SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

392,961 CVEs1,710 in CISA KEV17,375 with EPSS ≥ 10%Updated 15 September 2026

17,375 results · page 5 of 348

CVESummaryPriorityPublished
CVE-2026-3612A vulnerability was determined in Wavlink WL-NU516U1 V240425.HIGH 7.3EPSS 12.7%6 March 2026
CVE-2026-27944Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header.CRITICAL 9.8EPSS 22.2%5 March 2026
CVE-2026-20131Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 10.0EPSS 33.4%4 March 2026
CVE-2026-20079Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVCRITICAL 10.0EPSS 75.8%4 March 2026
CVE-2026-27446Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis.CRITICAL 9.3EPSS 10.0%4 March 2026
CVE-2026-28289A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width…HIGH 8.1EPSS 31.1%3 March 2026
CVE-2026-1492The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including,…CRITICAL 9.8EPSS 28.0%3 March 2026
CVE-2026-28208Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix.MEDIUM 5.9EPSS 12.0%26 February 2026
CVE-2026-27966Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`).CRITICAL 9.8EPSS 33.7%26 February 2026
CVE-2026-22719Broadcom VMware Aria Operations Command Injection VulnerabilityKEVHIGH 8.1EPSS 17.4%25 February 2026
CVE-2026-21902An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root.CRITICAL 9.3EPSS 17.7%25 February 2026
CVE-2026-20133Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityKEVHIGH 7.5EPSS 31.4%25 February 2026
CVE-2026-20127Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass VulnerabilityKEVCRITICAL 10.0EPSS 88.2%25 February 2026
CVE-2026-20122Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs VulnerabilityKEVMEDIUM 5.4EPSS 24.6%25 February 2026
CVE-2026-27483Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution.HIGH 8.8EPSS 11.1%24 February 2026
CVE-2026-3066This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/PlatformUtils.java of the component Cloud Compliance Scanning.LOW 2.1EPSS 11.8%24 February 2026
CVE-2026-3065A vulnerability was detected in HummerRisk up to 1.5.0.LOW 2.1EPSS 30.5%24 February 2026
CVE-2026-3064A security vulnerability has been detected in HummerRisk up to 1.5.0.LOW 2.1EPSS 19.5%24 February 2026
CVE-2026-26046A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection.HIGH 7.2EPSS 11.9%21 February 2026
CVE-2026-2043Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability.HIGH 8.8EPSS 72.9%20 February 2026
CVE-2026-2041Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability.HIGH 8.8EPSS 73.4%20 February 2026
CVE-2026-2824Executing a manipulation of the argument destination can lead to command injection.LOW 2.1EPSS 15.3%20 February 2026
CVE-2026-2823A vulnerability was detected in Comfast CF-E7 2.6.0.9.LOW 2.1EPSS 16.8%20 February 2026
CVE-2026-26980Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database.HIGH 7.5EPSS 70.2%20 February 2026
CVE-2026-2670A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA…HIGH 7.3EPSS 12.3%18 February 2026
CVE-2026-2329An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get.CRITICAL 9.3EPSS 40.0%18 February 2026
CVE-2026-22769Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials VulnerabilityKEVCRITICAL 10.0EPSS 13.1%17 February 2026
CVE-2026-2615Executing a manipulation of the argument del_flag can lead to command injection.HIGH 7.3EPSS 11.6%17 February 2026
CVE-2026-2537A vulnerability was identified in Comfast CF-E4 2.6.0.1.LOW 2.0EPSS 24.5%16 February 2026
CVE-2026-2535A vulnerability was found in Comfast CF-N1 V2 2.6.0.2.LOW 2.1EPSS 13.5%16 February 2026
CVE-2026-2534A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2.LOW 2.1EPSS 13.0%16 February 2026
CVE-2026-2441Google Chromium CSS Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 22.4%13 February 2026
CVE-2026-26190Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses.CRITICAL 9.8EPSS 36.9%13 February 2026
CVE-2026-1357The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123.CRITICAL 9.8EPSS 32.7%11 February 2026
CVE-2026-21513Microsoft MSHTML Framework Protection Mechanism Failure VulnerabilityKEVHIGH 8.8EPSS 15.6%10 February 2026
CVE-2026-21510Microsoft Windows Shell Protection Mechanism Failure VulnerabilityKEVHIGH 8.8EPSS 26.2%10 February 2026
CVE-2026-21249External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.LOW 3.3EPSS 11.1%10 February 2026
CVE-2026-20841Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.HIGH 7.8EPSS 11.8%10 February 2026
CVE-2026-0652On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization.HIGH 8.7EPSS 21.9%10 February 2026
CVE-2026-1603Ivanti Endpoint Manager (EPM) Authentication Bypass VulnerabilityKEVHIGH 7.5EPSS 80.6%10 February 2026
CVE-2025-68686Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityKEVMEDIUM 5.9EPSS 29.6%10 February 2026
CVE-2026-25939From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on actions.CRITICAL 9.3EPSS 11.7%9 February 2026
CVE-2026-25895A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem.CRITICAL 9.5EPSS 11.2%9 February 2026
CVE-2026-2184A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73.MEDIUM 6.9EPSS 10.3%8 February 2026
CVE-2026-2131A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0.LOW 2.1EPSS 15.6%8 February 2026
CVE-2026-1731BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection VulnerabilityKEVCRITICAL 9.9EPSS 89.5%6 February 2026
CVE-2026-21643Fortinet FortiClient EMS SQL Injection VulnerabilityKEVCRITICAL 9.8EPSS 94.1%6 February 2026
CVE-2026-2000A vulnerability was found in DCN DCME-320 up to 20260121.LOW 2.0EPSS 17.8%6 February 2026
CVE-2026-25512Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execution (RCE) vulnerability in Group-Office.CRITICAL 9.4EPSS 18.5%4 February 2026
CVE-2026-1207Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter.MEDIUM 5.4EPSS 13.0%3 February 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.