Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,283 results · page 94 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2025-71325 | picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection. | CRITICAL 9.3EPSS 0.47% | 17 June 2026 |
| CVE-2025-71323 | picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory. | CRITICAL 9.3EPSS 0.76% | 17 June 2026 |
| CVE-2025-71321 | picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. | CRITICAL 9.3EPSS 0.62% | 17 June 2026 |
| CVE-2025-71320 | picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. | CRITICAL 9.3EPSS 0.62% | 17 June 2026 |
| CVE-2026-55743 | The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. | CRITICAL 9.4EPSS 0.39% | 17 June 2026 |
| CVE-2026-54812 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. | CRITICAL 9.3EPSS 0.28% | 17 June 2026 |
| CVE-2026-47103 | Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. | CRITICAL 9.3EPSS 1.36% | 17 June 2026 |
| CVE-2026-42530 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. | CRITICAL 9.2EPSS 3.82% | 17 June 2026 |
| CVE-2026-42055 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. | CRITICAL 9.2EPSS 6.54% | 17 June 2026 |
| CVE-2026-54819 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. | CRITICAL 9.3EPSS 0.23% | 17 June 2026 |
| CVE-2026-54815 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. | CRITICAL 9.3EPSS 0.23% | 17 June 2026 |
| CVE-2026-54809 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. | CRITICAL 9.3EPSS 0.23% | 17 June 2026 |
| CVE-2026-54808 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. | CRITICAL 9.3EPSS 0.31% | 17 June 2026 |
| CVE-2026-49108 | Unauthenticated PHP Object Injection in Moderno < 1.43 versions. | CRITICAL 9.8EPSS 0.30% | 17 June 2026 |
| CVE-2025-69127 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. | CRITICAL 9.8EPSS 0.39% | 17 June 2026 |
| CVE-2025-69111 | Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. | CRITICAL 9.8EPSS 0.39% | 17 June 2026 |
| CVE-2025-60236 | Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. | CRITICAL 9.8EPSS 0.31% | 17 June 2026 |
| CVE-2025-60231 | Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. | CRITICAL 9.8EPSS 0.31% | 17 June 2026 |
| CVE-2025-60230 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. | CRITICAL 9.8EPSS 0.43% | 17 June 2026 |
| CVE-2025-60229 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. | CRITICAL 9.8EPSS 0.43% | 17 June 2026 |
| CVE-2025-59554 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | CRITICAL 9.3EPSS 0.40% | 17 June 2026 |
| CVE-2026-54811 | Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. | CRITICAL 9.3EPSS 0.28% | 17 June 2026 |
| CVE-2026-54807 | Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. | CRITICAL 9.8EPSS 0.44% | 17 June 2026 |
| CVE-2026-54806 | Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. | CRITICAL 9.8EPSS 0.70% | 17 June 2026 |
| CVE-2026-54803 | Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions. | CRITICAL 9.8EPSS 0.45% | 17 June 2026 |
| CVE-2026-54194 | Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. | CRITICAL 9.8EPSS 0.38% | 17 June 2026 |
| CVE-2026-54187 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. | CRITICAL 9.3EPSS 0.28% | 17 June 2026 |
| CVE-2026-54186 | Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. | CRITICAL 9.3EPSS 0.29% | 17 June 2026 |
| CVE-2026-52706 | Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. | CRITICAL 9.8EPSS 0.47% | 17 June 2026 |
| CVE-2026-52705 | Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. | CRITICAL 9.0EPSS 0.29% | 17 June 2026 |
| CVE-2026-50203 | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. | CRITICAL 9.1EPSS 0.63% | 17 June 2026 |
| CVE-2026-49767 | Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. | CRITICAL 9.8EPSS 0.55% | 17 June 2026 |
| CVE-2026-49107 | Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. | CRITICAL 9.8EPSS 0.38% | 17 June 2026 |
| CVE-2026-49084 | Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. | CRITICAL 9.3EPSS 0.28% | 17 June 2026 |
| CVE-2026-49080 | Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. | CRITICAL 9.3EPSS 0.31% | 17 June 2026 |
| CVE-2026-49079 | Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. | CRITICAL 9.3EPSS 0.35% | 17 June 2026 |
| CVE-2026-49076 | Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. | CRITICAL 9.3EPSS 0.37% | 17 June 2026 |
| CVE-2026-49075 | Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. | CRITICAL 9.8EPSS 0.38% | 17 June 2026 |
| CVE-2026-49058 | Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. | CRITICAL 9.8EPSS 0.32% | 17 June 2026 |
| CVE-2026-48875 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. | CRITICAL 9.3EPSS 0.37% | 17 June 2026 |
| CVE-2026-48797 | In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push. | CRITICAL 9.3EPSS 0.32% | 17 June 2026 |
| CVE-2026-48781 | In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from… | CRITICAL 9.9EPSS 0.21% | 17 June 2026 |
| CVE-2026-48745 | In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. | CRITICAL 9.3EPSS 0.32% | 17 June 2026 |
| CVE-2026-48616 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. | CRITICAL 9.3EPSS 0.33% | 17 June 2026 |
| CVE-2026-48055 | In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. | CRITICAL 10.0EPSS 0.62% | 17 June 2026 |
| CVE-2026-42380 | Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. | CRITICAL 9.8EPSS 0.51% | 17 June 2026 |
| CVE-2026-40783 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. | CRITICAL 9.9EPSS 0.54% | 17 June 2026 |
| CVE-2026-40749 | Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. | CRITICAL 9.9EPSS 0.43% | 17 June 2026 |
| CVE-2026-40748 | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. | CRITICAL 9.9EPSS 0.43% | 17 June 2026 |
| CVE-2026-40747 | Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. | CRITICAL 9.9EPSS 0.43% | 17 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.