SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,286 results · page 113 of 786

CVESummaryPriorityPublished
CVE-2026-44482Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app.CRITICAL 9.6EPSS 0.34%14 May 2026
CVE-2026-42457Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef.CRITICAL 9.0EPSS 0.31%14 May 2026
CVE-2026-2347Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd.CRITICAL 9.8EPSS 0.43%14 May 2026
CVE-2025-11024Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd.CRITICAL 9.8EPSS 0.36%14 May 2026
CVE-2026-6512The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2.CRITICAL 9.1EPSS 0.26%14 May 2026
CVE-2026-6510The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2.CRITICAL 9.8EPSS 0.44%14 May 2026
CVE-2026-6271The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler.CRITICAL 9.8EPSS 0.66%14 May 2026
CVE-2026-8181The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1.CRITICAL 9.8EPSS 14.6%14 May 2026
CVE-2026-8500Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.CRITICAL 9.8EPSS 1.65%13 May 2026
CVE-2026-45158Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system.CRITICAL 9.1EPSS 0.53%13 May 2026
CVE-2026-44442Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role.CRITICAL 9.9EPSS 0.28%13 May 2026
CVE-2026-44194Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root.CRITICAL 9.1EPSS 6.35%13 May 2026
CVE-2026-44193Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution.CRITICAL 9.1EPSS 0.69%13 May 2026
CVE-2026-45714Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms).CRITICAL 9.1EPSS 0.41%13 May 2026
CVE-2026-45053Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart.CRITICAL 9.1EPSS 0.58%13 May 2026
CVE-2026-44381Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints.CRITICAL 9.3EPSS 0.67%13 May 2026
CVE-2026-44377Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents).CRITICAL 9.1EPSS 0.73%13 May 2026
CVE-2025-27851The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack.CRITICAL 9.3EPSS 0.14%13 May 2026
CVE-2026-44364In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerability in the MISP Modules website allowed an attacker to cause an authenticated user to submit unintended requests to the home endpoint.CRITICAL 9.3EPSS 0.18%13 May 2026
CVE-2026-44351Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic.CRITICAL 9.1EPSS 0.24%13 May 2026
CVE-2026-42584This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.CRITICAL 9.1EPSS 0.84%13 May 2026
CVE-2026-42581An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage.CRITICAL 9.8EPSS 0.63%13 May 2026
CVE-2026-42579This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder.CRITICAL 9.1EPSS 1.01%13 May 2026
CVE-2026-45411This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.CRITICAL 9.8EPSS 0.57%13 May 2026
CVE-2026-44009Prior to 3.11.2, This vulnerability is fixed in 3.11.2.CRITICAL 9.8EPSS 0.81%13 May 2026
CVE-2026-44008Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox.CRITICAL 9.8EPSS 0.85%13 May 2026
CVE-2026-44007With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestricted require settings and executes arbitrary OS commands on the host.CRITICAL 9.1EPSS 0.96%13 May 2026
CVE-2026-44006Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes.CRITICAL 10.0EPSS 0.81%13 May 2026
CVE-2026-44005From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled…CRITICAL 10.0EPSS 0.83%13 May 2026
CVE-2026-43999Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard).CRITICAL 9.9EPSS 0.97%13 May 2026
CVE-2026-43997This vulnerability is fixed in 3.11.0.CRITICAL 10.0EPSS 0.98%13 May 2026
CVE-2026-42945NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module.CRITICAL 9.2EPSS 68.0%13 May 2026
CVE-2020-37168Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation.CRITICAL 9.3EPSS 0.25%13 May 2026
CVE-2026-42062ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter.CRITICAL 9.3EPSS 1.63%13 May 2026
CVE-2026-40621ELECOM wireless LAN access point devices do not require authentication to access some specific URLs.CRITICAL 9.3EPSS 0.49%13 May 2026
CVE-2026-41050Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.CRITICAL 9.9EPSS 0.39%13 May 2026
CVE-2026-32661Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version).CRITICAL 9.3EPSS 0.47%13 May 2026
CVE-2026-44547This vulnerability is fixed in 7.3.1.CRITICAL 9.6EPSS 0.21%12 May 2026
CVE-2026-42288The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard via unsanitized DB_PASSWORD remains fully exploitable This vulnerability is fixed in 7.3.2.CRITICAL 10.0EPSS 0.58%12 May 2026
CVE-2026-41901Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf.CRITICAL 9.0EPSS 0.43%12 May 2026
CVE-2026-44262From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code…EXPLOITCRITICAL 9.4EPSS 5.86%12 May 2026
CVE-2026-44258Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and home containment, but does not validate the dst (destination) parameter used by elfinder_paste.CRITICAL 9.3EPSS 0.29%12 May 2026
CVE-2026-44257Combined with the framework's multipart /uploadServlet and an event that calls file.saveUploadFiles + FileManager.unZip, a remote attacker with no credentials drops a JSP webshell and executes arbitrary commands as the Tomcat user.CRITICAL 9.3EPSS 0.32%12 May 2026
CVE-2026-44015In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header.CRITICAL 9.9EPSS 0.32%12 May 2026
CVE-2026-43948Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object comparison (!=) that evaluates None != None as False, silently bypassing the guard when both the attacker and…CRITICAL 9.9EPSS 0.37%12 May 2026
CVE-2026-42854Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a Variable Length Array (VLA) on the stack whose size is derived from an attacker-controlled HTTP header field (Content-Type: multipart/form-data; boundary=...) without…CRITICAL 9.8EPSS 0.57%12 May 2026
CVE-2026-42196Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into request.FILES.CRITICAL 9.9EPSS 0.56%12 May 2026
CVE-2026-45185Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.CRITICAL 9.8EPSS 1.23%12 May 2026
CVE-2026-44225Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem.EXPLOITCRITICAL 9.3EPSS 1.35%12 May 2026
CVE-2026-44221Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestAccessOnFile treated as allow-all; (2) ArcadeDBServer.createDatabase() omitted factory.setSecurity(...) so…CRITICAL 9.0EPSS 0.40%12 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.