SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 101 of 786

CVESummaryPriorityPublished
CVE-2026-49060Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation.CRITICAL 9.8EPSS 0.51%11 June 2026
CVE-2026-42647Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection.CRITICAL 9.3EPSS 1.32%11 June 2026
CVE-2026-39494Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection.CRITICAL 9.3EPSS 0.39%11 June 2026
CVE-2026-12027Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.22%11 June 2026
CVE-2026-41005Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser…CRITICAL 9.0EPSS 0.13%11 June 2026
CVE-2026-49973Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin…CRITICAL 9.2EPSS 0.54%11 June 2026
CVE-2026-47174If an attacker can make a pull request build satisfy the deploy workflow’s main branch condition, the deploy job checks out the triggering workflow commit, builds it into a Docker image, pushes it as latest, and triggers Dokploy deployment.CRITICAL 9.5EPSS 0.31%11 June 2026
CVE-2026-47172If an attacker can open a pull request from a branch named main, the deploy workflow condition can treat the PR build as deployable and build the attacker-controlled commit in a privileged deployment context.CRITICAL 9.5EPSS 0.32%11 June 2026
CVE-2026-45177Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components.CRITICAL 9.1EPSS 0.50%11 June 2026
CVE-2026-49261Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node.CRITICAL 9.8EPSS 1.58%11 June 2026
CVE-2026-9648The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees.CRITICAL 9.1EPSS 0.22%11 June 2026
CVE-2026-11839Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc.CRITICAL 9.9EPSS 0.34%11 June 2026
CVE-2026-38581SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49).CRITICAL 9.8EPSS 0.33%11 June 2026
CVE-2026-7852Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc.CRITICAL 9.8EPSS 0.36%11 June 2026
CVE-2026-11561Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc.CRITICAL 9.8EPSS 0.45%11 June 2026
CVE-2026-4764A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a maliciously…CRITICAL 9.4EPSS 0.21%11 June 2026
CVE-2026-41699Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries.CRITICAL 9.8EPSS 0.43%11 June 2026
CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.8EPSS 95.5%11 June 2026
CVE-2026-46703Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code.CRITICAL 9.6EPSS 0.48%10 June 2026
CVE-2026-46695Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code.CRITICAL 10.0EPSS 0.29%10 June 2026
CVE-2026-50638Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections.CRITICAL 9.1EPSS 0.34%10 June 2026
CVE-2026-50566Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privileged / allowPrivilegeEscalation / dangerous-capability containers in the Fission function or builder namespace, scheduled under the executor's high-privilege…CRITICAL 9.9EPSS 0.29%10 June 2026
CVE-2026-50564Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged into the Kubernetes pod specs for runtime and builder pods.CRITICAL 9.9EPSS 0.27%10 June 2026
CVE-2026-50563Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly; the executor merges it into the executor-built podspec and creates a Deployment whose pods run the user's container image.CRITICAL 9.9EPSS 0.27%10 June 2026
CVE-2026-50545Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes.CRITICAL 9.9EPSS 0.30%10 June 2026
CVE-2026-46614The route was mounted on the same listener as user-defined HTTPTriggers (svc/router, port 8888), so any caller who could reach the router could invoke any function by guessing its metadata.name (and namespace), bypassing the host / path / method /…CRITICAL 9.8EPSS 0.35%10 June 2026
CVE-2026-20253Splunk Enterprise Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.8EPSS 96.9%10 June 2026
CVE-2026-53476An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability.CRITICAL 9.6EPSS 0.29%10 June 2026
CVE-2026-45558Because Roxy-WI then pushes the generated config to the load balancer and runs systemctl reload haproxy, an authenticated user with role ≤ 3 (user) can inject arbitrary HAProxy directives into the config that runs on every load balancer their group…CRITICAL 9.9EPSS 0.44%10 June 2026
CVE-2026-45556The validation chain (_replace_config_path_to_correct → check_is_conf) only requires the path to contain a hard-coded service substring (nginx/haproxy/apache2/httpd/keepalived) and the substring conf or cfg, and to not contain ...CRITICAL 9.9EPSS 0.37%10 June 2026
CVE-2026-45552Because the missing decorators omit both role and group checks, any logged-in user — including the default guest role 4 — can install/reconfigure exporters, WAF, and GeoIP databases on every server in the Roxy-WI database, regardless of tenant ownership.CRITICAL 9.9EPSS 0.27%10 June 2026
CVE-2026-45550The downstream SQL update functions update_smon, update_smonHttp, update_smonTcp, update_smonPing, update_smonDns (app/modules/db/smon.py:515-562) all execute WHERE smon_id = ? with no user_group filter.CRITICAL 9.1EPSS 0.20%10 June 2026
CVE-2025-6254The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8.CRITICAL 9.8EPSS 0.49%10 June 2026
CVE-2026-9067The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type,…CRITICAL 9.1EPSS 0.57%10 June 2026
CVE-2025-66276We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and laterCRITICAL 9.2EPSS 0.29%10 June 2026
CVE-2026-44963A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.CRITICAL 9.4EPSS 2.35%9 June 2026
CVE-2026-48303Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 10.0EPSS 0.55%9 June 2026
CVE-2026-47938Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation.CRITICAL 10.0EPSS 0.45%9 June 2026
CVE-2026-47928ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.6EPSS 2.32%9 June 2026
CVE-2026-36727An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.CRITICAL 9.1EPSS 0.36%9 June 2026
CVE-2026-36721A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.CRITICAL 9.8EPSS 0.27%9 June 2026
CVE-2026-30141A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file.CRITICAL 9.8EPSS 0.57%9 June 2026
CVE-2026-10045Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces.CRITICAL 9.8EPSS 0.21%9 June 2026
CVE-2026-34691Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.CRITICAL 9.3EPSS 0.36%9 June 2026
CVE-2026-49841The body-read loop is bounded by Content-Length rather than the buffer size, producing an attacker-controlled heap overflow of up to ~8 MiB -- before the HTTP basic-auth check runs.CRITICAL 9.8EPSS 0.39%9 June 2026
CVE-2026-49840A malicious or man-in-the-middle ESL peer can send a frame with a negative Content-Length to corrupt the heap of, or crash, any process linked against libesl, before the client has authenticated to that peer.CRITICAL 9.1EPSS 0.31%9 June 2026
CVE-2026-47643External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.75%9 June 2026
CVE-2026-47291Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 22.8%9 June 2026
CVE-2026-47281Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.6EPSS 0.76%9 June 2026
CVE-2026-45657Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 15.5%9 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.