Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
Known exploited — most recently added
All KEV entries →| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-53266 | Linux Kernel Out-of-Bounds Write Vulnerability | KEVHIGH 8.8EPSS 0.28% | 25 June 2026 |
| CVE-2025-39964 | Linux Kernel Race Condition Vulnerability | KEVMEDIUM 5.5EPSS 0.79% | 13 October 2025 |
| CVE-2025-39682 | Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability | KEVHIGH 7.1EPSS 1.20% | 5 September 2025 |
| CVE-2026-87886 | Acronis Backup Incorrect Default Permissions Vulnerability | KEVHIGH 7.8EPSS 0.25% | 17 September 2026 |
| CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | KEVCRITICAL 10.0EPSS 0.78% | 16 September 2026 |
| CVE-2026-58704 | Google Pixel Improper Authorization Vulnerability | KEVHIGH 8.8EPSS 0.21% | 15 September 2026 |
| CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection Vulnerability | KEVCRITICAL 9.8EPSS 2.01% | 14 September 2026 |
| CVE-2026-85706 | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | KEVCRITICAL 10.0EPSS 14.6% | 12 September 2026 |
Newest public exploits
All with a public exploit →| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-80428 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and… | EXPLOITCRITICAL 9.3EPSS 2.33% | 26 August 2026 |
| CVE-2025-57819 | Sangoma FreePBX Authentication Bypass Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 85.5% | 28 August 2025 |
| CVE-2026-59827 | Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation,… | EXPLOITHIGH 8.8EPSS 3.25% | 9 July 2026 |
| CVE-2026-41456 | Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. | EXPLOITMEDIUM 5.1EPSS 1.90% | 21 April 2026 |
| CVE-2025-70336 | A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. | EXPLOITMEDIUM 4.8EPSS 0.40% | 28 January 2026 |
| CVE-2025-68137 | Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current buffer length to be set to 7 after a complete header of size 8 has been read. | EXPLOITHIGH 8.3EPSS 1.09% | 21 January 2026 |
| CVE-2026-29053 | From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. | EXPLOITCRITICAL 9.8EPSS 3.58% | 5 March 2026 |
| CVE-2026-39987 | Marimo Remote Code Execution Vulnerability | KEVEXPLOITCRITICAL 9.3EPSS 99.6% | 9 April 2026 |
Most likely to be exploited this month
All with EPSS ≥ 10% →| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2024-3400 | Palo Alto Networks PAN-OS Command Injection Vulnerability | KEVEXPLOITCRITICAL 10.0EPSS 100.0% | 12 April 2024 |
| CVE-2024-23897 | Jenkins Command Line Interface (CLI) Path Traversal Vulnerability | KEVEXPLOITCRITICAL 9.8EPSS 100.0% | 24 January 2024 |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability | KEVHIGH 8.2EPSS 100.0% | 31 January 2024 |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | KEVCRITICAL 9.1EPSS 100.0% | 12 January 2024 |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | KEVHIGH 7.5EPSS 100.0% | 10 October 2023 |
| CVE-2023-44487 | HTTP/2 Rapid Reset Attack Vulnerability | KEVEXPLOITHIGH 7.5EPSS 100.0% | 10 October 2023 |
| CVE-2023-35082 | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 15 August 2023 |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability | KEVCRITICAL 9.8EPSS 100.0% | 25 July 2023 |
Newest CVEs
Browse everything →| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-94031 | A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. | LOW 2.1EPSS — | 20 September 2026 |
| CVE-2026-94030 | A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. | LOW 1.3EPSS — | 20 September 2026 |
| CVE-2026-94028 | A weakness has been identified in mealie-recipes Mealie up to 3.25.1. | LOW 2.1EPSS — | 20 September 2026 |
| CVE-2026-94016 | Performing a manipulation of the argument txtname results in cross site scripting. | LOW 1.9EPSS — | 20 September 2026 |
| CVE-2026-94015 | A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. | MEDIUM 5.5EPSS — | 20 September 2026 |
| CVE-2026-92254 | Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM… | MEDIUM 6.9EPSS — | 20 September 2026 |
| CVE-2026-92253 | Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem location by creating… | MEDIUM 5.2EPSS — | 20 September 2026 |
| CVE-2026-92252 | Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files, because the installer grants the Users group Full… | MEDIUM 5.9EPSS — | 20 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.