SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,238 results · page 10 of 785

CVESummaryPriorityPublished
CVE-2026-82431Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered.CRITICAL 9.8EPSS 0.48%14 September 2026
CVE-2026-57125Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools.CRITICAL 9.8EPSS 0.41%14 September 2026
CVE-2026-57123Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS rebinding, with impact determined by the registered file, shell, and code-execution tools.CRITICAL 9.8EPSS 0.47%14 September 2026
CVE-2026-90961The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability.CRITICAL 9.3EPSS 0.46%14 September 2026
CVE-2026-82441Separately, on acquiring leadership a Nimbus compares the dependency keys of all active topologies against the blobstore contents and surrenders leadership if any is missing.CRITICAL 9.1EPSS 0.42%14 September 2026
CVE-2026-82439Function names come from the client and are not constrained to functions any topology has registered, so the number of retained entries is bounded only by the number of distinct names an attacker chooses to send, and each retained entry holds the name…CRITICAL 9.8EPSS 0.52%14 September 2026
CVE-2026-73370Incorrect Authorization vulnerability in Apache Syncope.CRITICAL 9.8EPSS 0.48%14 September 2026
CVE-2026-90937froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives.CRITICAL 9.4EPSS 0.26%14 September 2026
CVE-2026-78330Incorrect privilege assignment vulnerability in Apache Syncope.CRITICAL 9.8EPSS 0.60%14 September 2026
CVE-2026-78299In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.CRITICAL 9.1EPSS 0.35%14 September 2026
CVE-2026-77181Incorrect Authorization vulnerability in Apache Syncope.CRITICAL 9.8EPSS 0.48%14 September 2026
CVE-2026-77051Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.CRITICAL 9.8EPSS 0.56%14 September 2026
CVE-2026-75030Missing Authorization vulnerability in Apache Syncope.CRITICAL 9.8EPSS 0.58%14 September 2026
CVE-2026-73668Incorrect Authorization vulnerability in Apache Syncope.CRITICAL 9.8EPSS 0.48%14 September 2026
CVE-2026-73579Incorrect Authorization vulnerability in Apache Syncope.CRITICAL 9.8EPSS 0.48%14 September 2026
CVE-2026-73470Improper Privilege Management vulnerability in Apache Syncope.CRITICAL 9.8EPSS 0.48%14 September 2026
CVE-2026-12258The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address.CRITICAL 9.2EPSS 0.40%14 September 2026
CVE-2026-90919LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads().CRITICAL 9.3EPSS 1.01%14 September 2026
CVE-2026-21391An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden.CRITICAL 9.5EPSS 0.45%14 September 2026
CVE-2026-90898One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image). transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.CRITICAL 9.8EPSS 0.34%14 September 2026
CVE-2026-87802Improper verification of cryptographic signature vulnerability in Apache Syncope.CRITICAL 9.1EPSS 0.26%14 September 2026
CVE-2026-87785Authentication bypass by spoofing vulnerability in Apache Syncope.CRITICAL 9.1EPSS 0.51%14 September 2026
CVE-2026-86460Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions.CRITICAL 9.8EPSS 0.56%14 September 2026
CVE-2026-82232Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope.CRITICAL 9.8EPSS 0.56%14 September 2026
CVE-2026-90693This manipulation of the argument Primary/Secondary causes stack-based buffer overflow.CRITICAL 9.4EPSS 0.47%14 September 2026
CVE-2026-90692A vulnerability was detected in D-Link DIR-878 120B05.CRITICAL 9.4EPSS 0.47%14 September 2026
CVE-2026-85192Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax.CRITICAL 9.4EPSS 0.48%14 September 2026
CVE-2026-90680The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow.CRITICAL 9.4EPSS 0.51%14 September 2026
CVE-2026-81648The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server,…CRITICAL 10.0EPSS 0.28%13 September 2026
CVE-2026-90562Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.CRITICAL 9.2EPSS 0.42%13 September 2026
CVE-2026-90561Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text.CRITICAL 9.3EPSS 0.24%13 September 2026
CVE-2026-90647ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode).CRITICAL 9.1EPSS 0.14%12 September 2026
CVE-2026-90558sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit.CRITICAL 9.3EPSS 0.51%12 September 2026
CVE-2026-78159The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function.CRITICAL 9.8EPSS 0.76%12 September 2026
CVE-2026-78006The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function.CRITICAL 9.8EPSS 0.78%12 September 2026
CVE-2026-85681The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing…CRITICAL 9.8EPSS 0.28%12 September 2026
CVE-2026-84171The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary…CRITICAL 9.8EPSS 0.37%12 September 2026
CVE-2026-82845The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped…CRITICAL 9.9EPSS 0.35%12 September 2026
CVE-2026-81402The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a…CRITICAL 9.8EPSS 0.45%12 September 2026
CVE-2026-77006The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a…CRITICAL 9.6EPSS 0.18%12 September 2026
CVE-2026-77005The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to…CRITICAL 9.6EPSS 0.30%12 September 2026
CVE-2026-75800The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as…CRITICAL 9.8EPSS 0.42%12 September 2026
CVE-2026-87719GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search…CRITICAL 9.9EPSS 0.61%12 September 2026
CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal VulnerabilityKEVCRITICAL 10.0EPSS 14.6%12 September 2026
CVE-2026-90456A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.CRITICAL 9.2EPSS 0.25%11 September 2026
CVE-2026-89713In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC before it takes inode_lock().CRITICAL 9.1EPSS 0.60%11 September 2026
CVE-2026-89712In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...).CRITICAL 9.8EPSS 0.70%11 September 2026
CVE-2026-89708In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown After a DESTROY_SESSION the per-session teardown path can free a session while rpciod still holds an inflight…CRITICAL 9.8EPSS 0.43%11 September 2026
CVE-2026-89703In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations nfsd4_drop_revoked_stid() handles FREE_STATEID for admin-revoked delegations but does not set SC_STATUS_FREED before…CRITICAL 9.8EPSS 0.61%11 September 2026
CVE-2026-89702In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_locallen The nfsd_fh_verify and nfsd_fh_verify_err tracepoints declare the server sockaddr slot sized by xpt_remotelen but fill it from…CRITICAL 9.8EPSS 0.46%11 September 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.