SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 105 of 786

CVESummaryPriorityPublished
CVE-2026-46266In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. socket(AF_INET, SOCK_RAW,…CRITICAL 9.1EPSS 0.37%3 June 2026
CVE-2026-46244In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset…CRITICAL 9.1EPSS 0.32%3 June 2026
CVE-2026-36748RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.CRITICAL 9.0EPSS 0.30%3 June 2026
CVE-2026-36576An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.CRITICAL 9.8EPSS 1.49%3 June 2026
CVE-2026-5241A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization.CRITICAL 9.6EPSS 0.60%3 June 2026
CVE-2026-35075An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.CRITICAL 9.3EPSS 0.47%3 June 2026
CVE-2026-47065ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed.CRITICAL 9.8EPSS 0.50%3 June 2026
CVE-2026-35482Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an authenticated administrator to execute arbitrary operating system commands on the server.CRITICAL 9.1EPSS 0.28%2 June 2026
CVE-2026-32625Any authenticated user can create a malicious MCP server configuration with a URL pointing to an attacker-controlled domain containing environment variable references, causing the LibreChat server to connect to the attacker's server and transmit…CRITICAL 9.6EPSS 2.94%2 June 2026
CVE-2026-49448Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST.CRITICAL 9.8EPSS 0.40%2 June 2026
CVE-2026-42849Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage.CRITICAL 9.3EPSS 0.36%2 June 2026
CVE-2026-5076The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1.CRITICAL 9.8EPSS 0.42%2 June 2026
CVE-2026-38967CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.CRITICAL 9.8EPSS 0.33%2 June 2026
CVE-2026-42074Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted principal per the project's own threat model) can set it to true in any tool_use response.CRITICAL 9.3EPSS 0.59%2 June 2026
CVE-2026-0611Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform…CRITICAL 9.2EPSS 0.66%2 June 2026
CVE-2026-47117OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path.CRITICAL 9.3EPSS 0.92%2 June 2026
CVE-2026-7198CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and…CRITICAL 9.8EPSS 0.44%2 June 2026
CVE-2026-42684Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection.CRITICAL 9.3EPSS 0.30%2 June 2026
CVE-2026-34906Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE).CRITICAL 9.3EPSS 0.56%2 June 2026
CVE-2025-53209Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation.CRITICAL 9.8EPSS 0.27%2 June 2026
CVE-2026-8206The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6.CRITICAL 9.8EPSS 1.28%2 June 2026
CVE-2026-25879Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection.CRITICAL 9.8EPSS 0.55%1 June 2026
CVE-2026-40965Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure.CRITICAL 10.0EPSS 0.35%1 June 2026
CVE-2018-25427Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field.CRITICAL 9.3EPSS 0.92%1 June 2026
CVE-2026-9319IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.CRITICAL 9.0EPSS 0.46%1 June 2026
CVE-2026-9311IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.CRITICAL 9.0EPSS 0.51%1 June 2026
CVE-2026-8644IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.CRITICAL 9.1EPSS 0.33%1 June 2026
CVE-2026-49121AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by…CRITICAL 9.2EPSS 1.10%1 June 2026
CVE-2026-0072In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check.CRITICAL 10.0EPSS 0.12%1 June 2026
CVE-2026-45132Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices.CRITICAL 10.0EPSS 0.26%1 June 2026
CVE-2026-45131Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens without requiring…CRITICAL 10.0EPSS 0.27%1 June 2026
CVE-2026-44211In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers.CRITICAL 9.6EPSS 0.18%1 June 2026
CVE-2026-42672Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.CRITICAL 9.3EPSS 0.24%1 June 2026
CVE-2026-8931A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.CRITICAL 9.4EPSS 0.72%1 June 2026
CVE-2026-48879Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation.CRITICAL 9.8EPSS 0.33%1 June 2026
CVE-2026-48866Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc.CRITICAL 9.6EPSS 0.47%1 June 2026
CVE-2026-42682Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels.CRITICAL 9.1EPSS 0.29%1 June 2026
CVE-2026-42680Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation.CRITICAL 9.8EPSS 0.33%1 June 2026
CVE-2026-0826In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.CRITICAL 9.2EPSS 32.2%1 June 2026
CVE-2026-7858A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an…CRITICAL 9.8EPSS 0.54%1 June 2026
CVE-2026-44825Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials…CRITICAL 9.8EPSS 2.89%1 June 2026
CVE-2026-42252Dag authors who copied the pattern verbatim into deployments where users had `Dag.can_trigger` permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter injection via…CRITICAL 9.1EPSS 0.38%1 June 2026
CVE-2026-48188An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass.CRITICAL 9.1EPSS 0.74%1 June 2026
CVE-2018-25412Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data.CRITICAL 9.3EPSS 0.77%30 May 2026
CVE-2026-45697This vulnerability is fixed in 2.2.20 and 3.1.24.CRITICAL 9.8EPSS 0.47%29 May 2026
CVE-2026-45372This vulnerability is fixed in 0.44.0.CRITICAL 9.9EPSS 0.29%29 May 2026
CVE-2026-9051There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure.CRITICAL 9.3EPSS 0.62%29 May 2026
CVE-2026-47744Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system.CRITICAL 9.9EPSS 0.32%29 May 2026
CVE-2026-44650SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models.CRITICAL 9.1EPSS 0.57%29 May 2026
CVE-2026-44649SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models.CRITICAL 9.8EPSS 0.22%29 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.