SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,286 results · page 114 of 786

CVESummaryPriorityPublished
CVE-2026-42889Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints.CRITICAL 9.1EPSS 0.37%12 May 2026
CVE-2026-8431An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.CRITICAL 9.4EPSS 0.37%12 May 2026
CVE-2026-8430SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server.CRITICAL 9.2EPSS 0.43%12 May 2026
CVE-2026-34660Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.3EPSS 0.44%12 May 2026
CVE-2026-34659Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.6EPSS 0.64%12 May 2026
CVE-2026-44343Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file system without authentication.CRITICAL 9.3EPSS 1.55%12 May 2026
CVE-2026-44277A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via…CRITICAL 9.8EPSS 0.55%12 May 2026
CVE-2026-44196From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely.CRITICAL 9.1EPSS 0.30%12 May 2026
CVE-2026-44183That entry is attacker-controlled — X-Forwarded-For is append-only, so the leftmost value is whatever the original HTTP client claimed.CRITICAL 9.8EPSS 0.22%12 May 2026
CVE-2026-42898Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.CRITICAL 9.9EPSS 1.19%12 May 2026
CVE-2026-42833Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.CRITICAL 9.1EPSS 0.75%12 May 2026
CVE-2026-42823Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.CRITICAL 9.9EPSS 0.60%12 May 2026
CVE-2026-42300DevGuard provides vulnerability management for the full software supply chain.CRITICAL 9.3EPSS 0.26%12 May 2026
CVE-2026-42048Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases).CRITICAL 9.6EPSS 4.42%12 May 2026
CVE-2026-41103Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.1EPSS 5.38%12 May 2026
CVE-2026-41096Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.93%12 May 2026
CVE-2026-41089Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 79.6%12 May 2026
CVE-2026-40402Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.CRITICAL 9.3EPSS 0.33%12 May 2026
CVE-2026-33821Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.CRITICAL 9.9EPSS 0.66%12 May 2026
CVE-2026-33117In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks.CRITICAL 9.1EPSS 0.48%12 May 2026
CVE-2026-31242An unauthenticated attacker can send a DELETE request that triggers a reset operation, leading to the execution of a DROP TABLE SQL statement.CRITICAL 9.1EPSS 0.49%12 May 2026
CVE-2026-31239The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub.CRITICAL 9.8EPSS 0.41%12 May 2026
CVE-2026-31238The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component.CRITICAL 9.8EPSS 0.50%12 May 2026
CVE-2026-31237The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method.CRITICAL 9.8EPSS 0.60%12 May 2026
CVE-2026-31236The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument.CRITICAL 9.8EPSS 0.33%12 May 2026
CVE-2026-31235The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module.CRITICAL 9.8EPSS 0.47%12 May 2026
CVE-2026-31234Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component.CRITICAL 9.8EPSS 0.69%12 May 2026
CVE-2026-31233Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism.CRITICAL 9.8EPSS 0.64%12 May 2026
CVE-2026-31231Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint.CRITICAL 9.8EPSS 0.64%12 May 2026
CVE-2026-31230The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py).CRITICAL 9.8EPSS 0.55%12 May 2026
CVE-2026-31229The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality.CRITICAL 9.8EPSS 0.60%12 May 2026
CVE-2026-29204Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account.CRITICAL 9.1EPSS 0.32%12 May 2026
CVE-2026-26083A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS…CRITICAL 9.8EPSS 0.73%12 May 2026
CVE-2026-43992Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_transfer, etc.) accepted 'mnemonic: string' as an explicit tool-call parameter.CRITICAL 9.8EPSS 0.22%12 May 2026
CVE-2026-20794Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege.CRITICAL 9.3EPSS 0.13%12 May 2026
CVE-2025-65719An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.CRITICAL 9.8EPSS 0.58%12 May 2026
CVE-2026-43515Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.CRITICAL 9.1EPSS 1.22%12 May 2026
CVE-2026-43512DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.CRITICAL 9.8EPSS 1.33%12 May 2026
CVE-2026-41293Improper Input Validation vulnerability in Apache Tomcat.CRITICAL 9.8EPSS 1.68%12 May 2026
CVE-2026-31228The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component.CRITICAL 9.8EPSS 0.61%12 May 2026
CVE-2026-31226The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities.CRITICAL 9.8EPSS 1.16%12 May 2026
CVE-2026-31220PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code.CRITICAL 9.8EPSS 0.63%12 May 2026
CVE-2026-31217The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution.CRITICAL 9.8EPSS 0.43%12 May 2026
CVE-2026-31216The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API.CRITICAL 9.1EPSS 0.40%12 May 2026
CVE-2026-31215The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface.CRITICAL 9.1EPSS 0.41%12 May 2026
CVE-2026-31214The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502).CRITICAL 9.8EPSS 0.49%12 May 2026
CVE-2026-30805Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access.CRITICAL 9.1EPSS 0.34%12 May 2026
CVE-2026-8401This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.CRITICAL 9.8EPSS 0.31%12 May 2026
CVE-2026-8043External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.CRITICAL 9.6EPSS 0.87%12 May 2026
CVE-2026-45091This vulnerability is fixed in 0.1.0-alpha.4.CRITICAL 9.1EPSS 0.33%12 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.