SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 107 of 786

CVESummaryPriorityPublished
CVE-2026-9645Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server.CRITICAL 9.9EPSS 0.41%28 May 2026
CVE-2026-46840Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service).CRITICAL 10.0EPSS 0.73%28 May 2026
CVE-2026-46839Vulnerability in Oracle REST Data Services (component: Core).CRITICAL 9.9EPSS 0.35%28 May 2026
CVE-2026-46833Vulnerability in the Net Service component of Oracle Database Server.CRITICAL 9.0EPSS 0.33%28 May 2026
CVE-2026-46824Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration).CRITICAL 9.9EPSS 0.26%28 May 2026
CVE-2026-46822Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.9EPSS 0.28%28 May 2026
CVE-2026-46819Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.1EPSS 0.33%28 May 2026
CVE-2026-46817Oracle E-Business Suite Improper Privilege Management VulnerabilityKEVCRITICAL 9.8EPSS 13.0%28 May 2026
CVE-2026-46775Vulnerability in Oracle REST Data Services (component: Core).CRITICAL 9.9EPSS 0.43%28 May 2026
CVE-2026-45288Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection…CRITICAL 9.8EPSS 0.38%28 May 2026
CVE-2026-34311Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera).CRITICAL 9.8EPSS 0.46%28 May 2026
CVE-2026-9037Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package.CRITICAL 9.3EPSS 0.25%28 May 2026
CVE-2026-45039This vulnerability is fixed in 1.0.0-beta.2.CRITICAL 9.8EPSS 0.27%28 May 2026
CVE-2026-45374Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:1499: self.allow_shell.unwrap_or(true)) and auto_approve defaults to true (task_manager.rs:297: auto_approve:…CRITICAL 9.6EPSS 0.26%28 May 2026
CVE-2026-45353From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.CRITICAL 9.3EPSS 0.11%28 May 2026
CVE-2026-45323Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary javascript in the Home Assistant frontend of anyone viewing the card.CRITICAL 9.6EPSS 0.32%28 May 2026
CVE-2026-45311From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user approval prompt. cargo test compiles and executes arbitrary code: test binaries, build.rs build scripts, and…CRITICAL 9.6EPSS 0.38%28 May 2026
CVE-2026-45058In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets.CRITICAL 9.4EPSS 0.23%28 May 2026
CVE-2026-43898Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback.CRITICAL 10.0EPSS 0.47%28 May 2026
CVE-2026-9098As a result, an attacker controlling a registered upstream IdP can send unsolicited SAML responses, or replay a legitimately captured response in a different session or after the original flow has ended.CRITICAL 9.1EPSS 0.23%28 May 2026
CVE-2026-9097Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active.CRITICAL 9.8EPSS 0.40%28 May 2026
CVE-2026-9094Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange.CRITICAL 9.8EPSS 0.42%28 May 2026
CVE-2026-9093This allows assertions issued for other service providers to be accepted by Casdoor.CRITICAL 9.8EPSS 0.36%28 May 2026
CVE-2026-9092Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover.CRITICAL 9.1EPSS 0.32%28 May 2026
CVE-2026-9090Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate.CRITICAL 9.1EPSS 0.22%28 May 2026
CVE-2026-45261Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler desktop application.CRITICAL 9.3EPSS 0.52%28 May 2026
CVE-2026-44477This vulnerability is fixed in 1.29.1 and 1.28.3.CRITICAL 9.4EPSS 0.48%28 May 2026
CVE-2026-38707A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions.CRITICAL 9.8EPSS 1.24%28 May 2026
CVE-2026-38704A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions.CRITICAL 9.8EPSS 1.27%28 May 2026
CVE-2026-38703A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions.CRITICAL 9.8EPSS 1.24%28 May 2026
CVE-2026-38702A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions.CRITICAL 9.8EPSS 1.24%28 May 2026
CVE-2026-24444SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain root access by…CRITICAL 9.3EPSS 0.53%28 May 2026
CVE-2026-44672From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated.CRITICAL 9.3EPSS 0.33%28 May 2026
CVE-2026-8980The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation.CRITICAL 9.3EPSS 0.33%28 May 2026
CVE-2026-8979The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass.CRITICAL 9.3EPSS 0.61%28 May 2026
CVE-2026-46195In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DACL pointers parse_sec_desc(), build_sec_desc(), and the chown path in id_mode_to_cifs_acl() all add the server-supplied dacloffset to…CRITICAL 9.8EPSS 0.68%28 May 2026
CVE-2026-46185In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message() returns success without length validation for the symlink error response, in symlink_data() it is…CRITICAL 9.1EPSS 0.51%28 May 2026
CVE-2026-46155In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns…CRITICAL 9.1EPSS 0.48%28 May 2026
CVE-2026-46137In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() helper is executed as a timer callback in softirq context.CRITICAL 9.8EPSS 0.43%28 May 2026
CVE-2026-46135In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp), but it does so…CRITICAL 9.8EPSS 0.40%28 May 2026
CVE-2026-46119In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is…CRITICAL 9.1EPSS 0.53%28 May 2026
CVE-2026-46115In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeable biovec_phys_mergeable() is used by the request merge, DMA mapping, and integrity merge paths to decide if two physically contiguous bvec…CRITICAL 9.8EPSS 0.49%28 May 2026
CVE-2026-4408A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature.CRITICAL 9.8EPSS 2.50%28 May 2026
CVE-2026-32999Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.CRITICAL 9.0EPSS 0.31%28 May 2026
CVE-2026-32998This vulnerability in Veeam Service Provider Console allows for remote code execution.CRITICAL 9.4EPSS 0.52%28 May 2026
CVE-2026-9739Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790).CRITICAL 9.4EPSS 0.28%27 May 2026
CVE-2026-45083The Goobi viewer is a web application that allows digitised material to be displayed in a web browser.CRITICAL 9.8EPSS 0.41%27 May 2026
CVE-2026-8364Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.CRITICAL 9.8EPSS 0.30%27 May 2026
CVE-2026-8363A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:CRITICAL 9.8EPSS 0.34%27 May 2026
CVE-2026-8362A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshomeCRITICAL 9.8EPSS 0.32%27 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.