SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

1,710 results · page 3 of 35

CVESummaryPriorityPublished
CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityKEVCRITICAL 9.8EPSS 72.7%14 April 2026
CVE-2026-32202Microsoft Windows Protection Mechanism Failure VulnerabilityKEVMEDIUM 4.3EPSS 63.7%14 April 2026
CVE-2026-32201Microsoft SharePoint Server Improper Input Validation VulnerabilityKEVMEDIUM 6.5EPSS 43.4%14 April 2026
CVE-2026-39808Fortinet FortiSandbox OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 92.8%14 April 2026
CVE-2026-34621Adobe Acrobat and Reader Prototype Pollution VulnerabilityKEVHIGH 8.6EPSS 7.09%11 April 2026
CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data VulnerabilityKEVHIGH 7.5EPSS 98.6%9 April 2026
CVE-2026-39987Marimo Remote Code Execution VulnerabilityKEVCRITICAL 9.3EPSS 98.9%9 April 2026
CVE-2026-34197Apache ActiveMQ Improper Input Validation VulnerabilityKEVHIGH 8.8EPSS 98.3%7 April 2026
CVE-2026-35616Fortinet FortiClient EMS Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 90.7%4 April 2026
CVE-2026-5281Google Dawn Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 4.94%1 April 2026
CVE-2026-3502TrueConf Client Download of Code Without Integrity Check VulnerabilityKEVHIGH 7.8EPSS 5.75%30 March 2026
CVE-2026-33634Aquasecurity Trivy Embedded Malicious Code VulnerabilityKEVCRITICAL 9.4EPSS 59.2%23 March 2026
CVE-2026-3055Citrix NetScaler Out-of-Bounds Read VulnerabilityKEVCRITICAL 9.3EPSS 87.2%23 March 2026
CVE-2026-33017Langflow Code Injection VulnerabilityKEVCRITICAL 9.3EPSS 96.2%20 March 2026
CVE-2026-3910Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer VulnerabilityKEVHIGH 8.8EPSS 2.00%13 March 2026
CVE-2026-3909Google Skia Out-of-Bounds Write VulnerabilityKEVHIGH 8.8EPSS 1.63%13 March 2026
CVE-2025-67038Lantronix EDS5000 Code Injection VulnerabilityKEVCRITICAL 9.3EPSS 19.3%11 March 2026
CVE-2026-20131Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 10.0EPSS 33.4%4 March 2026
CVE-2026-20079Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVCRITICAL 10.0EPSS 75.8%4 March 2026
CVE-2026-21385Qualcomm Multiple Chipsets Memory Corruption VulnerabilityKEVHIGH 7.8EPSS 1.29%2 March 2026
CVE-2026-22719Broadcom VMware Aria Operations Command Injection VulnerabilityKEVHIGH 8.1EPSS 17.4%25 February 2026
CVE-2026-20133Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityKEVHIGH 7.5EPSS 31.4%25 February 2026
CVE-2026-20128Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format VulnerabilityKEVHIGH 7.5EPSS 6.94%25 February 2026
CVE-2026-20127Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass VulnerabilityKEVCRITICAL 10.0EPSS 88.2%25 February 2026
CVE-2026-20122Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs VulnerabilityKEVMEDIUM 5.4EPSS 24.6%25 February 2026
CVE-2026-22769Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials VulnerabilityKEVCRITICAL 10.0EPSS 13.1%17 February 2026
CVE-2026-2441Google Chromium CSS Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 22.4%13 February 2026
CVE-2026-25108Soliton Systems K.K FileZen OS Command Injection VulnerabilityKEVHIGH 8.7EPSS 5.07%13 February 2026
CVE-2026-20700Apple Multiple Buffer Overflow VulnerabilityKEVHIGH 7.8EPSS 1.34%11 February 2026
CVE-2026-21533Microsoft Windows Improper Privilege Management VulnerabilityKEVHIGH 7.8EPSS 3.91%10 February 2026
CVE-2026-21525Microsoft Windows NULL Pointer Dereference VulnerabilityKEVMEDIUM 6.2EPSS 5.04%10 February 2026
CVE-2026-21519Microsoft Windows Type Confusion VulnerabilityKEVHIGH 7.8EPSS 2.46%10 February 2026
CVE-2026-21514Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision VulnerabilityKEVHIGH 7.8EPSS 1.54%10 February 2026
CVE-2026-21513Microsoft MSHTML Framework Protection Mechanism Failure VulnerabilityKEVHIGH 8.8EPSS 15.6%10 February 2026
CVE-2026-21510Microsoft Windows Shell Protection Mechanism Failure VulnerabilityKEVHIGH 8.8EPSS 26.2%10 February 2026
CVE-2026-1603Ivanti Endpoint Manager (EPM) Authentication Bypass VulnerabilityKEVHIGH 7.5EPSS 80.6%10 February 2026
CVE-2025-68686Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityKEVMEDIUM 5.9EPSS 29.6%10 February 2026
CVE-2026-1731BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection VulnerabilityKEVCRITICAL 9.9EPSS 89.5%6 February 2026
CVE-2026-21643Fortinet FortiClient EMS SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 94.1%6 February 2026
CVE-2025-15556Notepad++ Download of Code Without Integrity Check VulnerabilityKEVHIGH 7.7EPSS 1.71%3 February 2026
CVE-2026-1340Ivanti Endpoint Manager Mobile (EPMM) Code Injection VulnerabilityKEVCRITICAL 9.8EPSS 86.2%29 January 2026
CVE-2026-1281Ivanti Endpoint Manager Mobile (EPMM) Code Injection VulnerabilityKEVCRITICAL 9.8EPSS 81.8%29 January 2026
CVE-2025-40551SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 83.6%28 January 2026
CVE-2025-40536SolarWinds Web Help Desk Security Control Bypass VulnerabilityKEVCRITICAL 9.8EPSS 81.6%28 January 2026
CVE-2026-24858Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVCRITICAL 9.8EPSS 86.1%27 January 2026
CVE-2026-21509Microsoft Office Security Feature Bypass VulnerabilityKEVHIGH 7.8EPSS 72.6%26 January 2026
CVE-2026-24423SmarterTools SmarterMail Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.3EPSS 88.0%23 January 2026
CVE-2026-0770Langflow Inclusion of Functionality from Untrusted Control Sphere VulnerabilityKEVCRITICAL 9.8EPSS 63.4%23 January 2026
CVE-2026-23760SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVCRITICAL 9.3EPSS 96.4%22 January 2026
CVE-2026-20045Cisco Unified Communications Products Code Injection VulnerabilityKEVCRITICAL 9.8EPSS 4.48%21 January 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.