SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

17,375 results · page 3 of 348

CVESummaryPriorityPublished
CVE-2026-34649Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service.HIGH 7.5EPSS 14.4%12 May 2026
CVE-2026-34648Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service.HIGH 7.5EPSS 22.6%12 May 2026
CVE-2026-41089Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 79.6%12 May 2026
CVE-2026-33112Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.HIGH 8.8EPSS 32.7%12 May 2026
CVE-2026-43500In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the…HIGH 7.8EPSS 92.9%11 May 2026
CVE-2026-7864SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.MEDIUM 6.9EPSS 17.0%8 May 2026
CVE-2026-44338PraisonAI is a multi-agent teams system.HIGH 7.3EPSS 28.6%8 May 2026
CVE-2026-44127SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of…HIGH 8.8EPSS 15.7%8 May 2026
CVE-2026-43284In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb.HIGH 8.8EPSS 93.2%8 May 2026
CVE-2026-42271BerriAI LiteLLM Command Injection VulnerabilityKEVHIGH 8.7EPSS 83.6%8 May 2026
CVE-2026-42208BerriAI LiteLLM SQL Injection VulnerabilityKEVCRITICAL 9.3EPSS 89.4%8 May 2026
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation VulnerabilityKEVHIGH 7.2EPSS 34.5%7 May 2026
CVE-2026-5786An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.HIGH 8.8EPSS 11.8%7 May 2026
CVE-2026-34474Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6.HIGH 7.5EPSS 24.7%6 May 2026
CVE-2026-0300Palo Alto Networks PAN-OS Out-of-bounds Write VulnerabilityKEVCRITICAL 9.3EPSS 31.7%6 May 2026
CVE-2026-36356The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.CRITICAL 9.1EPSS 13.5%5 May 2026
CVE-2026-23918Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.HIGH 8.8EPSS 49.7%4 May 2026
CVE-2026-41940WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.3EPSS 98.5%29 April 2026
CVE-2026-27760OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter.CRITICAL 9.2EPSS 34.6%28 April 2026
CVE-2026-41268Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability.CRITICAL 9.8EPSS 13.8%23 April 2026
CVE-2026-25874LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client…CRITICAL 9.3EPSS 15.5%23 April 2026
CVE-2026-3844The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4.CRITICAL 9.8EPSS 27.7%23 April 2026
CVE-2026-41679Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration.CRITICAL 10.0EPSS 18.9%23 April 2026
CVE-2026-41176The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself.CRITICAL 9.2EPSS 32.7%23 April 2026
CVE-2026-31431Linux Kernel Incorrect Resource Transfer Between Spheres VulnerabilityKEVHIGH 7.8EPSS 99.9%22 April 2026
CVE-2026-40933Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution.CRITICAL 9.9EPSS 12.0%21 April 2026
CVE-2026-40372Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.1EPSS 11.2%21 April 2026
CVE-2026-33626Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module.HIGH 7.5EPSS 45.3%20 April 2026
CVE-2026-3518OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the…HIGH 7.2EPSS 19.9%20 April 2026
CVE-2026-3517OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in…HIGH 7.2EPSS 18.2%20 April 2026
CVE-2026-6483A vulnerability was found in Wavlink WL-WN530H4 20220721.HIGH 7.3EPSS 13.4%17 April 2026
CVE-2026-20147A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.CRITICAL 9.9EPSS 10.4%15 April 2026
CVE-2026-27305ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read.HIGH 8.6EPSS 26.3%14 April 2026
CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityKEVCRITICAL 9.8EPSS 72.7%14 April 2026
CVE-2026-32202Microsoft Windows Protection Mechanism Failure VulnerabilityKEVMEDIUM 4.3EPSS 63.7%14 April 2026
CVE-2026-32201Microsoft SharePoint Server Improper Input Validation VulnerabilityKEVMEDIUM 6.5EPSS 43.4%14 April 2026
CVE-2026-20945Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.MEDIUM 5.4EPSS 19.1%14 April 2026
CVE-2026-39813A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.CRITICAL 9.8EPSS 22.2%14 April 2026
CVE-2026-39808Fortinet FortiSandbox OS Command Injection VulnerabilityKEVCRITICAL 9.8EPSS 92.8%14 April 2026
CVE-2026-6195A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024.HIGH 8.9EPSS 13.5%13 April 2026
CVE-2026-40217LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.HIGH 8.8EPSS 15.1%10 April 2026
CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data VulnerabilityKEVHIGH 7.5EPSS 98.6%9 April 2026
CVE-2026-39987Marimo Remote Code Execution VulnerabilityKEVCRITICAL 9.3EPSS 98.9%9 April 2026
CVE-2026-5854A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024.HIGH 8.9EPSS 16.6%9 April 2026
CVE-2026-5853A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024.HIGH 8.9EPSS 13.5%9 April 2026
CVE-2026-5852A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024.HIGH 8.9EPSS 13.5%9 April 2026
CVE-2026-5851The manipulation of the argument enable results in os command injection.HIGH 8.9EPSS 13.4%9 April 2026
CVE-2026-5850A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024.HIGH 8.9EPSS 15.1%9 April 2026
CVE-2026-33439Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter.CRITICAL 9.3EPSS 10.0%7 April 2026
CVE-2026-4631Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization.CRITICAL 9.8EPSS 15.5%7 April 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.