SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 109 of 786

CVESummaryPriorityPublished
CVE-2026-3660IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application.CRITICAL 9.8EPSS 0.58%26 May 2026
CVE-2026-9560Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channelCRITICAL 9.4EPSS 0.57%26 May 2026
CVE-2026-9170IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.CRITICAL 9.8EPSS 0.49%26 May 2026
CVE-2026-8856IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.CRITICAL 9.1EPSS 0.20%26 May 2026
CVE-2026-8855IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).CRITICAL 9.8EPSS 0.46%26 May 2026
CVE-2026-8633IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially…CRITICAL 9.8EPSS 0.85%26 May 2026
CVE-2026-7251Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password.CRITICAL 9.3EPSS 0.50%26 May 2026
CVE-2026-47202Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given knowledge of their username.CRITICAL 9.3EPSS 0.17%26 May 2026
CVE-2026-46624From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack.CRITICAL 9.9EPSS 0.48%26 May 2026
CVE-2026-44668Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system.CRITICAL 9.8EPSS 0.36%26 May 2026
CVE-2026-48902The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.CRITICAL 9.8EPSS 0.25%26 May 2026
CVE-2026-48691FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder.CRITICAL 9.8EPSS 0.31%26 May 2026
CVE-2026-45721Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured server root — looking for a file named handler.lua to execute as the…CRITICAL 9.0EPSS 0.44%26 May 2026
CVE-2026-44723The shell interprets the expanded string before invoking Python, allowing an attacker to break out of the quotes and execute arbitrary commands on the runner.CRITICAL 9.9EPSS 0.47%26 May 2026
CVE-2026-2264A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.CRITICAL 9.2EPSS 0.36%26 May 2026
CVE-2026-24212NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text.CRITICAL 9.8EPSS 0.66%26 May 2026
CVE-2025-36220IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection.CRITICAL 9.8EPSS 0.31%26 May 2026
CVE-2026-48687FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin.CRITICAL 9.8EPSS 1.65%26 May 2026
CVE-2026-48686FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder.CRITICAL 9.8EPSS 0.56%26 May 2026
CVE-2026-4480A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters.CRITICAL 9.0EPSS 13.9%26 May 2026
CVE-2026-45247Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data VulnerabilityKEVCRITICAL 9.3EPSS 27.5%26 May 2026
CVE-2026-7374This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets.CRITICAL 9.9EPSS 0.74%26 May 2026
CVE-2026-42496Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments.CRITICAL 9.1EPSS 0.43%26 May 2026
CVE-2026-8376Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.CRITICAL 9.8EPSS 0.44%26 May 2026
CVE-2026-42774Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection.CRITICAL 9.3EPSS 0.37%25 May 2026
CVE-2026-42773Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOne Store Manager allows Blind SQL Injection.CRITICAL 9.3EPSS 0.37%25 May 2026
CVE-2026-9058This flaw enables authentication bypass and user impersonation: (1) in use-cases other than qualified certificate authentication, or (2) if the qualified certificate authentication use-case is not correctly implemented by the integrating application.CRITICAL 9.3EPSS 0.31%25 May 2026
CVE-2026-2651A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled.CRITICAL 9.0EPSS 0.34%25 May 2026
CVE-2018-25357Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter.CRITICAL 9.3EPSS 1.70%23 May 2026
CVE-2018-25350userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint.CRITICAL 9.3EPSS 0.43%23 May 2026
CVE-2026-47280Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.49%22 May 2026
CVE-2026-42901Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 0.30%22 May 2026
CVE-2026-41090Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.CRITICAL 9.3EPSS 0.42%22 May 2026
CVE-2026-40412Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.53%22 May 2026
CVE-2026-33843Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.47%22 May 2026
CVE-2026-23652Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.58%22 May 2026
CVE-2026-48700This could be used to achieve code execution or circumvent network namespace restrictions.CRITICAL 9.3EPSS 0.18%22 May 2026
CVE-2026-33712In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side code blocks.CRITICAL 10.0EPSS 0.35%22 May 2026
CVE-2026-32253In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled.CRITICAL 9.8EPSS 0.29%22 May 2026
CVE-2026-39821This behavior can lead to privilege escalation in programs using the idna package.CRITICAL 9.6EPSS 0.69%22 May 2026
CVE-2026-9256NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module.CRITICAL 9.2EPSS 10.9%22 May 2026
CVE-2026-9277A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command.CRITICAL 9.2EPSS 0.85%22 May 2026
CVE-2026-8673Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks.CRITICAL 9.1EPSS 0.19%22 May 2026
CVE-2026-8670Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay).CRITICAL 9.6EPSS 0.22%22 May 2026
CVE-2026-44930An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.CRITICAL 9.8EPSS 0.69%22 May 2026
CVE-2026-9054An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.CRITICAL 9.2EPSS 0.29%22 May 2026
CVE-2026-46595Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.CRITICAL 10.0EPSS 0.50%22 May 2026
CVE-2026-42508Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation.CRITICAL 9.1EPSS 7.31%22 May 2026
CVE-2026-39834When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress.CRITICAL 9.1EPSS 0.53%22 May 2026
CVE-2026-39833The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it.CRITICAL 9.1EPSS 0.41%22 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.