SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 106 of 786

CVESummaryPriorityPublished
CVE-2026-7786Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image.CRITICAL 9.8EPSS 0.41%29 May 2026
CVE-2026-5386The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset.CRITICAL 9.1EPSS 0.62%29 May 2026
CVE-2026-45668Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traversal and XSS by combining a payload note (type: code, mime: text/plain) containing raw HTML/JS and a trigger note (type: doc or type:…CRITICAL 9.3EPSS 0.17%29 May 2026
CVE-2026-45661In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application deployment.CRITICAL 9.9EPSS 0.66%29 May 2026
CVE-2026-45633In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint.CRITICAL 9.9EPSS 0.92%29 May 2026
CVE-2026-45632Schedule types server and dokploy-server write and execute scripts on the host or remote servers, enabling RCE on the Dokploy host or a target server.CRITICAL 9.9EPSS 0.26%29 May 2026
CVE-2026-45631From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign-in as admin, and execute commands on the host via the built-in SSH…CRITICAL 10.0EPSS 0.35%29 May 2026
CVE-2026-45630In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote servers via unsanitized echo shell interpolation.CRITICAL 9.0EPSS 0.76%29 May 2026
CVE-2026-45629In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote servers managed by Dokploy, leading to full server compromise.CRITICAL 9.9EPSS 0.76%29 May 2026
CVE-2026-45628In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via child_process.exec() (which runs through /bin/sh -c).CRITICAL 9.6EPSS 0.23%29 May 2026
CVE-2026-45625Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps source repositories and their stored credentials.CRITICAL 9.9EPSS 0.39%29 May 2026
CVE-2026-48501This vulnerability is fixed in 2.93.0.CRITICAL 9.1EPSS 0.29%29 May 2026
CVE-2026-45663In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality.CRITICAL 9.9EPSS 0.87%29 May 2026
CVE-2026-44962Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization.CRITICAL 9.9EPSS 0.69%29 May 2026
CVE-2026-4290The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0.CRITICAL 9.1EPSS 0.26%29 May 2026
CVE-2026-10042manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method_name}…CRITICAL 9.2EPSS 0.62%29 May 2026
CVE-2026-46376From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP.CRITICAL 9.3EPSS 0.43%29 May 2026
CVE-2026-9508Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot.CRITICAL 10.0EPSS 0.34%29 May 2026
CVE-2026-8326Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root.CRITICAL 10.0EPSS 0.38%29 May 2026
CVE-2026-45312In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server.CRITICAL 9.9EPSS 0.45%29 May 2026
CVE-2026-45043Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, including the root user (minioadmin).CRITICAL 9.3EPSS 0.23%29 May 2026
CVE-2026-10071DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.CRITICAL 9.3EPSS 0.51%29 May 2026
CVE-2026-9559A path traversal vulnerability exists in the campaign import feature of Mautic 7.CRITICAL 9.9EPSS 0.58%29 May 2026
CVE-2025-41277Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote…CRITICAL 9.3EPSS 1.38%29 May 2026
CVE-2025-41276Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote…CRITICAL 9.3EPSS 1.38%29 May 2026
CVE-2025-41275Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote…CRITICAL 9.3EPSS 1.38%29 May 2026
CVE-2025-41274Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote…CRITICAL 9.3EPSS 1.38%29 May 2026
CVE-2025-41273Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass…CRITICAL 9.3EPSS 0.41%29 May 2026
CVE-2025-41272Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote…CRITICAL 9.3EPSS 1.38%29 May 2026
CVE-2025-41270Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote…CRITICAL 9.3EPSS 1.38%29 May 2026
CVE-2025-41269Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote…CRITICAL 9.3EPSS 1.38%29 May 2026
CVE-2026-9558A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine.CRITICAL 9.9EPSS 0.57%29 May 2026
CVE-2026-49201The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key.CRITICAL 10.0EPSS 0.26%29 May 2026
CVE-2026-49200This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.CRITICAL 10.0EPSS 0.52%29 May 2026
CVE-2026-49199Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.CRITICAL 10.0EPSS 1.34%29 May 2026
CVE-2026-49197Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.CRITICAL 10.0EPSS 0.33%29 May 2026
CVE-2026-3655The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60.CRITICAL 9.8EPSS 0.51%29 May 2026
CVE-2026-8732The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0.CRITICAL 9.8EPSS 22.7%29 May 2026
CVE-2026-9967Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.24%28 May 2026
CVE-2026-9918Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.24%28 May 2026
CVE-2026-9891Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension.CRITICAL 9.0EPSS 0.24%28 May 2026
CVE-2026-9886Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.24%28 May 2026
CVE-2026-9881Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.CRITICAL 9.0EPSS 0.20%28 May 2026
CVE-2026-9876Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.24%28 May 2026
CVE-2026-9875Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.24%28 May 2026
CVE-2026-9874Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.23%28 May 2026
CVE-2026-9872Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.37%28 May 2026
CVE-2026-8809The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5.CRITICAL 9.8EPSS 0.80%28 May 2026
CVE-2026-44849This vulnerability is fixed in 2.33.8, 2.39.2, and 2.41.0.CRITICAL 9.4EPSS 0.35%28 May 2026
CVE-2026-44848The vulnerability is exposed when a non-admin Portainer user (Standard User role, or any role granted endpoint-level access) has been given access to a Docker endpoint via Portainer RBAC.CRITICAL 9.4EPSS 0.40%28 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.