
| CVE-2026-49454 | A forged SignatureValue carrying an attacker-controlled NameID could be accepted as {:ok}. | CRITICAL 9.1EPSS 0.23% | 18 June 2026 |
| CVE-2026-49257 | All MCP tools, including SQL query execution, schema creation, and table-config mutation, are reachable by any network-adjacent caller. | CRITICAL 10.0EPSS 0.93% | 18 June 2026 |
| CVE-2026-49252 | deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. | CRITICAL 9.9EPSS 0.47% | 18 June 2026 |
| CVE-2026-43994 | Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). | CRITICAL 9.8EPSS 0.68% | 18 June 2026 |
| CVE-2026-47846 | Bitnami Cassandra container images are affected by a retained default superuser vulnerability. | CRITICAL 9.8EPSS 0.48% | 18 June 2026 |
| CVE-2026-54390 | JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. | CRITICAL 9.3EPSS 0.60% | 18 June 2026 |
| CVE-2026-56020 | The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. | CRITICAL 9.2EPSS 0.50% | 18 June 2026 |
| CVE-2026-55203 | HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. | CRITICAL 9.0EPSS 0.35% | 18 June 2026 |
| CVE-2026-54103 | A remote, unauthenticated attacker could change an arbitrary user's password. | CRITICAL 9.3EPSS 0.77% | 18 June 2026 |
| CVE-2026-38717 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. | CRITICAL 9.8EPSS 2.31% | 18 June 2026 |
| CVE-2026-38716 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. | CRITICAL 9.8EPSS 2.31% | 18 June 2026 |
| CVE-2026-38715 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. | CRITICAL 9.8EPSS 2.31% | 18 June 2026 |
| CVE-2026-38714 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. | CRITICAL 9.8EPSS 2.31% | 18 June 2026 |
| CVE-2026-8024 | A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems. | CRITICAL 9.3EPSS 0.55% | 18 June 2026 |
| CVE-2026-54419 | claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities. | CRITICAL 9.3EPSS 0.44% | 18 June 2026 |
| CVE-2026-11718 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. | CRITICAL 9.3EPSS 0.18% | 18 June 2026 |
| CVE-2026-11717 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. | CRITICAL 9.3EPSS 0.18% | 18 June 2026 |
| CVE-2025-10560 | Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. | CRITICAL 9.3EPSS 0.39% | 18 June 2026 |
| CVE-2026-55742 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. | CRITICAL 9.4EPSS 0.15% | 18 June 2026 |
| CVE-2026-28573 | In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. | CRITICAL 10.0EPSS 0.14% | 18 June 2026 |
| CVE-2026-55740 | Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. | CRITICAL 9.3EPSS 0.28% | 18 June 2026 |
| CVE-2026-12569 | PTC Windchill and FlexPLM Improper Input Validation Vulnerability | KEVCRITICAL 9.3EPSS 40.6% | 18 June 2026 |
| CVE-2026-48768 | As a result, any anonymous visitor to a published bot with a file input can upload attacker-controlled HTML, SVG, or JS to attacker-chosen subpaths, including other tenants’ publicly served result paths, enabling arbitrary content hosting and potential… | CRITICAL 9.3EPSS 0.27% | 18 June 2026 |
| CVE-2026-55200 | libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. | CRITICAL 9.2EPSS 4.02% | 17 June 2026 |
| CVE-2026-54388 | Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking. | CRITICAL 9.3EPSS 0.44% | 17 June 2026 |
| CVE-2026-54387 | Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking. | CRITICAL 9.3EPSS 0.44% | 17 June 2026 |
| CVE-2026-48814 | In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. | CRITICAL 9.1EPSS 0.30% | 17 June 2026 |
| CVE-2026-55196 | Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. | CRITICAL 9.1EPSS 0.58% | 17 June 2026 |
| CVE-2026-53805 | NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's… | CRITICAL 9.3EPSS 0.87% | 17 June 2026 |
| CVE-2026-3894 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from… | CRITICAL 9.2EPSS 0.20% | 17 June 2026 |
| CVE-2026-2467 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0… | CRITICAL 9.2EPSS 0.19% | 17 June 2026 |
| CVE-2026-20266 | In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. | CRITICAL 9.1EPSS 0.63% | 17 June 2026 |
| CVE-2026-53874 | picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. | CRITICAL 9.3EPSS 0.52% | 17 June 2026 |
| CVE-2026-53873 | picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec(). | CRITICAL 9.3EPSS 0.46% | 17 June 2026 |
| CVE-2026-3490 | picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. | CRITICAL 10.0EPSS 0.62% | 17 June 2026 |
| CVE-2026-36418 | JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. | CRITICAL 9.1EPSS 0.47% | 17 June 2026 |
| CVE-2026-20181 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. | CRITICAL 9.1EPSS 8.93% | 17 June 2026 |
| CVE-2025-71325 | picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection. | CRITICAL 9.3EPSS 0.47% | 17 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.