Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,283 results · page 95 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-40746 | Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. | CRITICAL 9.9EPSS 0.43% | 17 June 2026 |
| CVE-2026-40725 | Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. | CRITICAL 9.8EPSS 0.38% | 17 June 2026 |
| CVE-2026-39596 | Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. | CRITICAL 9.3EPSS 0.37% | 17 June 2026 |
| CVE-2026-39589 | Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. | CRITICAL 9.9EPSS 0.45% | 17 June 2026 |
| CVE-2026-39529 | Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. | CRITICAL 9.8EPSS 0.38% | 17 June 2026 |
| CVE-2026-39438 | Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. | CRITICAL 9.3EPSS 0.37% | 17 June 2026 |
| CVE-2026-32967 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. | CRITICAL 9.1EPSS 0.34% | 17 June 2026 |
| CVE-2026-32966 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. | CRITICAL 9.8EPSS 0.39% | 17 June 2026 |
| CVE-2026-28615 | In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. | CRITICAL 10.0EPSS 0.12% | 17 June 2026 |
| CVE-2026-28587 | In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. | CRITICAL 10.0EPSS 0.11% | 17 June 2026 |
| CVE-2026-28576 | In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. | CRITICAL 10.0EPSS 0.15% | 17 June 2026 |
| CVE-2026-28575 | This could lead to local denial of service with no additional execution privileges needed. | CRITICAL 10.0EPSS 0.13% | 17 June 2026 |
| CVE-2026-27429 | Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. | CRITICAL 9.8EPSS 0.56% | 17 June 2026 |
| CVE-2026-27395 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. | CRITICAL 9.8EPSS 0.34% | 17 June 2026 |
| CVE-2026-27041 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. | CRITICAL 9.9EPSS 0.32% | 17 June 2026 |
| CVE-2026-25470 | Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions. | CRITICAL 10.0EPSS 0.65% | 17 June 2026 |
| CVE-2026-25446 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. | CRITICAL 9.9EPSS 0.43% | 17 June 2026 |
| CVE-2026-24611 | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. | CRITICAL 9.1EPSS 0.44% | 17 June 2026 |
| CVE-2026-22340 | Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. | CRITICAL 9.3EPSS 0.37% | 17 June 2026 |
| CVE-2026-22332 | Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. | CRITICAL 9.3EPSS 0.28% | 17 June 2026 |
| CVE-2026-22327 | Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions. | CRITICAL 9.9EPSS 0.46% | 17 June 2026 |
| CVE-2026-12440 | Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.25% | 17 June 2026 |
| CVE-2026-10094 | A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitrary files on the server. | CRITICAL 9.8EPSS 0.38% | 17 June 2026 |
| CVE-2026-0092 | In Package Manager, there is a possible device lock controller bypass due to a missing permission check. | CRITICAL 10.0EPSS 0.22% | 17 June 2026 |
| CVE-2026-0083 | In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. | CRITICAL 10.0EPSS 0.12% | 17 June 2026 |
| CVE-2026-0082 | In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. | CRITICAL 10.0EPSS 0.17% | 17 June 2026 |
| CVE-2026-0081 | In NFC, there is a possible way to spoof an NFC event due to a missing permission check. | CRITICAL 10.0EPSS 0.15% | 17 June 2026 |
| CVE-2026-0071 | In SettingsLib, there is a possible missing permission check due to a logic error in the code. | CRITICAL 10.0EPSS 0.15% | 17 June 2026 |
| CVE-2026-0068 | This could lead to local escalation of privilege if a user can install a malicious app with no additional execution privileges needed. | CRITICAL 10.0EPSS 0.12% | 17 June 2026 |
| CVE-2026-0064 | In multiple places, there is a possible persistent denial of service due to resource exhaustion. | CRITICAL 10.0EPSS 0.12% | 17 June 2026 |
| CVE-2026-0063 | In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the code. | CRITICAL 10.0EPSS 0.15% | 17 June 2026 |
| CVE-2025-69179 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. | CRITICAL 9.8EPSS 0.45% | 17 June 2026 |
| CVE-2025-69129 | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | CRITICAL 10.0EPSS 0.43% | 17 June 2026 |
| CVE-2025-69122 | Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions. | CRITICAL 9.8EPSS 0.53% | 17 June 2026 |
| CVE-2025-69108 | Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions. | CRITICAL 9.8EPSS 0.53% | 17 June 2026 |
| CVE-2025-60218 | Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. | CRITICAL 9.9EPSS 0.45% | 17 June 2026 |
| CVE-2025-60205 | Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions. | CRITICAL 9.8EPSS 0.53% | 17 June 2026 |
| CVE-2025-59872 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to… | CRITICAL 9.8EPSS 0.45% | 17 June 2026 |
| CVE-2024-52488 | Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions. | CRITICAL 9.9EPSS 0.47% | 17 June 2026 |
| CVE-2026-48776 | Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. | CRITICAL 9.1EPSS 0.22% | 17 June 2026 |
| CVE-2026-46978 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). | CRITICAL 10.0EPSS 0.31% | 17 June 2026 |
| CVE-2026-46964 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). | CRITICAL 9.9EPSS 0.40% | 17 June 2026 |
| CVE-2026-46963 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). | CRITICAL 9.9EPSS 0.40% | 17 June 2026 |
| CVE-2026-46949 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). | CRITICAL 9.1EPSS 0.40% | 17 June 2026 |
| CVE-2026-46946 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). | CRITICAL 9.1EPSS 0.46% | 17 June 2026 |
| CVE-2026-46945 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). | CRITICAL 9.1EPSS 0.46% | 17 June 2026 |
| CVE-2026-46944 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). | CRITICAL 9.1EPSS 0.45% | 17 June 2026 |
| CVE-2026-46933 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). | CRITICAL 9.9EPSS 0.41% | 17 June 2026 |
| CVE-2026-46930 | Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). | CRITICAL 9.1EPSS 0.40% | 17 June 2026 |
| CVE-2026-46919 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | CRITICAL 9.8EPSS 0.36% | 17 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.