Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,283 results · page 98 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-35292 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). | CRITICAL 10.0EPSS 0.48% | 17 June 2026 |
| CVE-2026-35286 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | CRITICAL 9.8EPSS 0.48% | 17 June 2026 |
| CVE-2026-35285 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL 9.9EPSS 0.41% | 17 June 2026 |
| CVE-2026-35284 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL 9.9EPSS 0.41% | 17 June 2026 |
| CVE-2026-35283 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL 9.9EPSS 0.41% | 17 June 2026 |
| CVE-2026-35282 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL 9.9EPSS 0.40% | 17 June 2026 |
| CVE-2026-35281 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL 9.9EPSS 0.48% | 17 June 2026 |
| CVE-2026-35280 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL 9.9EPSS 0.48% | 17 June 2026 |
| CVE-2026-35278 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). | CRITICAL 9.8EPSS 0.64% | 17 June 2026 |
| CVE-2026-35270 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | CRITICAL 9.1EPSS 0.50% | 17 June 2026 |
| CVE-2026-35268 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.9EPSS 0.52% | 17 June 2026 |
| CVE-2026-35263 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). | CRITICAL 9.9EPSS 0.36% | 17 June 2026 |
| CVE-2026-48777 | Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields with the trusted d.share.Path BEFORE the… | CRITICAL 9.3EPSS 0.45% | 16 June 2026 |
| CVE-2026-22313 | The device has a webserver that exposes a REST API authenticated with a token on the management network. | CRITICAL 9.1EPSS 0.92% | 16 June 2026 |
| CVE-2026-0126 | In WC-Radio, there is a possible out of bounds write due to a missing bounds check. | CRITICAL 9.8EPSS 0.28% | 16 June 2026 |
| CVE-2026-53776 | Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. | CRITICAL 9.3EPSS 0.36% | 16 June 2026 |
| CVE-2025-13036 | An authentication bypass security issue exists within FactoryTalk Historian Site Edition. | CRITICAL 9.2EPSS 0.29% | 16 June 2026 |
| CVE-2026-12316 | Mitigation bypass in the DOM: Security component. | CRITICAL 9.1EPSS 0.24% | 16 June 2026 |
| CVE-2026-12315 | Mitigation bypass in the DOM: Security component. | CRITICAL 9.1EPSS 0.25% | 16 June 2026 |
| CVE-2026-12304 | Same-origin policy bypass in the Networking: Cookies component. | CRITICAL 9.1EPSS 0.19% | 16 June 2026 |
| CVE-2026-12297 | This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | CRITICAL 9.6EPSS 0.39% | 16 June 2026 |
| CVE-2026-12296 | This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | CRITICAL 9.6EPSS 0.39% | 16 June 2026 |
| CVE-2026-12295 | This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | CRITICAL 9.6EPSS 0.39% | 16 June 2026 |
| CVE-2026-12294 | This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | CRITICAL 9.6EPSS 0.36% | 16 June 2026 |
| CVE-2026-12293 | Use-after-free in the Graphics: WebGPU component. | CRITICAL 9.8EPSS 0.30% | 16 June 2026 |
| CVE-2026-40750 | Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. | CRITICAL 9.9EPSS 0.27% | 16 June 2026 |
| CVE-2026-52715 | Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. | CRITICAL 9.3EPSS 0.24% | 16 June 2026 |
| CVE-2026-49774 | Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. | CRITICAL 9.9EPSS 0.28% | 16 June 2026 |
| CVE-2026-49772 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. | CRITICAL 9.3EPSS 0.35% | 16 June 2026 |
| CVE-2026-39574 | Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. | CRITICAL 9.3EPSS 0.23% | 16 June 2026 |
| CVE-2026-48853 | Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call… | CRITICAL 9.2EPSS 0.57% | 15 June 2026 |
| CVE-2026-12205 | Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. | CRITICAL 9.1EPSS 0.29% | 15 June 2026 |
| CVE-2026-48714 | In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did not reject dotted variants such as "__proto__.polluted". | CRITICAL 9.1EPSS 0.51% | 15 June 2026 |
| CVE-2026-48713 | Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). | CRITICAL 9.1EPSS 0.51% | 15 June 2026 |
| CVE-2026-12087 | Socket versions before 2.041 for Perl have an out-of-bounds heap read. | CRITICAL 9.1EPSS 0.37% | 15 June 2026 |
| CVE-2026-11832 | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. | CRITICAL 9.1EPSS 0.33% | 15 June 2026 |
| CVE-2026-9691 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | CRITICAL 9.8EPSS 0.48% | 15 June 2026 |
| CVE-2026-52703 | Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. | CRITICAL 9.6EPSS 0.44% | 15 June 2026 |
| CVE-2026-52693 | Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. | CRITICAL 9.3EPSS 0.29% | 15 June 2026 |
| CVE-2026-49781 | Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. | CRITICAL 9.8EPSS 0.50% | 15 June 2026 |
| CVE-2026-49776 | Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions. | CRITICAL 9.3EPSS 0.29% | 15 June 2026 |
| CVE-2026-49770 | Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | CRITICAL 9.8EPSS 0.38% | 15 June 2026 |
| CVE-2026-49769 | Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. | CRITICAL 9.8EPSS 0.38% | 15 June 2026 |
| CVE-2026-49768 | Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. | CRITICAL 9.8EPSS 0.38% | 15 June 2026 |
| CVE-2026-49766 | Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. | CRITICAL 9.9EPSS 0.51% | 15 June 2026 |
| CVE-2026-49765 | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. | CRITICAL 9.8EPSS 0.38% | 15 June 2026 |
| CVE-2026-49764 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. | CRITICAL 9.8EPSS 0.40% | 15 June 2026 |
| CVE-2026-49763 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. | CRITICAL 9.8EPSS 0.38% | 15 June 2026 |
| CVE-2026-49109 | Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. | CRITICAL 9.8EPSS 0.38% | 15 June 2026 |
| CVE-2026-49106 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. | CRITICAL 9.8EPSS 0.38% | 15 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.