SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 108 of 786

CVESummaryPriorityPublished
CVE-2026-45102This vulnerability is fixed in 10.0.98.CRITICAL 9.9EPSS 0.27%27 May 2026
CVE-2026-44888Since pialert.conf is loaded via Python's exec() every 3–5 minutes by the background cron process, an attacker can inject arbitrary Python code and achieve unauthenticated OS-level RCE.CRITICAL 9.8EPSS 0.31%27 May 2026
CVE-2026-44887Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf.CRITICAL 9.8EPSS 0.55%27 May 2026
CVE-2026-44590Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger.CRITICAL 9.3EPSS 1.14%27 May 2026
CVE-2026-48150The whole flow is tenant-wide privilege escalation from an app-level role, available to anyone with an Enterprise license that unlocks the EXPANDED_PUBLIC_API feature.CRITICAL 9.0EPSS 0.29%27 May 2026
CVE-2026-46425This vulnerability is fixed in 3.38.2.CRITICAL 9.9EPSS 0.29%27 May 2026
CVE-2026-45087Dalfox is a powerful open-source XSS scanner and utility focused on automation.CRITICAL 10.0EPSS 13.0%27 May 2026
CVE-2026-48027Nx Console Embedded Malicious Code VulnerabilityKEVCRITICAL 9.3EPSS 1.85%27 May 2026
CVE-2026-44330A network attacker who can reach NEF on the SBI can use a forged or arbitrary bearer token (e.g.CRITICAL 10.0EPSS 0.29%27 May 2026
CVE-2026-44329A network attacker who can reach SMF on the SBI can hit UPI endpoints with no Authorization header at all, and the requests reach the SMF business handlers.CRITICAL 10.0EPSS 0.33%27 May 2026
CVE-2026-44327A network attacker who can reach NEF on the SBI can hit the OAM route with no Authorization header at all and the handler returns 200 OK.CRITICAL 10.0EPSS 0.31%27 May 2026
CVE-2026-44326A network attacker who can reach NEF on the SBI can create, read, patch, and delete traffic-influence subscriptions either with no Authorization header at all, or with a forged bearer token (e.g.CRITICAL 9.4EPSS 0.31%27 May 2026
CVE-2026-44315A network attacker who can reach NEF on the SBI can create, read, and delete PFD-management transaction state with a forged or arbitrary bearer token (e.g.CRITICAL 9.4EPSS 0.31%27 May 2026
CVE-2026-49103Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component.CRITICAL 9.4EPSS 0.40%27 May 2026
CVE-2026-8175IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component.CRITICAL 9.8EPSS 0.58%27 May 2026
CVE-2026-7876IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability.CRITICAL 9.1EPSS 0.31%27 May 2026
CVE-2026-7524IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.CRITICAL 9.8EPSS 0.79%27 May 2026
CVE-2026-46043In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv rxe_rcv() currently checks only that the incoming packet is at least header_size(pkt) bytes long before payload_size()…CRITICAL 9.1EPSS 0.51%27 May 2026
CVE-2026-46039In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length check Fix potential integer overflow in rxgk_extract_token() when checking the length of the ticket.CRITICAL 9.8EPSS 0.44%27 May 2026
CVE-2026-45988In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a RESPONSE packet gets a temporary failure during processing, it may end up in a partially decrypted state - and then get requeued for a…CRITICAL 9.8EPSS 0.46%27 May 2026
CVE-2026-45972In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in smb2_open_file() Zero out @err_iov and @err_buftype before retrying SMB2_open() to prevent an UAF bug if @data != NULL, otherwise a…CRITICAL 9.8EPSS 0.33%27 May 2026
CVE-2026-45898In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removing work_list The commit e1168f0 ("RDMA/iwcm: Simplify cm_event_handler()") changed the work submission logic to unconditionally call…CRITICAL 9.8EPSS 0.46%27 May 2026
CVE-2026-35090In Slican telephone exchanges it is possible to manage the control panel remotely.CRITICAL 9.3EPSS 0.63%27 May 2026
CVE-2026-35087Slican telephone exchanges allow administrative protocol authentication bypass.CRITICAL 9.3EPSS 0.66%27 May 2026
CVE-2024-40684IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have…CRITICAL 9.8EPSS 0.36%27 May 2026
CVE-2026-48906The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.CRITICAL 9.3EPSS 0.27%27 May 2026
CVE-2026-42761Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products…CRITICAL 9.3EPSS 0.23%27 May 2026
CVE-2026-42758Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253.CRITICAL 9.8EPSS 0.32%27 May 2026
CVE-2026-42757Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a through < 4.08.253.CRITICAL 9.9EPSS 0.36%27 May 2026
CVE-2026-42756Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP…CRITICAL 9.9EPSS 0.34%27 May 2026
CVE-2026-42755Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: from n/a through <= 1.0.5.1.CRITICAL 9.3EPSS 0.24%27 May 2026
CVE-2026-42748Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1.CRITICAL 9.9EPSS 0.28%27 May 2026
CVE-2026-42747Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 4.0.6.CRITICAL 9.3EPSS 0.24%27 May 2026
CVE-2026-42740Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Injection.This issue affects Tainacan: from n/a through <= 1.0.3.CRITICAL 9.3EPSS 0.24%27 May 2026
CVE-2026-42731Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.CRITICAL 9.8EPSS 0.33%27 May 2026
CVE-2026-42727Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products…CRITICAL 9.3EPSS 0.29%27 May 2026
CVE-2026-8054Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote…CRITICAL 10.0EPSS 1.58%27 May 2026
CVE-2026-49002Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information.CRITICAL 9.1EPSS 0.29%27 May 2026
CVE-2025-13392Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of…CRITICAL 9.8EPSS 0.53%27 May 2026
CVE-2025-12686Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.CRITICAL 9.8EPSS 2.76%27 May 2026
CVE-2026-8760The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6.CRITICAL 9.8EPSS 0.62%27 May 2026
CVE-2026-8450HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open().CRITICAL 9.1EPSS 1.40%27 May 2026
CVE-2026-9312A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint.CRITICAL 9.2EPSS 6.55%27 May 2026
CVE-2026-44966In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs.CRITICAL 9.8EPSS 0.55%26 May 2026
CVE-2026-44895Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: * on every response.CRITICAL 9.2EPSS 0.39%26 May 2026
CVE-2026-44451Both controls are bypassed.CRITICAL 9.3EPSS 0.23%26 May 2026
CVE-2026-44450Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation.CRITICAL 9.9EPSS 0.38%26 May 2026
CVE-2026-44449A path whose directory component is clean but whose basename contains "; !<cmd>; echo " achieves arbitrary command execution on the Lumiverse server.CRITICAL 9.1EPSS 0.45%26 May 2026
CVE-2026-44444A malicious extension that ships a package.json with a preinstall, postinstall, or prepare lifecycle script achieves host-level code execution the moment an admin presses Install before any dist file is inspected.CRITICAL 9.1EPSS 0.37%26 May 2026
CVE-2026-48689FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp).CRITICAL 9.8EPSS 0.68%26 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.