SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

392,197 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

17,375 results · page 1 of 348

CVESummaryPriorityPublished
CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal VulnerabilityKEVCRITICAL 10.0EPSS 11.1%12 September 2026
CVE-2026-60004Gitea Code Injection VulnerabilityKEVCRITICAL 9.8EPSS 86.8%26 August 2026
CVE-2026-64849MLflow Server-Side Request Forgery VulnerabilityKEVCRITICAL 9.3EPSS 16.4%17 August 2026
CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection VulnerabilityKEVHIGH 8.9EPSS 32.4%13 August 2026
CVE-2026-71362Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.CRITICAL 9.1EPSS 25.1%11 August 2026
CVE-2026-48376is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass.MEDIUM 5.4EPSS 15.5%11 August 2026
CVE-2026-72898Metabase SQL Injection VulnerabilityKEVCRITICAL 10.0EPSS 94.2%10 August 2026
CVE-2026-64638WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.HIGH 8.9EPSS 31.2%7 August 2026
CVE-2026-15733A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier.CRITICAL 9.8EPSS 13.5%6 August 2026
CVE-2026-18577N-able N-central Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVHIGH 8.2EPSS 54.1%2 August 2026
CVE-2026-18556N-able N-central Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVHIGH 8.2EPSS 40.2%1 August 2026
CVE-2026-66066In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation.CRITICAL 9.5EPSS 27.9%30 July 2026
CVE-2026-59310Broadcom VMware vCenter Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS 45.9%30 July 2026
CVE-2026-20316Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityKEVMEDIUM 5.3EPSS 11.2%29 July 2026
CVE-2026-63077JetBrains TeamCity Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 86.5%27 July 2026
CVE-2026-61511vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying…CRITICAL 9.3EPSS 70.8%27 July 2026
CVE-2026-16723A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83.CRITICAL 9.0EPSS 16.0%23 July 2026
CVE-2026-62144An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server.CRITICAL 9.1EPSS 20.8%22 July 2026
CVE-2026-16232Check Point SmartConsole Improper Authentication VulnerabilityKEVCRITICAL 9.3EPSS 72.1%22 July 2026
CVE-2026-63030WordPress Core Interpretation Conflict VulnerabilityKEVCRITICAL 9.8EPSS 97.3%17 July 2026
CVE-2026-60137WordPress Core SQL Injection VulnerabilityKEVMEDIUM 5.9EPSS 78.3%17 July 2026
CVE-2026-9198IBM Langflow Code Injection VulnerabilityKEVCRITICAL 9.8EPSS 60.6%17 July 2026
CVE-2026-9586Sangoma Switchvox SQL Injection VulnerabilityKEVCRITICAL 9.3EPSS 11.8%17 July 2026
CVE-2026-48319ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.1EPSS 32.3%14 July 2026
CVE-2026-15410SonicWall SMA1000 Appliances Code Injection VulnerabilityKEVHIGH 7.2EPSS 11.8%14 July 2026
CVE-2026-15409SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityKEVCRITICAL 10.0EPSS 84.5%14 July 2026
CVE-2026-55040Microsoft SharePoint Weak Authentication VulnerabilityKEVCRITICAL 9.1EPSS 50.6%14 July 2026
CVE-2026-58644Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.8EPSS 15.9%14 July 2026
CVE-2026-56164Microsoft SharePoint Server Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.8EPSS 26.6%14 July 2026
CVE-2026-50522Microsoft SharePoint Deserialization of Untrusted Data Vulnerability KEVCRITICAL 9.8EPSS 85.4%14 July 2026
CVE-2026-6875ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform.CRITICAL 9.5EPSS 77.6%13 July 2026
CVE-2026-3576The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0.HIGH 7.2EPSS 12.9%11 July 2026
CVE-2026-56291Balbooa Forms Unrestricted Upload of File with Dangerous Type VulnerabilityKEVCRITICAL 10.0EPSS 14.9%9 July 2026
CVE-2026-43825Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document categorization module; introduced in OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(InputStream)…HIGH 7.3EPSS 13.9%6 July 2026
CVE-2026-48282Adobe ColdFusion Path Traversal VulnerabilityKEVCRITICAL 10.0EPSS 42.4%30 June 2026
CVE-2026-8451Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDPHIGH 8.8EPSS 15.7%30 June 2026
CVE-2026-56290Joomlack Page Builder Improper Access Control VulnerabilityKEVCRITICAL 10.0EPSS 30.4%29 June 2026
CVE-2026-48939iCagenda Unrestricted Upload of File with Dangerous Type VulnerabilityKEVCRITICAL 10.0EPSS 20.1%20 June 2026
CVE-2026-48908JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type VulnerabilityKEVCRITICAL 10.0EPSS 15.1%20 June 2026
CVE-2026-12569PTC Windchill and FlexPLM Improper Input Validation VulnerabilityKEVCRITICAL 9.3EPSS 40.6%18 June 2026
CVE-2026-50656Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".HIGH 7.0EPSS 11.4%16 June 2026
CVE-2026-20262Cisco Catalyst SD-WAN Manager Directory or Path Traversal VulnerabilityKEVMEDIUM 6.5EPSS 28.2%15 June 2026
CVE-2026-48558SimpleHelp Authentication Bypass VulnerabilityKEVCRITICAL 9.5EPSS 64.3%12 June 2026
CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.8EPSS 95.5%11 June 2026
CVE-2026-20253Splunk Enterprise Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.8EPSS 96.9%10 June 2026
CVE-2026-20251In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a…HIGH 8.8EPSS 32.2%10 June 2026
CVE-2026-53435In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle…HIGH 8.8EPSS 53.1%10 June 2026
CVE-2026-49160Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.HIGH 7.5EPSS 53.8%9 June 2026
CVE-2026-47291Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 22.8%9 June 2026
CVE-2026-45657Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 15.5%9 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.