Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,283 results · page 99 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-49105 | Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | CRITICAL 9.8EPSS 0.48% | 15 June 2026 |
| CVE-2026-49104 | Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions. | CRITICAL 9.8EPSS 0.48% | 15 June 2026 |
| CVE-2026-49085 | Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | CRITICAL 9.8EPSS 0.48% | 15 June 2026 |
| CVE-2026-49067 | Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions. | CRITICAL 9.3EPSS 0.29% | 15 June 2026 |
| CVE-2026-48886 | Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-48881 | Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. | CRITICAL 9.1EPSS 0.28% | 15 June 2026 |
| CVE-2026-48836 | Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. | CRITICAL 10.0EPSS 0.57% | 15 June 2026 |
| CVE-2026-45439 | Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions. | CRITICAL 9.3EPSS 0.29% | 15 June 2026 |
| CVE-2026-42665 | Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-42639 | Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-42386 | Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-42381 | Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-40798 | Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-40772 | Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions. | CRITICAL 10.0EPSS 0.36% | 15 June 2026 |
| CVE-2026-40771 | Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-39591 | Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions. | CRITICAL 9.9EPSS 0.46% | 15 June 2026 |
| CVE-2026-39583 | Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions. | CRITICAL 9.8EPSS 0.36% | 15 June 2026 |
| CVE-2026-39530 | Unauthenticated SQL Injection in SpeakOut! | CRITICAL 9.3EPSS 0.30% | 15 June 2026 |
| CVE-2026-39519 | Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-39512 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-39511 | Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions. | CRITICAL 9.3EPSS 0.29% | 15 June 2026 |
| CVE-2026-39502 | Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions. | CRITICAL 9.3EPSS 0.29% | 15 June 2026 |
| CVE-2026-39493 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions. | CRITICAL 9.3EPSS 0.36% | 15 June 2026 |
| CVE-2026-39492 | Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions. | CRITICAL 9.3EPSS 0.36% | 15 June 2026 |
| CVE-2026-39465 | Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions. | CRITICAL 9.1EPSS 0.68% | 15 June 2026 |
| CVE-2026-39441 | Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions. | CRITICAL 9.3EPSS 0.28% | 15 June 2026 |
| CVE-2026-34901 | Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions. | CRITICAL 9.8EPSS 0.32% | 15 June 2026 |
| CVE-2026-27053 | Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions. | CRITICAL 9.8EPSS 0.39% | 15 June 2026 |
| CVE-2026-50890 | Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. | CRITICAL 9.8EPSS 0.32% | 15 June 2026 |
| CVE-2026-50887 | A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl. | CRITICAL 9.1EPSS 0.29% | 15 June 2026 |
| CVE-2026-50886 | Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request. | CRITICAL 9.1EPSS 0.31% | 15 June 2026 |
| CVE-2026-50883 | An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload. | CRITICAL 9.6EPSS 0.37% | 15 June 2026 |
| CVE-2026-50880 | An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request. | CRITICAL 9.8EPSS 0.48% | 15 June 2026 |
| CVE-2026-50873 | An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file. | CRITICAL 9.8EPSS 0.44% | 15 June 2026 |
| CVE-2026-50872 | An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP request. | CRITICAL 9.8EPSS 0.56% | 15 June 2026 |
| CVE-2026-50871 | An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input. | CRITICAL 9.8EPSS 1.57% | 15 June 2026 |
| CVE-2026-50869 | An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request. | CRITICAL 9.8EPSS 0.72% | 15 June 2026 |
| CVE-2026-49952 | X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key… | EXPLOITCRITICAL 9.3EPSS 4.72% | 15 June 2026 |
| CVE-2026-48114 | Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint. | CRITICAL 9.8EPSS 0.37% | 15 June 2026 |
| CVE-2026-45390 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. | CRITICAL 9.1EPSS 0.37% | 15 June 2026 |
| CVE-2026-45388 | In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage). | CRITICAL 9.1EPSS 0.22% | 15 June 2026 |
| CVE-2026-39196 | Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. | CRITICAL 9.8EPSS 0.32% | 15 June 2026 |
| CVE-2026-39006 | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. | CRITICAL 9.8EPSS 0.52% | 15 June 2026 |
| CVE-2026-38812 | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. | CRITICAL 9.8EPSS 0.39% | 15 June 2026 |
| CVE-2026-38329 | Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. | CRITICAL 9.8EPSS 0.63% | 15 June 2026 |
| CVE-2026-38065 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter. | CRITICAL 9.8EPSS 1.34% | 15 June 2026 |
| CVE-2026-38064 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter. | CRITICAL 9.8EPSS 1.05% | 15 June 2026 |
| CVE-2026-38063 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter. | CRITICAL 9.8EPSS 1.05% | 15 June 2026 |
| CVE-2026-38062 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter. | CRITICAL 9.8EPSS 1.05% | 15 June 2026 |
| CVE-2026-38061 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter. | CRITICAL 9.8EPSS 1.05% | 15 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.