Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,592 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,238 results · page 1 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-94084 | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform. | CRITICAL 9.4EPSS — | 20 September 2026 |
| CVE-2026-94083 | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). | CRITICAL 9.4EPSS — | 20 September 2026 |
| CVE-2026-93985 | OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. | CRITICAL 9.4EPSS — | 19 September 2026 |
| CVE-2026-78030 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. | CRITICAL 9.8EPSS — | 19 September 2026 |
| CVE-2026-86591 | The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a… | CRITICAL 9.8EPSS 0.18% | 19 September 2026 |
| CVE-2026-93741 | Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. | CRITICAL 9.3EPSS 0.64% | 19 September 2026 |
| CVE-2026-92229 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. | CRITICAL 9.1EPSS 0.40% | 19 September 2026 |
| CVE-2026-89274 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. | CRITICAL 9.1EPSS 0.38% | 19 September 2026 |
| CVE-2026-84434 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. | CRITICAL 9.8EPSS 0.70% | 19 September 2026 |
| CVE-2026-93740 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. | CRITICAL 9.3EPSS 0.61% | 18 September 2026 |
| CVE-2026-75885 | Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. | CRITICAL 9.3EPSS 0.41% | 18 September 2026 |
| CVE-2026-93868 | Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account password including administrators. | CRITICAL 9.2EPSS 0.61% | 18 September 2026 |
| CVE-2026-93839 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. | CRITICAL 9.3EPSS 0.60% | 18 September 2026 |
| CVE-2026-84082 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | CRITICAL 9.8EPSS 0.40% | 18 September 2026 |
| CVE-2026-84078 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. | CRITICAL 9.9EPSS 0.28% | 18 September 2026 |
| CVE-2026-84075 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet. | CRITICAL 9.9EPSS 0.35% | 18 September 2026 |
| CVE-2026-84073 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | CRITICAL 9.1EPSS 0.26% | 18 September 2026 |
| CVE-2026-84064 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | CRITICAL 9.9EPSS 0.37% | 18 September 2026 |
| CVE-2026-84031 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | CRITICAL 9.0EPSS 0.33% | 18 September 2026 |
| CVE-2026-82967 | IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface. | CRITICAL 9.8EPSS 0.43% | 18 September 2026 |
| CVE-2026-82832 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. | CRITICAL 9.6EPSS 0.38% | 18 September 2026 |
| CVE-2026-82340 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. | CRITICAL 9.8EPSS 0.51% | 18 September 2026 |
| CVE-2026-81657 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | CRITICAL 9.8EPSS 0.58% | 18 September 2026 |
| CVE-2026-80442 | IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. | CRITICAL 9.9EPSS 0.63% | 18 September 2026 |
| CVE-2026-80441 | IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. | CRITICAL 9.8EPSS 0.38% | 18 September 2026 |
| CVE-2026-75878 | IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header. | CRITICAL 9.1EPSS 0.48% | 18 September 2026 |
| CVE-2026-63647 | Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the caller-controlled userId instead of deriving an… | CRITICAL 9.3EPSS 0.47% | 18 September 2026 |
| CVE-2026-61781 | Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. | CRITICAL 9.9EPSS 0.57% | 18 September 2026 |
| CVE-2026-58264 | An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible code execution. | CRITICAL 9.8EPSS 0.59% | 18 September 2026 |
| CVE-2023-54399 | Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. | CRITICAL 9.3EPSS 0.42% | 18 September 2026 |
| CVE-2026-93762 | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. | CRITICAL 9.2EPSS 0.34% | 18 September 2026 |
| CVE-2026-92702 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. | CRITICAL 9.1EPSS 0.21% | 18 September 2026 |
| CVE-2026-92701 | trusted execution environments. | CRITICAL 9.1EPSS 0.22% | 18 September 2026 |
| CVE-2026-61550 | An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. | CRITICAL 9.8EPSS 0.37% | 18 September 2026 |
| CVE-2026-59163 | The vulnerability is not exploitable against an unreachable endpoint. | CRITICAL 9.1EPSS 0.25% | 18 September 2026 |
| CVE-2025-66455 | Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. | CRITICAL 9.8EPSS 0.70% | 18 September 2026 |
| CVE-2026-85497 | An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices running the same firmware. | CRITICAL 9.3EPSS 0.21% | 18 September 2026 |
| CVE-2026-81321 | An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key. | CRITICAL 9.3EPSS 0.20% | 18 September 2026 |
| CVE-2026-77240 | In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and account_id, allowing a viewer to self-promote or move into… | CRITICAL 9.9EPSS 0.27% | 18 September 2026 |
| CVE-2026-84383 | The output geometry controls the overflow extent and the encoded sample values control the data written, allowing a remote file processed by heif_decode_image() to cause a heap out-of-bounds write. | CRITICAL 9.8EPSS 0.64% | 18 September 2026 |
| CVE-2026-75031 | In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. | CRITICAL 9.8EPSS 0.71% | 18 September 2026 |
| CVE-2026-61682 | Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. | CRITICAL 9.9EPSS 0.28% | 18 September 2026 |
| CVE-2026-10858 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages. | CRITICAL 9.9EPSS 0.33% | 18 September 2026 |
| CVE-2026-10747 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication. | CRITICAL 10.0EPSS 0.52% | 18 September 2026 |
| CVE-2025-53837 | Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write… | CRITICAL 9.9EPSS 0.64% | 18 September 2026 |
| CVE-2025-15399 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the… | CRITICAL 10.0EPSS 0.25% | 18 September 2026 |
| CVE-2026-93659 | Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data. | CRITICAL 9.3EPSS 0.26% | 18 September 2026 |
| CVE-2026-93606 | When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots… | CRITICAL 10.0EPSS 0.52% | 18 September 2026 |
| CVE-2026-93605 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. | CRITICAL 10.0EPSS 0.38% | 18 September 2026 |
| CVE-2026-93603 | This allows a complete sandbox escape: untrusted script can reach `process` and execute arbitrary code/commands on the host (for example via `process.getBuiltinModule('child_process').execSync`). | CRITICAL 10.0EPSS 0.43% | 18 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.