SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,288 results · page 122 of 786

CVESummaryPriorityPublished
CVE-2026-31178An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.58%23 April 2026
CVE-2026-31177An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.60%23 April 2026
CVE-2026-31175An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.58%23 April 2026
CVE-2026-40472In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks.CRITICAL 9.9EPSS 0.30%23 April 2026
CVE-2026-40471hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints.CRITICAL 9.6EPSS 0.14%23 April 2026
CVE-2026-40470A critical XSS vulnerability affected hackage-server and hackage.haskell.org.CRITICAL 9.9EPSS 0.31%23 April 2026
CVE-2026-23751Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a…CRITICAL 9.3EPSS 0.88%23 April 2026
CVE-2025-62373Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integration.CRITICAL 9.8EPSS 0.70%23 April 2026
CVE-2025-50229Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.CRITICAL 9.8EPSS 0.36%23 April 2026
CVE-2026-41460SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query.CRITICAL 9.3EPSS 0.97%23 April 2026
CVE-2026-39440Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1.CRITICAL 9.9EPSS 0.36%23 April 2026
CVE-2026-6887Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.CRITICAL 9.3EPSS 0.36%23 April 2026
CVE-2026-6886Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.CRITICAL 9.3EPSS 0.45%23 April 2026
CVE-2026-6885Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on…CRITICAL 9.3EPSS 0.50%23 April 2026
CVE-2026-3960A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior.CRITICAL 9.8EPSS 0.94%23 April 2026
CVE-2026-41229Since this file is `require`d on every request via `Database::getDB()`, an attacker can inject arbitrary PHP code that executes as the web server user on every subsequent page load.CRITICAL 9.1EPSS 0.48%23 April 2026
CVE-2026-41228An authenticated customer can set `def_language` to a path traversal payload (e.g., `../../../../../var/customers/webs/customer1/evil`), which is stored in the database.CRITICAL 9.9EPSS 0.52%23 April 2026
CVE-2026-3844The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4.CRITICAL 9.8EPSS 27.7%23 April 2026
CVE-2026-41679Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration.CRITICAL 10.0EPSS 18.9%23 April 2026
CVE-2026-41197Foreign calls returning nested arrays of tuples or other composite types corrupt the Brillig VM heap.CRITICAL 9.3EPSS 0.40%23 April 2026
CVE-2026-41196Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and gain full filesystem access on the user's device.CRITICAL 9.0EPSS 0.37%23 April 2026
CVE-2026-5935IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.CRITICAL 9.8EPSS 0.34%23 April 2026
CVE-2026-41179Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and accepts attacker-controlled `fs` input.CRITICAL 9.2EPSS 8.58%23 April 2026
CVE-2026-41176The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself.CRITICAL 9.2EPSS 32.7%23 April 2026
CVE-2026-29198In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.CRITICAL 9.8EPSS 0.42%23 April 2026
CVE-2026-41167An authenticated user can inject arbitrary SQL via `POST /api/getUserDetails` and `POST /api/getLibrary`, enabling full read of any table in the database - including `app_config`, which stores the Jellystat admin credentials, the Jellyfin API key, and…CRITICAL 9.1EPSS 0.52%22 April 2026
CVE-2026-33656Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field on `Attachment` entities.CRITICAL 9.1EPSS 0.50%22 April 2026
CVE-2026-33471Prior to version 1.3.0, if an attacker can get a `SkipBlockProof` verified where `MultiSignature.signers` contains out-of-range indices spaced by 65536, these indices inflate `len()` but collide onto the same in-range `u16` slot during aggregation.CRITICAL 9.6EPSS 0.22%22 April 2026
CVE-2026-41468When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM…CRITICAL 9.3EPSS 0.39%22 April 2026
CVE-2026-34415Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern.CRITICAL 9.3EPSS 3.57%22 April 2026
CVE-2026-26354Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain a stack-based Buffer…CRITICAL 9.8EPSS 0.50%22 April 2026
CVE-2026-32885Downloads and extracts archives from remote sources without path validation.CRITICAL 9.1EPSS 0.42%22 April 2026
CVE-2018-25272ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions.CRITICAL 9.3EPSS 0.42%22 April 2026
CVE-2018-25270ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter.CRITICAL 9.3EPSS 0.89%22 April 2026
CVE-2026-6356A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitive information.CRITICAL 9.6EPSS 0.29%22 April 2026
CVE-2026-33608An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring…CRITICAL 9.8EPSS 0.38%22 April 2026
CVE-2026-33598A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.CRITICAL 9.1EPSS 1.07%22 April 2026
CVE-2026-31501In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path cppi5_hdesc_get_psdata() returns a pointer into the CPPI descriptor.CRITICAL 9.8EPSS 0.38%22 April 2026
CVE-2026-31478In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() After this commit (e2b76ab8b5c9 "ksmbd: add support for read compound"), response buffer management was…CRITICAL 9.8EPSS 0.50%22 April 2026
CVE-2026-31463In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access when i_blkbits differs from I/O granularity Commit aa35dd5cbc06 ("iomap: fix invalid folio access after folio_end_read()") partially addressed invalid…CRITICAL 9.8EPSS 0.38%22 April 2026
CVE-2026-31448In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if inserting a new extent into the extent tree fails (in this…CRITICAL 9.4EPSS 0.44%22 April 2026
CVE-2026-31444In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock() has two issues in the oplock publication sequence: 1) opinfo is linked into ci->m_op_list (via…CRITICAL 9.8EPSS 0.45%22 April 2026
CVE-2026-31436In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() At the end of this function, d is the traversal cursor of flist, but the code completes found instead.CRITICAL 9.8EPSS 0.46%22 April 2026
CVE-2026-6235The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20.CRITICAL 9.8EPSS 0.58%22 April 2026
CVE-2026-4119The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1.CRITICAL 9.1EPSS 0.73%22 April 2026
CVE-2026-6023In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client.CRITICAL 9.8EPSS 0.54%22 April 2026
CVE-2026-41144Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow.CRITICAL 9.8EPSS 0.43%22 April 2026
CVE-2026-41064WWBN AVideo is an open source video platform.CRITICAL 9.3EPSS 0.34%22 April 2026
CVE-2026-40575An attacker can spoof this header so OAuth2 Proxy evaluates authentication and skip-auth rules against a different path than the one actually sent to the upstream application.CRITICAL 9.1EPSS 0.48%22 April 2026
CVE-2026-40946This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia.CRITICAL 9.2EPSS 0.26%21 April 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.