SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 110 of 786

CVESummaryPriorityPublished
CVE-2026-39832When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request.CRITICAL 9.1EPSS 0.60%22 May 2026
CVE-2026-39831Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key.CRITICAL 9.1EPSS 0.42%22 May 2026
CVE-2026-39830A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop.CRITICAL 9.1EPSS 0.62%22 May 2026
CVE-2026-9264A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files.CRITICAL 9.3EPSS 0.23%22 May 2026
CVE-2026-34910Ubiquiti UniFi OS Improper Input Validation VulnerabilityKEVCRITICAL 10.0EPSS 87.5%22 May 2026
CVE-2026-34909Ubiquiti UniFi OS Path Traversal VulnerabilityKEVCRITICAL 10.0EPSS 65.0%22 May 2026
CVE-2026-34908Ubiquiti UniFi OS Improper Access Control VulnerabilityKEVCRITICAL 10.0EPSS 85.2%22 May 2026
CVE-2026-33000A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.CRITICAL 9.1EPSS 1.25%22 May 2026
CVE-2026-6960The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6.CRITICAL 9.8EPSS 0.70%21 May 2026
CVE-2026-8134Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts.CRITICAL 9.4EPSS 0.74%21 May 2026
CVE-2026-48242Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php.CRITICAL 9.2EPSS 0.30%21 May 2026
CVE-2026-48241Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository.CRITICAL 9.2EPSS 0.30%21 May 2026
CVE-2026-48207Deserialization of untrusted data in Apache Fory PyFory.CRITICAL 9.8EPSS 0.57%21 May 2026
CVE-2026-39531Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.CRITICAL 9.3EPSS 0.24%21 May 2026
CVE-2025-71211A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.CRITICAL 9.8EPSS 3.75%21 May 2026
CVE-2025-71210A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.CRITICAL 9.8EPSS 3.81%21 May 2026
CVE-2026-5118The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2.CRITICAL 9.8EPSS 0.49%21 May 2026
CVE-2026-43501In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr->daddr,…CRITICAL 9.8EPSS 0.65%21 May 2026
CVE-2026-5433Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface.CRITICAL 9.1EPSS 0.97%21 May 2026
CVE-2026-4858Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token…CRITICAL 9.9EPSS 0.33%21 May 2026
CVE-2026-44050A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.CRITICAL 9.9EPSS 0.42%21 May 2026
CVE-2026-6279The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2.CRITICAL 9.8EPSS 3.16%21 May 2026
CVE-2026-9152A missing authentication vulnerability exists in the Altium 365 SearchService.CRITICAL 10.0EPSS 0.34%21 May 2026
CVE-2026-48172LiteSpeed cPanel Plugin Privilege Escalation VulnerabilityKEVCRITICAL 10.0EPSS 18.9%21 May 2026
CVE-2026-47372Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts.CRITICAL 9.1EPSS 0.40%20 May 2026
CVE-2026-8631A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software.CRITICAL 9.3EPSS 1.81%20 May 2026
CVE-2026-9141Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access internal application pages without any session management or…CRITICAL 9.3EPSS 0.48%20 May 2026
CVE-2026-9139Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-side JavaScript in login.zhtml, exposing static…CRITICAL 9.3EPSS 0.45%20 May 2026
CVE-2026-9129A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters.CRITICAL 9.4EPSS 0.24%20 May 2026
CVE-2026-9102A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs.CRITICAL 9.4EPSS 0.56%20 May 2026
CVE-2026-9082Drupal Core SQL Injection VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 90.0%20 May 2026
CVE-2026-45444Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files.CRITICAL 10.0EPSS 0.28%20 May 2026
CVE-2026-39405Frappe Learning Management System (LMS) is a learning system that helps users structure their content.CRITICAL 9.4EPSS 0.30%20 May 2026
CVE-2026-33137In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create…CRITICAL 9.3EPSS 0.59%20 May 2026
CVE-2026-23734Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal.CRITICAL 9.3EPSS 19.6%20 May 2026
CVE-2026-20223A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role.CRITICAL 10.0EPSS 0.83%20 May 2026
CVE-2026-8598This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.CRITICAL 9.1EPSS 0.51%20 May 2026
CVE-2026-8467Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation.CRITICAL 9.5EPSS 2.11%20 May 2026
CVE-2026-3593A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.CRITICAL 9.8EPSS 1.54%20 May 2026
CVE-2025-31973HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'.CRITICAL 9.8EPSS 0.18%20 May 2026
CVE-2026-22314Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems.CRITICAL 9.0EPSS 0.39%20 May 2026
CVE-2026-33278NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a…CRITICAL 9.1EPSS 1.27%20 May 2026
CVE-2026-9065SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'provider') on the REST API endpoint '/surecart/v1/integrations/{id}'.CRITICAL 9.3EPSS 0.34%20 May 2026
CVE-2026-9059NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'.CRITICAL 9.3EPSS 0.29%20 May 2026
CVE-2026-7637The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie.CRITICAL 9.8EPSS 0.57%20 May 2026
CVE-2026-24214NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow.CRITICAL 9.8EPSS 0.72%20 May 2026
CVE-2026-24213NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read.CRITICAL 9.8EPSS 0.72%20 May 2026
CVE-2026-24207NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.CRITICAL 9.8EPSS 2.55%20 May 2026
CVE-2026-24206NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.CRITICAL 9.8EPSS 0.55%20 May 2026
CVE-2026-24163NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization.CRITICAL 9.8EPSS 0.59%20 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.