SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,287 results · page 119 of 786

CVESummaryPriorityPublished
CVE-2026-42090Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app.CRITICAL 9.6EPSS 0.48%4 May 2026
CVE-2026-42076Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell commands on the server.CRITICAL 9.8EPSS 1.31%4 May 2026
CVE-2026-42027Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its…CRITICAL 9.8EPSS 0.71%4 May 2026
CVE-2026-40682XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load…CRITICAL 9.1EPSS 0.50%4 May 2026
CVE-2026-26956In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution.CRITICAL 9.8EPSS 0.92%4 May 2026
CVE-2026-26332Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code.CRITICAL 10.0EPSS 0.71%4 May 2026
CVE-2026-25293Buffer overflow due to incorrect authorization in PLC FWCRITICAL 9.8EPSS 0.18%4 May 2026
CVE-2026-24781Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function.CRITICAL 9.8EPSS 1.19%4 May 2026
CVE-2026-24120Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.CRITICAL 9.8EPSS 0.90%4 May 2026
CVE-2026-24118Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability.CRITICAL 9.8EPSS 0.91%4 May 2026
CVE-2025-136053onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by providing payload in the "IP address" field of the diagnosis test…CRITICAL 9.3EPSS 0.20%4 May 2026
CVE-2025-70067Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer.CRITICAL 9.8EPSS 0.34%4 May 2026
CVE-2025-14320Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allows Reflected XSS.CRITICAL 9.8EPSS 0.33%4 May 2026
CVE-2026-29200A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1.CRITICAL 9.9EPSS 0.30%4 May 2026
CVE-2026-7372A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2.CRITICAL 9.0EPSS 0.47%4 May 2026
CVE-2026-7161An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5.CRITICAL 9.3EPSS 0.22%4 May 2026
CVE-2026-42370A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2.CRITICAL 9.8EPSS 0.55%4 May 2026
CVE-2026-42369It is a native application accessed locally, but it is also possible to enable remote access via the "WebCam Server" feature.CRITICAL 10.0EPSS 0.54%4 May 2026
CVE-2026-42368A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10.CRITICAL 9.9EPSS 0.36%4 May 2026
CVE-2026-7458The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46.CRITICAL 9.8EPSS 0.58%2 May 2026
CVE-2026-4882The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to, and including, 1.6.20.CRITICAL 9.8EPSS 0.65%2 May 2026
CVE-2026-37541Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005.CRITICAL 10.0EPSS 0.68%1 May 2026
CVE-2026-37540OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing.CRITICAL 9.8EPSS 0.25%1 May 2026
CVE-2026-37539Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remote attackers to cause a denial of service (crash) or possibly execute arbitrary code…CRITICAL 9.8EPSS 0.54%1 May 2026
CVE-2026-37534Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Protocol_Data_Transfer,allows attackers to write to arbitrary memory via crafted sequence number from the CAN…CRITICAL 9.8EPSS 0.42%1 May 2026
CVE-2026-37531AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow.CRITICAL 9.8EPSS 0.71%1 May 2026
CVE-2026-42473Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17.CRITICAL 9.8EPSS 0.38%1 May 2026
CVE-2026-42472Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17.CRITICAL 9.8EPSS 0.38%1 May 2026
CVE-2026-43039In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix missing data copy and wrong recycle in ZC RX dispatch emac_dispatch_skb_zc() allocates a new skb via napi_alloc_skb() but never copies the packet data from…CRITICAL 9.8EPSS 0.31%1 May 2026
CVE-2026-43038In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet where its cb…CRITICAL 9.8EPSS 0.26%1 May 2026
CVE-2026-43037In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as…CRITICAL 9.8EPSS 0.56%1 May 2026
CVE-2026-43011In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error).CRITICAL 9.8EPSS 0.59%1 May 2026
CVE-2026-42484A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash file.CRITICAL 9.8EPSS 0.44%1 May 2026
CVE-2026-42483A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted Kerberos hash file.CRITICAL 9.8EPSS 0.30%1 May 2026
CVE-2026-42482A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted rule file, or via the -j or -k rule…CRITICAL 9.8EPSS 0.40%1 May 2026
CVE-2026-31718In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger When a durable file handle survives session disconnect (TCP close without SMB2_LOGOFF), session_fd_check() sets…CRITICAL 9.8EPSS 0.36%1 May 2026
CVE-2026-31705In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment smb2_get_ea() applies 4-byte alignment padding via memset() after writing each EA entry.CRITICAL 9.8EPSS 0.39%1 May 2026
CVE-2026-42779Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary…CRITICAL 9.8EPSS 0.90%1 May 2026
CVE-2026-42778The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed.CRITICAL 9.8EPSS 0.66%1 May 2026
CVE-2026-7567The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0.EXPLOITCRITICAL 9.8EPSS 9.25%1 May 2026
CVE-2026-42996JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator.CRITICAL 10.0EPSS 0.48%1 May 2026
CVE-2026-40687In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.CRITICAL 9.1EPSS 0.37%30 April 2026
CVE-2026-40685In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.CRITICAL 9.8EPSS 0.32%30 April 2026
CVE-2026-2311IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.CRITICAL 9.8EPSS 0.20%30 April 2026
CVE-2026-33845A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read.CRITICAL 9.1EPSS 0.80%30 April 2026
CVE-2026-36767A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.CRITICAL 10.0EPSS 0.41%30 April 2026
CVE-2026-36760An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem…CRITICAL 9.6EPSS 0.38%30 April 2026
CVE-2025-71284Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly into a sed command without…CRITICAL 9.3EPSS 5.73%30 April 2026
CVE-2022-50993Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with…CRITICAL 9.3EPSS 0.77%30 April 2026
CVE-2026-4670Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.CRITICAL 9.8EPSS 5.63%30 April 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.