SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,287 results · page 118 of 786

CVESummaryPriorityPublished
CVE-2025-59852HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of…CRITICAL 9.1EPSS 0.09%6 May 2026
CVE-2025-59851HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and exploit publicly known security vulnerabilities to…CRITICAL 9.8EPSS 0.21%6 May 2026
CVE-2026-43117In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on top of btrfs, dentry->d_sb translates to overlay's super block and fsid…CRITICAL 9.1EPSS 0.40%6 May 2026
CVE-2026-43114In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used.CRITICAL 9.4EPSS 0.37%6 May 2026
CVE-2026-43083In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can…CRITICAL 9.1EPSS 0.44%6 May 2026
CVE-2026-40010Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket.CRITICAL 9.1EPSS 0.38%6 May 2026
CVE-2026-28780Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.CRITICAL 9.8EPSS 1.38%5 May 2026
CVE-2026-40331This value is injected directly into a SQL FROM clause within feedGateway.cfc.CRITICAL 9.3EPSS 0.32%5 May 2026
CVE-2026-40330In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's handling of the sortDirection parameter.CRITICAL 9.3EPSS 0.43%5 May 2026
CVE-2026-40329In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's processing of the sortBy parameter.CRITICAL 9.3EPSS 0.30%5 May 2026
CVE-2026-34458In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration restrictions (EditAdminOnly and ConfigPassword) and inject arbitrary directives into the global Sandboxie.ini configuration file.CRITICAL 9.3EPSS 0.25%5 May 2026
CVE-2026-34084In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wrapper path (such as…CRITICAL 9.2EPSS 0.71%5 May 2026
CVE-2026-33324In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection.CRITICAL 9.4EPSS 0.60%5 May 2026
CVE-2026-38428Kestra v1.3.3 and before is vulnerable to SQL Injection.CRITICAL 9.8EPSS 0.37%5 May 2026
CVE-2026-27960In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin account.CRITICAL 9.8EPSS 1.99%5 May 2026
CVE-2026-38431ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI).CRITICAL 9.8EPSS 0.39%5 May 2026
CVE-2026-38429OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.CRITICAL 9.8EPSS 0.30%5 May 2026
CVE-2026-7411In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack.CRITICAL 10.0EPSS 3.68%5 May 2026
CVE-2026-43071In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1': BUG: unable to handle page fault for address:…CRITICAL 9.1EPSS 0.40%5 May 2026
CVE-2026-43067In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks for indirect mapped blocks Commit 4865c768b563 ("ext4: always allocate blocks only from groups inode can use") restricts what blocks…CRITICAL 9.8EPSS 0.40%5 May 2026
CVE-2026-34002This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling.CRITICAL 9.1EPSS 0.49%5 May 2026
CVE-2026-34000This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory.CRITICAL 9.1EPSS 0.49%5 May 2026
CVE-2026-36356The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.EXPLOITCRITICAL 9.1EPSS 13.5%5 May 2026
CVE-2026-34408The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known.CRITICAL 9.1EPSS 0.26%5 May 2026
CVE-2026-43566OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content.CRITICAL 9.1EPSS 0.42%5 May 2026
CVE-2026-43534OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events.CRITICAL 9.3EPSS 0.19%5 May 2026
CVE-2023-54344Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface.CRITICAL 9.3EPSS 0.55%5 May 2026
CVE-2023-54342Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality.CRITICAL 9.3EPSS 0.46%5 May 2026
CVE-2026-40797Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection.CRITICAL 9.3EPSS 0.35%5 May 2026
CVE-2026-5294The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2.CRITICAL 9.8EPSS 0.46%5 May 2026
CVE-2025-13618The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8.CRITICAL 9.8EPSS 0.34%5 May 2026
CVE-2026-5722The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14.CRITICAL 9.8EPSS 0.46%5 May 2026
CVE-2026-42238Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation.CRITICAL 9.0EPSS 0.76%4 May 2026
CVE-2026-42222In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install.CRITICAL 9.8EPSS 0.34%4 May 2026
CVE-2026-42221From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window.CRITICAL 9.8EPSS 1.17%4 May 2026
CVE-2026-41926WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across five request handlers that apply insufficient input validation.CRITICAL 9.3EPSS 1.23%4 May 2026
CVE-2026-41925WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious…CRITICAL 9.3EPSS 3.39%4 May 2026
CVE-2026-41924WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the…CRITICAL 9.3EPSS 2.71%4 May 2026
CVE-2026-41923WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the…CRITICAL 9.3EPSS 2.61%4 May 2026
CVE-2026-41922WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the…CRITICAL 9.3EPSS 4.98%4 May 2026
CVE-2026-42232Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype pollution.CRITICAL 9.4EPSS 0.48%4 May 2026
CVE-2026-42231Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload.CRITICAL 9.4EPSS 0.85%4 May 2026
CVE-2026-42796Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization.CRITICAL 9.2EPSS 2.75%4 May 2026
CVE-2026-42087From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS.CRITICAL 9.6EPSS 0.32%4 May 2026
CVE-2026-41571In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored password.CRITICAL 9.4EPSS 0.30%4 May 2026
CVE-2026-42812For a table already registered in a Polaris-managed catalog, changing only that property through an `ALTER TABLE`-style settings change (not a row-level `INSERT`, `SELECT`, `UPDATE`, or `DELETE`) bypasses the commit-time branch that is supposed to…CRITICAL 9.4EPSS 0.36%4 May 2026
CVE-2026-42811In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead.CRITICAL 9.4EPSS 0.43%4 May 2026
CVE-2026-42810A control case using ordinary different names did not allow the same cross-table access.CRITICAL 9.4EPSS 0.43%4 May 2026
CVE-2026-42809Those temporary credentials are meant to limit the scope of accessible table data and metadata, but this scope limitation becomes attacker- directed because the attacker can choose a reachable target location.CRITICAL 9.4EPSS 0.36%4 May 2026
CVE-2026-42376D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor.CRITICAL 9.8EPSS 0.46%4 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.