SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,286 results · page 117 of 786

CVESummaryPriorityPublished
CVE-2026-37709Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php componentCRITICAL 9.8EPSS 0.60%7 May 2026
CVE-2026-7415The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs.CRITICAL 9.8EPSS 0.54%7 May 2026
CVE-2026-7414Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image.CRITICAL 9.8EPSS 0.53%7 May 2026
CVE-2026-7413A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality.CRITICAL 9.8EPSS 0.58%7 May 2026
CVE-2026-7821Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM…CRITICAL 9.1EPSS 0.51%7 May 2026
CVE-2026-5788An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.CRITICAL 9.8EPSS 0.82%7 May 2026
CVE-2026-5787An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.CRITICAL 9.1EPSS 0.69%7 May 2026
CVE-2025-63704NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution.CRITICAL 9.8EPSS 0.48%7 May 2026
CVE-2025-63703npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().CRITICAL 9.8EPSS 0.42%7 May 2026
CVE-2026-36458ChestnutCMS v1.5.10 has a SQL injection vulnerability.CRITICAL 9.8EPSS 0.37%7 May 2026
CVE-2025-63706NPM package next-npm-version1.0.1 is vulnerable to Command injection.CRITICAL 9.8EPSS 1.52%7 May 2026
CVE-2026-6795URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc.CRITICAL 9.6EPSS 0.23%7 May 2026
CVE-2026-41589From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks.CRITICAL 9.6EPSS 0.39%7 May 2026
CVE-2026-30496The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device.CRITICAL 9.8EPSS 0.33%7 May 2026
CVE-2026-8094This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.CRITICAL 9.8EPSS 0.45%7 May 2026
CVE-2026-8091This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.CRITICAL 9.8EPSS 0.47%7 May 2026
CVE-2026-6508Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs.CRITICAL 9.8EPSS 0.22%7 May 2026
CVE-2026-42010A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass.CRITICAL 9.8EPSS 1.05%7 May 2026
CVE-2026-33587Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.CRITICAL 9.2EPSS 0.23%7 May 2026
CVE-2025-1978Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090,…CRITICAL 9.8EPSS 0.55%7 May 2026
CVE-2025-9661OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28.CRITICAL 9.8EPSS 0.90%7 May 2026
CVE-2026-41586From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter.CRITICAL 9.3EPSS 0.53%7 May 2026
CVE-2026-44603Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.CRITICAL 9.1EPSS 0.34%7 May 2026
CVE-2026-41203Prior to version 0.31.5.0, ci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create permission to write files to arbitrary filesystem locations (Zip Slip) and…CRITICAL 9.4EPSS 0.48%7 May 2026
CVE-2026-41202Prior to version 0.31.5.0, ci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and…CRITICAL 9.4EPSS 0.53%7 May 2026
CVE-2026-41201In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege Escalation via Stored DOM XSS in backup module filename field manipulated via a sql file that tampers with the file name field to contain hidden XSS payload.CRITICAL 9.1EPSS 0.33%7 May 2026
CVE-2026-40982Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module.CRITICAL 9.1EPSS 0.73%7 May 2026
CVE-2026-44597Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.CRITICAL 9.1EPSS 0.45%7 May 2026
CVE-2026-40281A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink, and -HardLink.CRITICAL 9.1EPSS 0.61%6 May 2026
CVE-2026-44109OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch.CRITICAL 9.2EPSS 0.72%6 May 2026
CVE-2026-43585OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation.CRITICAL 9.2EPSS 0.54%6 May 2026
CVE-2026-43581OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0.CRITICAL 9.0EPSS 0.21%6 May 2026
CVE-2026-43578OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events.CRITICAL 9.1EPSS 0.29%6 May 2026
CVE-2026-43575OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials.CRITICAL 9.2EPSS 0.40%6 May 2026
CVE-2026-40076In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint at POST `/openmrs/ws/rest/v1/module` is vulnerable to a Zip Slip path traversal attack.CRITICAL 9.4EPSS 0.85%6 May 2026
CVE-2026-7910Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.CRITICAL 9.6EPSS 0.22%6 May 2026
CVE-2026-7908Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.22%6 May 2026
CVE-2026-41930Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials.CRITICAL 9.2EPSS 0.35%6 May 2026
CVE-2026-0300Palo Alto Networks PAN-OS Out-of-bounds Write VulnerabilityKEVCRITICAL 9.3EPSS 31.7%6 May 2026
CVE-2026-29090### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.create_postgres_query()`.CRITICAL 9.0EPSS 0.30%6 May 2026
CVE-2026-7875NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that allows a compromised or prompt-injected container to read files outside the intended outbox directory by…CRITICAL 9.3EPSS 0.15%6 May 2026
CVE-2026-29080A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search endpoint (`GET /dids/<scope>/dids/search`).CRITICAL 9.4EPSS 0.28%6 May 2026
CVE-2026-5081Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure.CRITICAL 9.1EPSS 0.30%6 May 2026
CVE-2026-43208In the Linux kernel, the following vulnerability has been resolved: net: do not pass flow_id to set_rps_cpu() Blamed commit made the assumption that the RPS table for each receive queue would have the same size, and that it would not change.CRITICAL 9.8EPSS 0.48%6 May 2026
CVE-2026-43198In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late.CRITICAL 9.8EPSS 0.30%6 May 2026
CVE-2026-43197In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated.CRITICAL 9.1EPSS 0.48%6 May 2026
CVE-2026-43186In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node.CRITICAL 9.8EPSS 0.64%6 May 2026
CVE-2026-43185In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prepare_negotiation() casts an unsigned __u32 value from sp->max_recv_size and req->preferred_send_size to a…CRITICAL 9.8EPSS 0.62%6 May 2026
CVE-2026-43125In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages.CRITICAL 9.8EPSS 0.43%6 May 2026
CVE-2025-59852HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of…CRITICAL 9.1EPSS 0.09%6 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.