SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

392,197 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

Known exploited — most recently added

All KEV entries →
CVESummaryPriorityPublished
CVE-2026-76461Cisco Secure Email Gateway SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS —14 September 2026
CVE-2026-42018JFrog Artifactory Improper Authentication VulnerabilityKEVHIGH 7.5EPSS 0.92%12 August 2026
CVE-2026-42016JFrog Artifactory Incorrect Authorization VulnerabilityKEVHIGH 8.8EPSS 0.89%27 July 2026
CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization VulnerabilityKEVCRITICAL 9.9EPSS 0.69%8 September 2026
CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal VulnerabilityKEVCRITICAL 10.0EPSS 11.1%12 September 2026
CVE-2026-67277MikroTik RouterOS Missing Authentication for Critical Function VulnerabilityKEVHIGH 8.8EPSS 0.86%5 September 2026
CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command VulnerabilityKEVCRITICAL 9.2EPSS 1.02%5 September 2026
CVE-2026-19490Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVCRITICAL 9.3EPSS 5.60%19 August 2026

Most likely to be exploited this month

All with EPSS ≥ 10% →
CVESummaryPriorityPublished
CVE-2024-3400Palo Alto Networks PAN-OS Command Injection VulnerabilityKEVCRITICAL 10.0EPSS 100.0%12 April 2024
CVE-2024-23897Jenkins Command Line Interface (CLI) Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 100.0%24 January 2024
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) VulnerabilityKEVHIGH 8.2EPSS 100.0%31 January 2024
CVE-2024-21887Ivanti Connect Secure and Policy Secure Command Injection VulnerabilityKEVCRITICAL 9.1EPSS 100.0%12 January 2024
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityKEVHIGH 7.5EPSS 100.0%10 October 2023
CVE-2023-44487HTTP/2 Rapid Reset Attack VulnerabilityKEVHIGH 7.5EPSS 100.0%10 October 2023
CVE-2023-35082Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%15 August 2023
CVE-2023-35078Ivanti Endpoint Manager Mobile Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%25 July 2023
CVESummaryPriorityPublished
CVE-2026-92180pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability.HIGH 7.8EPSS —15 September 2026
CVE-2026-92179pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability.HIGH 7.8EPSS —15 September 2026
CVE-2026-92178pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability.HIGH 7.8EPSS —15 September 2026
CVE-2026-92177pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability.HIGH 7.8EPSS —15 September 2026
CVE-2026-92176pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability.HIGH 7.8EPSS —15 September 2026
CVE-2026-90971Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via…UnscoredEPSS —15 September 2026
CVE-2026-90969Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with…UnscoredEPSS —15 September 2026
CVE-2026-84850Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a…UnscoredEPSS —15 September 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.