SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

17,375 results · page 2 of 348

CVESummaryPriorityPublished
CVE-2026-45502Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.MEDIUM 5.0EPSS 20.3%9 June 2026
CVE-2026-45484Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.HIGH 8.8EPSS 35.2%9 June 2026
CVE-2026-25089Fortinet FortiSandbox OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 76.1%9 June 2026
CVE-2026-10727An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as rootHIGH 7.2EPSS 13.6%9 June 2026
CVE-2026-10523An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative accessCRITICAL 9.8EPSS 51.9%9 June 2026
CVE-2026-10520Ivanti Sentry OS Command Injection VulnerabilityKEVCRITICAL 10.0EPSS 99.9%9 June 2026
CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.HIGH 7.5EPSS 34.3%8 June 2026
CVE-2026-46442Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node.CRITICAL 9.4EPSS 36.3%8 June 2026
CVE-2026-50751Check Point Security Gateway Improper Authentication VulnerabilityKEVCRITICAL 9.3EPSS 83.8%8 June 2026
CVE-2026-48907Widget Factory Joomla Content Editor Improper Access Control VulnerabilityKEVCRITICAL 10.0EPSS 78.1%5 June 2026
CVE-2026-20245Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output VulnerabilityKEVHIGH 7.8EPSS 25.3%4 June 2026
CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption VulnerabilityKEVHIGH 7.5EPSS 40.0%4 June 2026
CVE-2026-8037Progress LoadMaster Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 99.6%4 June 2026
CVE-2026-20230Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) VulnerabilityKEVHIGH 8.6EPSS 88.2%3 June 2026
CVE-2026-0826In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.CRITICAL 9.2EPSS 32.2%1 June 2026
CVE-2026-49373In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settingsHIGH 8.8EPSS 27.1%29 May 2026
CVE-2026-8732The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0.CRITICAL 9.8EPSS 22.7%29 May 2026
CVE-2026-46817Oracle E-Business Suite Improper Privilege Management VulnerabilityKEVCRITICAL 9.8EPSS 13.0%28 May 2026
CVE-2026-45087Dalfox is a powerful open-source XSS scanner and utility focused on automation.CRITICAL 10.0EPSS 13.0%27 May 2026
CVE-2026-48710Kludex Starlette HTTP Request/Response Smuggling VulnerabilityKEVMEDIUM 6.5EPSS 36.3%26 May 2026
CVE-2026-4480A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters.CRITICAL 9.0EPSS 13.9%26 May 2026
CVE-2026-45247Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.3EPSS 27.5%26 May 2026
CVE-2026-9534Executing a manipulation of the argument PIN can lead to os command injection.LOW 2.1EPSS 10.8%26 May 2026
CVE-2026-9533A vulnerability was detected in Totolink CA750-PoE 6.2c.510.LOW 2.1EPSS 10.8%26 May 2026
CVE-2026-9532A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510.LOW 2.1EPSS 10.8%26 May 2026
CVE-2026-9531A weakness has been identified in Totolink CA750-PoE 6.2c.510.LOW 2.1EPSS 10.8%26 May 2026
CVE-2026-9515A vulnerability was detected in Totolink CA750-PoE 6.2c.510.LOW 2.1EPSS 10.8%26 May 2026
CVE-2026-9514A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510.LOW 2.1EPSS 10.8%25 May 2026
CVE-2026-9441Performing a manipulation of the argument rootAPmac results in command injection.LOW 2.1EPSS 11.7%25 May 2026
CVE-2026-9440A vulnerability was identified in Edimax BR-6478AC 1.23.LOW 2.1EPSS 13.0%25 May 2026
CVE-2026-45659Microsoft SharePoint Server Deserialization of Untrusted Data VulnerabilityKEVHIGH 8.8EPSS 76.1%22 May 2026
CVE-2026-9256NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module.CRITICAL 9.2EPSS 10.9%22 May 2026
CVE-2026-34910Ubiquiti UniFi OS Improper Input Validation VulnerabilityKEVCRITICAL 10.0EPSS 87.5%22 May 2026
CVE-2026-34909Ubiquiti UniFi OS Path Traversal VulnerabilityKEVCRITICAL 10.0EPSS 65.0%22 May 2026
CVE-2026-34908Ubiquiti UniFi OS Improper Access Control VulnerabilityKEVCRITICAL 10.0EPSS 85.2%22 May 2026
CVE-2026-34926Trend Micro Apex One (On-Premise) Directory Traversal VulnerabilityKEVMEDIUM 6.7EPSS 12.7%21 May 2026
CVE-2026-48172LiteSpeed cPanel Plugin Privilege Escalation VulnerabilityKEVCRITICAL 10.0EPSS 18.9%21 May 2026
CVE-2026-9082Drupal Core SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 87.9%20 May 2026
CVE-2026-23734Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal.CRITICAL 9.3EPSS 19.6%20 May 2026
CVE-2026-45498Microsoft Defender Denial of Service VulnerabilityKEVHIGH 7.5EPSS 63.1%20 May 2026
CVE-2026-45434Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06.CRITICAL 9.8EPSS 22.4%19 May 2026
CVE-2026-45829A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true…CRITICAL 10.0EPSS 12.4%18 May 2026
CVE-2026-2652A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI).HIGH 8.6EPSS 20.8%15 May 2026
CVE-2026-42897Microsoft Exchange Server Cross-Site Scripting VulnerabilityKEVMEDIUM 6.1EPSS 71.2%14 May 2026
CVE-2026-20182Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityKEVCRITICAL 10.0EPSS 91.5%14 May 2026
CVE-2026-8181The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1.CRITICAL 9.8EPSS 14.6%14 May 2026
CVE-2026-0257Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityKEVHIGH 7.8EPSS 95.2%13 May 2026
CVE-2026-44578From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests.HIGH 8.6EPSS 38.9%13 May 2026
CVE-2026-42945NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module.CRITICAL 9.2EPSS 68.0%13 May 2026
CVE-2026-34650Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service.HIGH 7.5EPSS 15.9%12 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.