SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 100 of 786

CVESummaryPriorityPublished
CVE-2026-38061Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.CRITICAL 9.8EPSS 1.05%15 June 2026
CVE-2026-38060Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.CRITICAL 9.8EPSS 1.05%15 June 2026
CVE-2026-36537ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange.CRITICAL 9.8EPSS 0.51%15 June 2026
CVE-2026-30121remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.CRITICAL 9.1EPSS 0.32%15 June 2026
CVE-2026-30120remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.CRITICAL 9.8EPSS 0.81%15 June 2026
CVE-2026-9862Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service.CRITICAL 9.8EPSS 0.99%15 June 2026
CVE-2026-52704Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion.CRITICAL 10.0EPSS 0.30%15 June 2026
CVE-2018-25436WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint.CRITICAL 9.3EPSS 0.66%15 June 2026
CVE-2026-5482Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution.CRITICAL 9.3EPSS 0.45%15 June 2026
CVE-2026-49757Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in.CRITICAL 9.2EPSS 0.61%15 June 2026
CVE-2026-8935The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a…CRITICAL 9.8EPSS 0.27%15 June 2026
CVE-2026-11526GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle.CRITICAL 9.8EPSS 1.35%14 June 2026
CVE-2026-12183Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.CRITICAL 9.3EPSS 0.44%13 June 2026
CVE-2026-11624In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabling users to specify permitted hosts at server startup.CRITICAL 9.4EPSS 0.22%13 June 2026
CVE-2026-53609In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator.CRITICAL 9.1EPSS 0.24%12 June 2026
CVE-2026-53519Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool.CRITICAL 9.1EPSS 1.93%12 June 2026
CVE-2026-46716From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command.CRITICAL 9.9EPSS 0.43%12 June 2026
CVE-2026-41157A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound write in the GPU user-space driver, leading to memory corruption and possible browser/GPU process crash.CRITICAL 9.8EPSS 0.36%12 June 2026
CVE-2026-44990Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript.CRITICAL 9.3EPSS 0.60%12 June 2026
CVE-2026-53407Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.CRITICAL 9.8EPSS 0.23%12 June 2026
CVE-2026-50101Because this credential remains valid indefinitely and cannot be reset or revoked by the legitimate owner, any party that obtains it through any exposure path can maintain persistent access to the device’s relay channel.CRITICAL 9.2EPSS 0.28%12 June 2026
CVE-2026-28742Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image.CRITICAL 9.2EPSS 0.33%12 June 2026
CVE-2026-48558SimpleHelp Authentication Bypass VulnerabilityKEVCRITICAL 9.5EPSS 64.3%12 June 2026
CVE-2026-50086The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication.CRITICAL 9.8EPSS 0.29%12 June 2026
CVE-2026-50085The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication.CRITICAL 9.8EPSS 0.41%12 June 2026
CVE-2026-50083The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical).CRITICAL 9.8EPSS 0.36%12 June 2026
CVE-2026-47691An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`).CRITICAL 10.0EPSS 0.39%12 June 2026
CVE-2026-45833A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the…CRITICAL 9.4EPSS 0.34%12 June 2026
CVE-2026-6853Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd.CRITICAL 9.8EPSS 0.35%12 June 2026
CVE-2026-54133jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures.CRITICAL 9.8EPSS 0.42%12 June 2026
CVE-2026-53787Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or…CRITICAL 9.3EPSS 5.64%12 June 2026
CVE-2026-47210Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly.promising / WebAssembly.Suspending).CRITICAL 9.8EPSS 1.80%12 June 2026
CVE-2026-47208Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability.CRITICAL 10.0EPSS 0.76%12 June 2026
CVE-2026-47140Both can be used from sandboxed code to reach host-side execution primitives.CRITICAL 10.0EPSS 0.82%12 June 2026
CVE-2026-47137However, the check uses strict equality (options.require === false), which is trivially bypassed by omitting the require option entirely.CRITICAL 10.0EPSS 0.38%12 June 2026
CVE-2026-47131Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError constructor can be obtained,…CRITICAL 10.0EPSS 0.62%12 June 2026
CVE-2026-45674Netty is a network application framework for development of protocol servers and clients.CRITICAL 10.0EPSS 0.30%12 June 2026
CVE-2026-10557The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices.CRITICAL 9.3EPSS 0.35%12 June 2026
CVE-2026-11849The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database.CRITICAL 9.3EPSS 0.35%12 June 2026
CVE-2026-50628A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address.CRITICAL 9.8EPSS 0.68%12 June 2026
CVE-2026-50627This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks.CRITICAL 9.1EPSS 0.45%12 June 2026
CVE-2026-49875Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution.CRITICAL 9.8EPSS 0.53%12 June 2026
CVE-2026-11535An unauthorized access vulnerability exists in the PcSuite APP.CRITICAL 9.4EPSS 0.15%12 June 2026
CVE-2026-48611Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.CRITICAL 9.8EPSS 3.86%12 June 2026
CVE-2026-47370A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.CRITICAL 9.9EPSS 0.83%12 June 2026
CVE-2026-47369A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.CRITICAL 9.9EPSS 0.30%12 June 2026
CVE-2026-47367A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.CRITICAL 9.9EPSS 0.83%12 June 2026
CVE-2026-47365Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.CRITICAL 9.9EPSS 0.41%12 June 2026
CVE-2026-45060Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection.CRITICAL 9.8EPSS 0.36%11 June 2026
CVE-2026-42846Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source.CRITICAL 9.8EPSS 0.60%11 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.