SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,288 results · page 123 of 786

CVESummaryPriorityPublished
CVE-2026-40933Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution.CRITICAL 9.9EPSS 12.0%21 April 2026
CVE-2026-40911In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies to every connected client without sanitizing the `msg` or `callback` fields.CRITICAL 10.0EPSS 0.65%21 April 2026
CVE-2026-40910From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used as part of access control.CRITICAL 9.1EPSS 0.27%21 April 2026
CVE-2026-34287Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).CRITICAL 9.1EPSS 0.35%21 April 2026
CVE-2026-34286Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).CRITICAL 9.1EPSS 0.41%21 April 2026
CVE-2026-34285Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).CRITICAL 9.1EPSS 0.41%21 April 2026
CVE-2026-34279Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management).CRITICAL 9.1EPSS 0.44%21 April 2026
CVE-2026-34275Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration).CRITICAL 9.8EPSS 0.38%21 April 2026
CVE-2026-33519An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.CRITICAL 9.8EPSS 0.31%21 April 2026
CVE-2026-40903Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability.CRITICAL 9.1EPSS 0.24%21 April 2026
CVE-2026-40887Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API.CRITICAL 9.1EPSS 1.76%21 April 2026
CVE-2026-40884Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used.CRITICAL 9.8EPSS 0.48%21 April 2026
CVE-2026-40872By submitting an unauthenticated Autodiscover request with a crafted EMailAddress containing HTML/JS, the payload is stored in Redis and executed when an admin views the Autodiscover logs.CRITICAL 9.3EPSS 0.28%21 April 2026
CVE-2026-40372Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.1EPSS 11.2%21 April 2026
CVE-2026-41193Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives without validating file paths, allowing an authenticated admin to write files arbitrarily on the server filesystem via a specially crafted ZIP.CRITICAL 9.1EPSS 0.39%21 April 2026
CVE-2026-5652An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.CRITICAL 9.0EPSS 0.44%21 April 2026
CVE-2026-40576A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7.CRITICAL 9.4EPSS 0.39%21 April 2026
CVE-2026-40569Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesController.php:468` and `connectionOutgoingSave()` at line 398).CRITICAL 9.0EPSS 0.30%21 April 2026
CVE-2026-40050CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale.CRITICAL 9.8EPSS 0.60%21 April 2026
CVE-2026-38835Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter.CRITICAL 9.8EPSS 2.15%21 April 2026
CVE-2026-21571This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.CRITICAL 9.4EPSS 1.34%21 April 2026
CVE-2019-25714Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with…CRITICAL 9.3EPSS 0.65%21 April 2026
CVE-2025-41029SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech.CRITICAL 9.3EPSS 0.24%21 April 2026
CVE-2025-15638Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt.CRITICAL 10.0EPSS 0.57%21 April 2026
CVE-2017-20230Storable versions before 3.05 for Perl has a stack overflow.CRITICAL 10.0EPSS 0.64%21 April 2026
CVE-2026-6771Mitigation bypass in the DOM: Security component.CRITICAL 9.8EPSS 0.31%21 April 2026
CVE-2026-6768Mitigation bypass in the Networking: Cookies component.CRITICAL 9.8EPSS 0.29%21 April 2026
CVE-2026-6760Mitigation bypass in the Networking: Cookies component.CRITICAL 9.8EPSS 0.28%21 April 2026
CVE-2026-6748This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.CRITICAL 9.8EPSS 0.40%21 April 2026
CVE-2026-5965NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.CRITICAL 9.3EPSS 1.64%21 April 2026
CVE-2026-41329OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation.CRITICAL 9.0EPSS 0.30%21 April 2026
CVE-2026-5450Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.CRITICAL 9.8EPSS 0.50%20 April 2026
CVE-2026-32613In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restricting that context to a set of trusted classes, but allowing FULL JVM access.CRITICAL 9.9EPSS 0.55%20 April 2026
CVE-2026-32604In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods.CRITICAL 9.9EPSS 0.61%20 April 2026
CVE-2026-29646This breaks privilege/virtualization isolation and can lead to denial of service or privilege-boundary violation in environments relying on NEMU for correct interrupt virtualization.CRITICAL 9.8EPSS 0.36%20 April 2026
CVE-2026-6257Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to rename files to blocked extensions .php or .htaccess.CRITICAL 9.2EPSS 0.63%20 April 2026
CVE-2026-32311Flowsint allows a user to create investigations, which are used to manage sketches and analyses.CRITICAL 9.3EPSS 0.51%20 April 2026
CVE-2026-29649This can lead to incorrect enforcement of virtualization configuration and may cause unexpected traps or denial of service when executing cache-block management instructions in virtualized contexts (V=1).CRITICAL 9.8EPSS 0.45%20 April 2026
CVE-2026-39109SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php).CRITICAL 9.4EPSS 0.33%20 April 2026
CVE-2026-30269Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}.CRITICAL 9.9EPSS 0.28%20 April 2026
CVE-2026-39918Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation.CRITICAL 9.2EPSS 0.66%20 April 2026
CVE-2026-24467OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests.CRITICAL 9.8EPSS 0.90%20 April 2026
CVE-2026-5760SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().CRITICAL 9.8EPSS 0.85%20 April 2026
CVE-2026-33557A possible security vulnerability has been identified in Apache Kafka.CRITICAL 9.1EPSS 0.68%20 April 2026
CVE-2026-5964EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.CRITICAL 9.3EPSS 0.37%20 April 2026
CVE-2026-5963EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.CRITICAL 9.3EPSS 0.37%20 April 2026
CVE-2026-6644A command injection vulnerability was found in the PPTP VPN Clients on the ADM.CRITICAL 9.4EPSS 1.45%20 April 2026
CVE-2026-32956SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs.CRITICAL 9.3EPSS 0.52%20 April 2026
CVE-2026-41242In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition.CRITICAL 9.4EPSS 0.77%18 April 2026
CVE-2026-40494Prior to commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302, the TGA codec's RLE decoder in `tga.c` has an asymmetric bounds check vulnerability.CRITICAL 9.8EPSS 0.31%18 April 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.