SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,288 results · page 126 of 786

CVESummaryPriorityPublished
CVE-2026-31048An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message.CRITICAL 9.8EPSS 0.57%13 April 2026
CVE-2026-40044Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files.CRITICAL 9.3EPSS 0.48%13 April 2026
CVE-2026-40042Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper.CRITICAL 9.3EPSS 0.37%13 April 2026
CVE-2026-6100Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used.CRITICAL 9.1EPSS 0.58%13 April 2026
CVE-2026-23891In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in…CRITICAL 9.3EPSS 0.36%13 April 2026
CVE-2025-31991This vulnerability is fixed in 5.1.7.CRITICAL 9.8EPSS 0.23%13 April 2026
CVE-2026-31283In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack.CRITICAL 9.8EPSS 0.40%13 April 2026
CVE-2026-31282Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control.CRITICAL 9.8EPSS 0.39%13 April 2026
CVE-2026-31414In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetlink and /proc to dump the helper name.CRITICAL 9.8EPSS 0.40%13 April 2026
CVE-2026-4810A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary…CRITICAL 9.3EPSS 1.82%13 April 2026
CVE-2026-5936An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations.CRITICAL 9.8EPSS 0.19%13 April 2026
CVE-2026-5085Solstice::Session versions through 1440 for Perl generates session ids insecurely.CRITICAL 9.1EPSS 0.34%13 April 2026
CVE-2026-34865Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.CRITICAL 10.0EPSS 0.21%13 April 2026
CVE-2026-40446Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.CRITICAL 9.8EPSS 0.23%13 April 2026
CVE-2026-25209Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.CRITICAL 9.1EPSS 0.25%13 April 2026
CVE-2026-25208Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.CRITICAL 9.8EPSS 0.25%13 April 2026
CVE-2026-25207Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.CRITICAL 9.8EPSS 0.19%13 April 2026
CVE-2026-25206Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.CRITICAL 9.1EPSS 0.18%13 April 2026
CVE-2026-25205Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write.This issue affects Escargot:commit hash 97e8115ab1110bc502b4b5e4a0c689a71520d335 .CRITICAL 9.8EPSS 0.19%13 April 2026
CVE-2026-40393In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.CRITICAL 9.8EPSS 0.43%12 April 2026
CVE-2019-25709CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory.CRITICAL 9.3EPSS 0.61%12 April 2026
CVE-2026-31845A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php).CRITICAL 9.3EPSS 0.43%11 April 2026
CVE-2026-5059aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability.CRITICAL 9.8EPSS 1.91%11 April 2026
CVE-2026-5058aws-mcp-server Command Injection Remote Code Execution Vulnerability.CRITICAL 9.8EPSS 1.83%11 April 2026
CVE-2026-4149Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability.CRITICAL 9.8EPSS 1.00%11 April 2026
CVE-2026-40190The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype.CRITICAL 9.8EPSS 0.31%10 April 2026
CVE-2026-40189An unauthenticated attacker can upload files with PUT, upload files with multipart POST /upload, create directories with ?mkdir, and delete files with ?delete inside a .goshs-protected directory.CRITICAL 9.3EPSS 0.64%10 April 2026
CVE-2026-40177ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly.CRITICAL 9.3EPSS 0.33%10 April 2026
CVE-2026-33707An attacker who knows a user's email can compute the reset token and change the victim's password without authentication.CRITICAL 9.8EPSS 0.43%10 April 2026
CVE-2026-33698Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions.CRITICAL 9.3EPSS 0.32%10 April 2026
CVE-2026-5483This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint.CRITICAL 9.9EPSS 0.49%10 April 2026
CVE-2026-40157An attacker who distributes a malicious bundle can overwrite arbitrary files on the victim's filesystem when they run praisonai recipe unpack.CRITICAL 9.4EPSS 0.38%10 April 2026
CVE-2026-34727This vulnerability is fixed in 2.3.0.CRITICAL 9.1EPSS 0.28%10 April 2026
CVE-2026-23781A set of default debug user credentials is hardcoded in cleartext within the application package.CRITICAL 9.8EPSS 0.28%10 April 2026
CVE-2026-36236SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.CRITICAL 9.8EPSS 0.32%10 April 2026
CVE-2026-36235A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0.CRITICAL 9.8EPSS 0.32%10 April 2026
CVE-2026-36234itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter.CRITICAL 9.8EPSS 0.32%10 April 2026
CVE-2026-36233A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0.CRITICAL 9.8EPSS 0.32%10 April 2026
CVE-2026-36232A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0.CRITICAL 9.8EPSS 0.32%10 April 2026
CVE-2026-29861PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.CRITICAL 9.8EPSS 0.32%10 April 2026
CVE-2025-44560owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.CRITICAL 9.8EPSS 0.34%10 April 2026
CVE-2026-6068NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used,…CRITICAL 9.6EPSS 0.43%10 April 2026
CVE-2026-6057FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.CRITICAL 9.8EPSS 0.93%10 April 2026
CVE-2026-1115A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0.CRITICAL 9.6EPSS 1.21%10 April 2026
CVE-2026-34424Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands.CRITICAL 9.3EPSS 0.55%9 April 2026
CVE-2026-40154Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates.CRITICAL 9.6EPSS 0.30%9 April 2026
CVE-2026-40114Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL validation.CRITICAL 10.0EPSS 0.28%9 April 2026
CVE-2026-40111Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a user-controlled command string directly to subprocess.run() with shell=True at src/praisonai-agents/praisonaiagents/memory/hooks.py.CRITICAL 9.3EPSS 0.23%9 April 2026
CVE-2026-33784A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial…CRITICAL 9.3EPSS 0.46%9 April 2026
CVE-2026-33771A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device.CRITICAL 9.1EPSS 0.26%9 April 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.