SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,284 results · page 111 of 786

CVESummaryPriorityPublished
CVE-2026-24142NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle.CRITICAL 9.8EPSS 0.38%20 May 2026
CVE-2025-33255NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization.CRITICAL 9.8EPSS 0.57%20 May 2026
CVE-2026-7284The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4.CRITICAL 9.8EPSS 0.49%20 May 2026
CVE-2026-6555The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0.CRITICAL 9.8EPSS 0.98%20 May 2026
CVE-2026-8495Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.CRITICAL 9.8EPSS 0.37%19 May 2026
CVE-2026-34234In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Execution (RCE) because it performs the install.lock check only after including and executing form handler files, leaving…CRITICAL 10.0EPSS 3.11%19 May 2026
CVE-2026-33642An attacker who can write escape sequences to a kitty terminal (e.g., via a malicious file, SSH login banner, or piped content) can supply crafted x_offset/y_offset values that pass the bounds check after wrapping but cause massive out-of-bounds heap…CRITICAL 9.8EPSS 0.29%19 May 2026
CVE-2026-47358Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode.CRITICAL 9.2EPSS 0.48%19 May 2026
CVE-2026-47357Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode.CRITICAL 9.2EPSS 0.48%19 May 2026
CVE-2026-36829An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7.CRITICAL 9.8EPSS 1.27%19 May 2026
CVE-2026-37281An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.CRITICAL 9.8EPSS 1.62%19 May 2026
CVE-2026-31072The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization.CRITICAL 9.8EPSS 0.81%19 May 2026
CVE-2026-31071Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserData, modify drug inventory, and access private medical prescription data via /api/doctorOder.CRITICAL 9.1EPSS 0.55%19 May 2026
CVE-2026-31070The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration.CRITICAL 9.8EPSS 0.48%19 May 2026
CVE-2026-30118scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint.CRITICAL 9.8EPSS 0.47%19 May 2026
CVE-2026-30117scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint.CRITICAL 9.8EPSS 0.53%19 May 2026
CVE-2026-8711NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript.CRITICAL 9.2EPSS 9.69%19 May 2026
CVE-2026-44159Tyler Identity Local (TID-L) uses documented, default administrative credentials.CRITICAL 9.3EPSS 0.48%19 May 2026
CVE-2026-2587A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler.CRITICAL 9.6EPSS 0.65%19 May 2026
CVE-2026-2586An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console.CRITICAL 9.1EPSS 0.84%19 May 2026
CVE-2026-8959This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.CRITICAL 9.6EPSS 0.42%19 May 2026
CVE-2026-8956Integer overflow in the Networking: JAR component.CRITICAL 9.8EPSS 0.60%19 May 2026
CVE-2026-8953Sandbox escape due to use-after-free in the Disability Access APIs component.CRITICAL 9.6EPSS 0.53%19 May 2026
CVE-2026-8950Same-origin policy bypass in the Networking: HTTP component.CRITICAL 9.3EPSS 0.19%19 May 2026
CVE-2026-8948Same-origin policy bypass in the DOM: Networking component.CRITICAL 9.1EPSS 0.42%19 May 2026
CVE-2026-47323Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and…CRITICAL 9.8EPSS 1.54%19 May 2026
CVE-2026-43633HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achieve root-level code execution.CRITICAL 9.5EPSS 1.07%19 May 2026
CVE-2026-42097An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication.CRITICAL 9.3EPSS 0.94%19 May 2026
CVE-2026-4883The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40.CRITICAL 9.8EPSS 0.81%19 May 2026
CVE-2026-43493In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY.CRITICAL 9.8EPSS 0.55%19 May 2026
CVE-2026-46725The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input.CRITICAL 9.2EPSS 2.63%19 May 2026
CVE-2026-45434Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06.CRITICAL 9.8EPSS 22.4%19 May 2026
CVE-2026-41919Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.CRITICAL 9.1EPSS 0.45%19 May 2026
CVE-2026-31986Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz.CRITICAL 9.1EPSS 0.44%19 May 2026
CVE-2026-2611In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints.CRITICAL 9.6EPSS 0.38%19 May 2026
CVE-2026-4885The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70.CRITICAL 9.8EPSS 0.95%19 May 2026
CVE-2026-47314Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.CRITICAL 9.8EPSS 0.29%19 May 2026
CVE-2026-47311Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.CRITICAL 9.8EPSS 0.29%19 May 2026
CVE-2026-47310Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.CRITICAL 9.8EPSS 0.29%19 May 2026
CVE-2026-8838Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client.CRITICAL 9.3EPSS 0.81%18 May 2026
CVE-2026-27130Versions 0.26.6 and below have OS command injection through the appName parameter.CRITICAL 9.9EPSS 0.98%18 May 2026
CVE-2026-25244Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration.CRITICAL 9.8EPSS 2.76%18 May 2026
CVE-2026-45495Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 0.99%18 May 2026
CVE-2026-42822Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 0.49%18 May 2026
CVE-2023-24215Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.CRITICAL 9.1EPSS 0.24%18 May 2026
CVE-2026-45829A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true…CRITICAL 10.0EPSS 12.4%18 May 2026
CVE-2026-41948Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization.CRITICAL 9.3EPSS 14.5%18 May 2026
CVE-2026-41947Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership.CRITICAL 9.3EPSS 5.97%18 May 2026
CVE-2026-7304SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.CRITICAL 9.8EPSS 0.58%18 May 2026
CVE-2026-7302SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when…CRITICAL 9.1EPSS 0.39%18 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.