SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,288 results · page 127 of 786

CVESummaryPriorityPublished
CVE-2026-5194Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature verification functions.CRITICAL 9.3EPSS 0.45%9 April 2026
CVE-2026-40089The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts).CRITICAL 9.9EPSS 0.23%9 April 2026
CVE-2026-40088Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LLM-generated tool calls, allowing attackers to inject arbitrary shell commands through shell…CRITICAL 9.6EPSS 0.42%9 April 2026
CVE-2026-29145CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.CRITICAL 9.1EPSS 0.71%9 April 2026
CVE-2025-13926An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.CRITICAL 9.3EPSS 0.44%9 April 2026
CVE-2026-39912V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active.CRITICAL 9.1EPSS 0.58%9 April 2026
CVE-2026-35556OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.CRITICAL 9.2EPSS 0.30%9 April 2026
CVE-2026-34987From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of its linear-memory sandbox.CRITICAL 9.0EPSS 0.28%9 April 2026
CVE-2026-34971Combined together this enables an arbitrary read/write primitive for guest WebAssembly when accesssing host memory.CRITICAL 9.0EPSS 0.32%9 April 2026
CVE-2026-31170An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parameter to /cgi-bin/cstecgi.cgi.CRITICAL 9.8EPSS 0.57%9 April 2026
CVE-2026-28205OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.CRITICAL 9.2EPSS 0.45%9 April 2026
CVE-2026-39987Marimo Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.3EPSS 99.6%9 April 2026
CVE-2026-30479A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted executable.CRITICAL 9.1EPSS 0.32%9 April 2026
CVE-2026-5445An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`.CRITICAL 9.1EPSS 0.67%9 April 2026
CVE-2026-5443A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images.CRITICAL 9.8EPSS 0.57%9 April 2026
CVE-2026-5442A heap buffer overflow vulnerability exists in the DICOM image decoder.CRITICAL 9.8EPSS 0.60%9 April 2026
CVE-2025-50228Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.CRITICAL 9.1EPSS 0.27%9 April 2026
CVE-2025-57735When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted.CRITICAL 9.1EPSS 0.67%9 April 2026
CVE-2026-34179In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a…CRITICAL 9.1EPSS 0.27%9 April 2026
CVE-2026-34178An authenticated remote attacker with instance-creation permission in a restricted project can craft a backup archive where backup.yaml carries restricted settings such as security.privileged=true or raw.lxc directives, bypassing all project restriction…CRITICAL 9.1EPSS 0.42%9 April 2026
CVE-2026-34177A remote attacker with can_edit permission on a VM instance in a restricted project can inject an AppArmor rule and a QEMU chardev configuration that bridges the LXD Unix socket into the guest VM, enabling privilege escalation to LXD cluster…CRITICAL 9.1EPSS 0.36%9 April 2026
CVE-2026-1830The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1.EXPLOITCRITICAL 9.8EPSS 8.09%9 April 2026
CVE-2026-3199A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security…CRITICAL 9.4EPSS 0.56%8 April 2026
CVE-2026-5902Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page.CRITICAL 9.8EPSS 0.21%8 April 2026
CVE-2026-5874Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.25%8 April 2026
CVE-2026-40035Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default.CRITICAL 9.3EPSS 0.56%8 April 2026
CVE-2026-39890This allows an attacker to craft a malicious YAML file that, when parsed, executes arbitrary JavaScript code.CRITICAL 9.8EPSS 0.58%8 April 2026
CVE-2026-39888Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a restricted __builtins__ dict and an AST-based blocklist.CRITICAL 9.9EPSS 0.48%8 April 2026
CVE-2026-39429Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place.CRITICAL 9.1EPSS 0.44%8 April 2026
CVE-2026-35477Additionally, the validator uses a dummy Part instance with pk=None, which allows conditional template expressions to behave differently during validation versus production rendering.CRITICAL 9.9EPSS 0.26%8 April 2026
CVE-2026-2942The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9.CRITICAL 9.8EPSS 0.58%8 April 2026
CVE-2026-33466Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139).CRITICAL 9.8EPSS 0.55%8 April 2026
CVE-2025-52221Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.CRITICAL 9.8EPSS 0.39%8 April 2026
CVE-2026-31017A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF.CRITICAL 9.1EPSS 0.24%8 April 2026
CVE-2023-46945QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted requestCRITICAL 9.1EPSS 0.24%8 April 2026
CVE-2026-31040A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.CRITICAL 9.8EPSS 0.56%8 April 2026
CVE-2026-39394Because newline characters in the value are not stripped, an attacker can inject arbitrary configuration directives into the .env file.CRITICAL 9.8EPSS 0.52%8 April 2026
CVE-2025-14816Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior,…CRITICAL 9.3EPSS 0.10%8 April 2026
CVE-2025-14815Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi…CRITICAL 9.3EPSS 0.10%8 April 2026
CVE-2026-5300Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requestsCRITICAL 9.1EPSS 0.22%8 April 2026
CVE-2026-39640Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.CRITICAL 9.6EPSS 0.14%8 April 2026
CVE-2026-39620Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.CRITICAL 9.6EPSS 0.14%8 April 2026
CVE-2026-39619Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5.2.CRITICAL 9.6EPSS 0.14%8 April 2026
CVE-2026-39617Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.CRITICAL 9.6EPSS 0.14%8 April 2026
CVE-2026-25776Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.CRITICAL 9.3EPSS 0.47%8 April 2026
CVE-2026-3535The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1.CRITICAL 9.8EPSS 0.92%8 April 2026
CVE-2026-4003The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15.CRITICAL 9.8EPSS 0.89%8 April 2026
CVE-2026-3296The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata.CRITICAL 9.8EPSS 3.47%8 April 2026
CVE-2026-27143Arithmetic over induction variables in loops were not correctly checked for underflow or overflow.CRITICAL 9.8EPSS 0.54%8 April 2026
CVE-2026-39846Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client.CRITICAL 9.0EPSS 0.54%7 April 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.