SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 103 of 786

CVESummaryPriorityPublished
CVE-2026-45758On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI.CRITICAL 9.6EPSS 0.28%5 June 2026
CVE-2026-11420Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on the server filesystem and to read package archive…CRITICAL 10.0EPSS 0.71%5 June 2026
CVE-2026-11419A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload requests.CRITICAL 9.4EPSS 0.55%5 June 2026
CVE-2026-11414A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service.CRITICAL 10.0EPSS 0.48%5 June 2026
CVE-2026-46496A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of the `<video-player>` component.CRITICAL 9.3EPSS 0.23%5 June 2026
CVE-2026-46399The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability.CRITICAL 9.4EPSS 0.29%5 June 2026
CVE-2026-46396A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of `<iframe>` elements.CRITICAL 9.3EPSS 0.23%5 June 2026
CVE-2026-46395Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated attacker to extract the system’s private signing key and forge arbitrary…CRITICAL 9.3EPSS 0.29%5 June 2026
CVE-2026-46389An attacker who can reach the Keycloak token endpoint and knows a `client_id` using this authenticator can authenticate as that client with any `client_secret` value and obtain OAuth2 tokens scoped to the client's service account.CRITICAL 9.8EPSS 0.34%5 June 2026
CVE-2026-10580The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4.CRITICAL 9.8EPSS 2.95%5 June 2026
CVE-2026-45750Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in the Termix File Manager component unsafely processes the path parameter and embeds it into a shell command executed over the active SSH session.CRITICAL 9.0EPSS 0.29%5 June 2026
CVE-2026-45748The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3.2 builds an SSH tunnel command by interpolating user-controlled host record fields (`endpointIP`, `endpointUsername`, `password`) directly into a shell command without escaping,…CRITICAL 9.8EPSS 1.73%5 June 2026
CVE-2026-45746Prior to version 2.3.2, the File Manager functionality in Termix contains a critical Broken Access Control vulnerability due to improper validation of the sessionId parameter.CRITICAL 9.0EPSS 0.39%5 June 2026
CVE-2026-45744Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in Termix is vulnerable to OS command injection.CRITICAL 9.9EPSS 2.01%5 June 2026
CVE-2026-36500An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.CRITICAL 9.1EPSS 0.69%5 June 2026
CVE-2025-71318A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and…CRITICAL 9.3EPSS 0.53%5 June 2026
CVE-2025-71317NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access.CRITICAL 9.3EPSS 0.43%5 June 2026
CVE-2026-9270DataDog::DogStatsd versions through 0.07 for Perl allow metric injections.CRITICAL 9.1EPSS 0.33%5 June 2026
CVE-2026-11362DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.CRITICAL 9.8EPSS 0.45%5 June 2026
CVE-2026-10879DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders.CRITICAL 9.8EPSS 0.48%5 June 2026
CVE-2026-6274Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd.CRITICAL 9.8EPSS 0.46%5 June 2026
CVE-2026-49777Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted.CRITICAL 10.0EPSS 1.66%5 June 2026
CVE-2026-48907Widget Factory Joomla Content Editor Improper Access Control VulnerabilityKEVEXPLOIT ×2CRITICAL 10.0EPSS 78.1%5 June 2026
CVE-2026-7763A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or…CRITICAL 9.8EPSS 0.54%5 June 2026
CVE-2026-7762A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or…CRITICAL 9.8EPSS 0.57%5 June 2026
CVE-2026-11293Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.20%5 June 2026
CVE-2026-11282Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.24%5 June 2026
CVE-2026-11250Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.CRITICAL 9.6EPSS 0.24%5 June 2026
CVE-2026-48567Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 1.03%4 June 2026
CVE-2026-11213Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.19%4 June 2026
CVE-2026-11207Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic.CRITICAL 9.6EPSS 0.22%4 June 2026
CVE-2026-11198Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file.CRITICAL 9.6EPSS 0.22%4 June 2026
CVE-2026-11167Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11165Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11163Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11153Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page.CRITICAL 9.1EPSS 0.26%4 June 2026
CVE-2026-11152Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11146Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11131Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11120Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.27%4 June 2026
CVE-2026-11119Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11114Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11113Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.27%4 June 2026
CVE-2026-11112Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension.CRITICAL 9.6EPSS 0.22%4 June 2026
CVE-2026-11100Use after free in File Input in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.26%4 June 2026
CVE-2026-11095Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.28%4 June 2026
CVE-2026-11094Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11088Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.32%4 June 2026
CVE-2026-11082Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%4 June 2026
CVE-2026-11070Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via malicious network traffic.CRITICAL 9.6EPSS 0.22%4 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.