SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,286 results · page 116 of 786

CVESummaryPriorityPublished
CVE-2026-43465In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ XDP multi-buf programs can modify the layout of the XDP buffer when the program calls bpf_xdp_pull_data() or…CRITICAL 9.8EPSS 0.41%8 May 2026
CVE-2026-43414In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free().CRITICAL 9.8EPSS 0.38%8 May 2026
CVE-2026-43407In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This patch fixes an out-of-bounds access in ceph_handle_auth_reply() that can be triggered by a message of type…CRITICAL 9.1EPSS 0.54%8 May 2026
CVE-2026-43406In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If the message frame is (maliciously) corrupted in a way that the length of the control segment ends up being…CRITICAL 9.1EPSS 0.50%8 May 2026
CVE-2026-43402In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent use-after-free Guillaume reported crashes via corrupted RCU callback function pointers during KUnit testing.CRITICAL 9.8EPSS 0.46%8 May 2026
CVE-2026-43384In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time.CRITICAL 9.8EPSS 0.46%8 May 2026
CVE-2026-43383In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time.CRITICAL 9.4EPSS 0.44%8 May 2026
CVE-2026-43379In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being accessed after rcu_read_unlock() has been called.CRITICAL 9.8EPSS 0.44%8 May 2026
CVE-2026-43376In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for oplock_info ksmbd currently frees oplock_info immediately using kfree(), even though it is accessed under RCU read-side critical…CRITICAL 9.8EPSS 0.44%8 May 2026
CVE-2026-41584The Zcash specification allows the field to be the identity (a "zero" value), however, the orchard crate which is used to verify Orchard proofs would panic when fed a rk with the identity value.CRITICAL 9.2EPSS 0.27%8 May 2026
CVE-2026-41583ZEBRA is a Zcash node written entirely in Rust.CRITICAL 9.3EPSS 0.28%8 May 2026
CVE-2026-41574The vulnerability is that several provider adapters do not correctly populate this field they either silently drop a verified field the provider API actually returns (Discord), or they fall back to accepting unconfirmed emails and marking them as…CRITICAL 9.3EPSS 0.81%8 May 2026
CVE-2026-37431Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint.CRITICAL 9.8EPSS 0.26%8 May 2026
CVE-2026-44336By setting rule_name="../../<some-path>" an attacker walks out of the rules directory and writes any file the running user can write.CRITICAL 9.4EPSS 0.62%8 May 2026
CVE-2026-44128SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval.CRITICAL 9.3EPSS 0.85%8 May 2026
CVE-2026-44126SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object.CRITICAL 9.2EPSS 0.47%8 May 2026
CVE-2026-44125SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to access functionality that should require a valid session.CRITICAL 9.3EPSS 0.39%8 May 2026
CVE-2026-43341In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound in trace fill ioam6_fill_trace_data() stores the schema contribution to the trace length in a u8.CRITICAL 9.8EPSS 0.41%8 May 2026
CVE-2026-43304In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When decoding the key, verify that the key material would fit into a fixed-size buffer in process_auth_done() and generally has a sane length.CRITICAL 9.8EPSS 0.50%8 May 2026
CVE-2026-41512From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerability via JavaScript injection in `BrowserAutomation::PlaywrightService`.CRITICAL 9.9EPSS 0.59%8 May 2026
CVE-2026-41507Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim into a new Function() body without sanitization.CRITICAL 9.8EPSS 0.39%8 May 2026
CVE-2026-41497Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to parse_mcp_command(), allowing arbitrary executables like bash, python, or /bin/sh with inline code execution flags to pass…CRITICAL 9.8EPSS 0.54%8 May 2026
CVE-2026-25199Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants.CRITICAL 9.1EPSS 0.50%8 May 2026
CVE-2022-50994DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated remote attackers to execute arbitrary commands by injecting shell metacharacters into the…CRITICAL 9.2EPSS 1.43%8 May 2026
CVE-2026-8153OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.CRITICAL 9.8EPSS 1.83%8 May 2026
CVE-2026-8076Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication.CRITICAL 9.3EPSS 0.32%8 May 2026
CVE-2026-6213A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side.CRITICAL 10.0EPSS 0.33%8 May 2026
CVE-2013-10075Apache::Session versions through 1.94 for Perl re-creates deleted sessions.CRITICAL 9.1EPSS 0.36%8 May 2026
CVE-2025-69691Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php.CRITICAL 9.9EPSS 0.68%8 May 2026
CVE-2025-69690Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property.CRITICAL 9.1EPSS 0.81%8 May 2026
CVE-2025-69599RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable.CRITICAL 9.8EPSS 0.39%8 May 2026
CVE-2025-678871C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file.CRITICAL 9.8EPSS 1.55%8 May 2026
CVE-2023-46453Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular expression.CRITICAL 9.8EPSS 0.76%8 May 2026
CVE-2024-51092LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().CRITICAL 9.1EPSS 7.18%8 May 2026
CVE-2026-43944From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts.CRITICAL 9.4EPSS 0.36%8 May 2026
CVE-2026-43941An attacker who controls terminal output (e.g., via a malicious SSH server, compromised remote host, or malicious plugin rendering terminal content) can thus achieve arbitrary code execution or local file access on the victim's machine, requiring only…CRITICAL 9.6EPSS 0.39%8 May 2026
CVE-2026-42264From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as…CRITICAL 9.1EPSS 0.71%8 May 2026
CVE-2026-42208BerriAI LiteLLM SQL Injection VulnerabilityKEVCRITICAL 9.3EPSS 89.4%8 May 2026
CVE-2026-41900Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution.CRITICAL 10.0EPSS 0.91%8 May 2026
CVE-2026-41501Prior to version 3.3.8, a command injection vulnerability exists in github.com/elcterm/electerm/npm/install.js:130.CRITICAL 9.8EPSS 1.29%8 May 2026
CVE-2026-41500Prior to version 3.3.8, a command injection vulnerability exists in github.com/elcterm/electerm/npm/install.js:150.CRITICAL 9.8EPSS 1.57%8 May 2026
CVE-2026-42880From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from…CRITICAL 9.6EPSS 0.51%7 May 2026
CVE-2026-7891A vulnerability has been identified in Mendix Runtime (All versions).CRITICAL 9.1EPSS 0.27%7 May 2026
CVE-2026-35435Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 1.16%7 May 2026
CVE-2026-35428Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.CRITICAL 9.6EPSS 0.93%7 May 2026
CVE-2026-33844Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.CRITICAL 9.0EPSS 0.99%7 May 2026
CVE-2026-33109Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.CRITICAL 9.9EPSS 0.71%7 May 2026
CVE-2026-41691When an application exposes the language-code selection to user-controlled input (the default — i18next-browser-languagedetector reads ?lng= query params, cookies, localStorage, and request headers), an attacker can inject characters that change the…CRITICAL 9.1EPSS 0.31%7 May 2026
CVE-2026-42284Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)).CRITICAL 9.8EPSS 0.57%7 May 2026
CVE-2026-41902Combined with realistic hash-leakage scenarios (forwarded invite emails, HTTP referrer to external CDNs on the setup page, server-side log exposure, abandoned invite emails in shared inboxes), this enables unauthenticated permanent account takeover…CRITICAL 9.1EPSS 0.25%7 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.