SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,288 results · page 128 of 786

CVESummaryPriorityPublished
CVE-2026-34580The impact is that if an end entity certificate is presented, and its DN (and subject key identifier, if set) match that of any trusted root, the end entity certificate is accepted immediately as if it itself were a trusted root. , This vulnerability is…CRITICAL 9.3EPSS 0.25%7 April 2026
CVE-2026-34078Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths.CRITICAL 9.3EPSS 1.68%7 April 2026
CVE-2026-31789Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.CRITICAL 9.8EPSS 0.24%7 April 2026
CVE-2026-39397Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control.CRITICAL 9.8EPSS 0.38%7 April 2026
CVE-2026-34045Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information.CRITICAL 9.1EPSS 0.47%7 April 2026
CVE-2026-33439Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter.CRITICAL 9.3EPSS 10.0%7 April 2026
CVE-2026-39382Because comment-body is attacker-controlled text and is inserted into shell syntax without escaping, a malicious comment body can break out of the quoted string and inject arbitrary shell commands.CRITICAL 9.3EPSS 0.39%7 April 2026
CVE-2026-39322PolarLearn is a free and open-source learning program.CRITICAL 9.2EPSS 0.24%7 April 2026
CVE-2025-69515An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.CRITICAL 9.1EPSS 0.46%7 April 2026
CVE-2025-71058Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configured upstream DNS server.CRITICAL 9.1EPSS 0.45%7 April 2026
CVE-2026-39342Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection.CRITICAL 9.4EPSS 0.31%7 April 2026
CVE-2026-39339Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protected API endpoints by including "api/public" anywhere in the…CRITICAL 9.1EPSS 1.35%7 April 2026
CVE-2026-39337Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise.CRITICAL 10.0EPSS 0.71%7 April 2026
CVE-2026-39324This allows an unauthenticated attacker to supply a crafted session cookie that is accepted as valid session data without knowledge of any configured secret.CRITICAL 9.3EPSS 0.27%7 April 2026
CVE-2026-35573Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files.CRITICAL 9.1EPSS 0.77%7 April 2026
CVE-2026-31272MRCMS 3.1.2 contains an access control vulnerability.CRITICAL 9.8EPSS 0.58%7 April 2026
CVE-2026-31271megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality.CRITICAL 9.8EPSS 0.55%7 April 2026
CVE-2026-4631Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization.EXPLOITCRITICAL 9.8EPSS 15.5%7 April 2026
CVE-2026-39305Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the configured workspace directory.CRITICAL 10.0EPSS 0.31%7 April 2026
CVE-2026-35615This makes the check completely useless and allows trivial path traversal to any file on the system.CRITICAL 9.2EPSS 0.42%7 April 2026
CVE-2026-35614Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update.CRITICAL 9.3EPSS 0.26%7 April 2026
CVE-2026-35580Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax.CRITICAL 9.1EPSS 0.57%7 April 2026
CVE-2026-23696Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter.CRITICAL 9.4EPSS 13.6%7 April 2026
CVE-2024-36058The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the…CRITICAL 9.8EPSS 0.48%7 April 2026
CVE-2026-35490This vulnerability is fixed in 0.54.8.CRITICAL 9.8EPSS 0.54%7 April 2026
CVE-2026-33816Memory-safety vulnerability in github.com/jackc/pgx/v5.CRITICAL 9.8EPSS 0.56%7 April 2026
CVE-2026-33815Memory-safety vulnerability in github.com/jackc/pgx/v5.CRITICAL 9.8EPSS 0.60%7 April 2026
CVE-2025-52908Incorrect Handling of the NL80211 vendor command leads to a buffer overflow via a certain ioctl message, issue 1 of 2.CRITICAL 9.8EPSS 0.50%7 April 2026
CVE-2024-36057Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution.CRITICAL 9.8EPSS 1.80%7 April 2026
CVE-2026-4277An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.CRITICAL 9.8EPSS 0.46%7 April 2026
CVE-2026-30079This allows authentication to be bypassed completely.CRITICAL 9.8EPSS 0.53%7 April 2026
CVE-2026-24450An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2.CRITICAL 9.8EPSS 0.57%7 April 2026
CVE-2026-21413A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b.CRITICAL 9.8EPSS 0.93%7 April 2026
CVE-2026-20911A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b.CRITICAL 9.8EPSS 0.63%7 April 2026
CVE-2026-20889A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b.CRITICAL 9.8EPSS 0.80%7 April 2026
CVE-2026-20884An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2.CRITICAL 9.8EPSS 0.57%7 April 2026
CVE-2025-62818An out-of-bounds write occurs due to a mismatch between the TP-UDHI and UDL values when processing an SMS TP-UD packet.CRITICAL 9.8EPSS 0.46%7 April 2026
CVE-2025-52909Incorrect Handling of the NL80211 vendor command leads to a buffer overflow via a certain ioctl message, issue 2 of 2.CRITICAL 9.8EPSS 0.50%7 April 2026
CVE-2026-5735Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.26%7 April 2026
CVE-2026-5734Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.33%7 April 2026
CVE-2026-5731Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.34%7 April 2026
CVE-2026-23818A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL.CRITICAL 9.6EPSS 0.32%7 April 2026
CVE-2026-22679Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking…CRITICAL 9.3EPSS 20.4%7 April 2026
CVE-2025-39666Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context…CRITICAL 9.3EPSS 0.12%7 April 2026
CVE-2021-4473Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated attackers to execute arbitrary commands by supplying a crafted objClass parameter containing shell…CRITICAL 9.3EPSS 6.17%7 April 2026
CVE-2026-1114In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT).CRITICAL 9.8EPSS 0.54%7 April 2026
CVE-2025-65115Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management -…CRITICAL 9.8EPSS 0.61%7 April 2026
CVE-2026-0740The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26.EXPLOITCRITICAL 9.8EPSS 62.9%7 April 2026
CVE-2026-35471Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check.CRITICAL 9.8EPSS 0.68%6 April 2026
CVE-2026-35408Without this header, a malicious cross-origin window that opens the Directus login page retains the ability to access and manipulate the window object of that page.CRITICAL 9.3EPSS 0.17%6 April 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.