SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,288 results · page 129 of 786

CVESummaryPriorityPublished
CVE-2026-35393This vulnerability is fixed in 2.0.0-beta.3.CRITICAL 9.8EPSS 0.68%6 April 2026
CVE-2026-35392This vulnerability is fixed in 2.0.0-beta.3.CRITICAL 9.8EPSS 0.68%6 April 2026
CVE-2026-35459In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability.CRITICAL 9.3EPSS 0.28%6 April 2026
CVE-2026-35197Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code.CRITICAL 9.8EPSS 0.29%6 April 2026
CVE-2026-35178Prior to 65.0.0, Workbench contains remote code execution vulnerability in the timezone conversion flow, which processes attacker-controlled cookie values in an unsafe manner.CRITICAL 9.3EPSS 0.49%6 April 2026
CVE-2025-54328A Stack-based Buffer Overflow occurs while parsing SMS RP-DATA messages.CRITICAL 10.0EPSS 0.52%6 April 2026
CVE-2025-58349Incorrect handling of LTE MAC packets containing many MAC Control Elements (CEs) leads to baseband crashes.CRITICAL 9.1EPSS 0.31%6 April 2026
CVE-2026-35171Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without validation.CRITICAL 9.8EPSS 0.71%6 April 2026
CVE-2026-35047Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts.CRITICAL 9.3EPSS 0.55%6 April 2026
CVE-2026-35044When a victim imports a malicious bento archive and runs bentoml containerize, attacker-controlled Jinja2 template code executes arbitrary Python directly on the host machine, bypassing all container isolation.CRITICAL 9.6EPSS 0.39%6 April 2026
CVE-2026-35039fast-jwt provides fast JSON Web Token (JWT) implementation.CRITICAL 9.1EPSS 0.21%6 April 2026
CVE-2026-35035Several administrative configuration fields accept attacker-controlled input that is stored server-side and later rendered without proper output encoding.CRITICAL 9.0EPSS 0.46%6 April 2026
CVE-2026-35030An unauthenticated attacker can craft a token whose first 20 characters match a legitimate user's cached token.CRITICAL 9.4EPSS 0.63%6 April 2026
CVE-2026-34989An attacker can inject a malicious JavaScript payload into their profile name, which is then stored server-side.CRITICAL 9.4EPSS 0.30%6 April 2026
CVE-2026-34977An unauthenticated attacker can achieve root-level RCE inside the worker container with a single HTTP request, enabling full read/write access to all user-uploaded images, analysis results, and plaintext steganography passwords stored on disk.CRITICAL 9.3EPSS 0.78%6 April 2026
CVE-2026-34976Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated.CRITICAL 10.0EPSS 2.04%6 April 2026
CVE-2026-34841Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT).CRITICAL 9.8EPSS 0.23%6 April 2026
CVE-2026-34950fast-jwt provides fast JSON Web Token (JWT) implementation.CRITICAL 9.1EPSS 0.24%6 April 2026
CVE-2026-34208Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypassed through an exposed callable constructor path: this.constructor.call(target, attackerObject).CRITICAL 10.0EPSS 0.56%6 April 2026
CVE-2026-31151An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the application 's resources.CRITICAL 9.8EPSS 0.38%6 April 2026
CVE-2026-31059A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.CRITICAL 9.8EPSS 0.90%6 April 2026
CVE-2026-26263From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine.CRITICAL 9.8EPSS 8.26%6 April 2026
CVE-2026-31405In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables in handle_one_ule_extension() are declared with 255…CRITICAL 9.8EPSS 0.55%6 April 2026
CVE-2019-25687Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality.CRITICAL 9.3EPSS 1.42%5 April 2026
CVE-2018-25254NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands.CRITICAL 9.3EPSS 0.91%4 April 2026
CVE-2016-20052Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory.CRITICAL 9.3EPSS 0.95%4 April 2026
CVE-2026-35616Fortinet FortiClient EMS Improper Access Control VulnerabilityKEVCRITICAL 9.8EPSS 90.7%4 April 2026
CVE-2026-34955The blocklist does not include sh or bash as standalone executables, allowing trivial sandbox escape in STRICT mode via sh -c '<command>'.CRITICAL 10.0EPSS 0.38%4 April 2026
CVE-2026-34775Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS.CRITICAL 9.8EPSS 0.29%4 April 2026
CVE-2026-34953Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access to all registered tools and agent capabilities.CRITICAL 9.1EPSS 0.38%3 April 2026
CVE-2026-34952Any network client can connect, enumerate registered agents, and send arbitrary messages to agents and their tool sets.CRITICAL 9.1EPSS 0.44%3 April 2026
CVE-2026-34938Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving…CRITICAL 10.0EPSS 13.2%3 April 2026
CVE-2026-34937The escaping logic only handles \ and ", leaving $() and backtick substitutions unescaped, allowing arbitrary OS command execution before Python is invoked.CRITICAL 9.8EPSS 0.55%3 April 2026
CVE-2026-34935From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and forwarded through the call chain to anyio.open_process() with no validation, allowlist check, or sanitization at any hop, allowing arbitrary OS…CRITICAL 9.8EPSS 0.82%3 April 2026
CVE-2026-34934An attacker stores a malicious thread ID via update_thread.CRITICAL 9.8EPSS 0.53%3 April 2026
CVE-2026-34612Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the following endpoint "GET /api/v1/main/flows/search".CRITICAL 9.0EPSS 0.66%3 April 2026
CVE-2021-4477Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall rules.CRITICAL 9.3EPSS 0.32%3 April 2026
CVE-2018-25236Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by…CRITICAL 9.3EPSS 0.50%3 April 2026
CVE-2017-20236ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input through…CRITICAL 9.3EPSS 0.68%3 April 2026
CVE-2017-20235ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials.CRITICAL 9.3EPSS 0.45%3 April 2026
CVE-2017-20234GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism.CRITICAL 9.3EPSS 0.46%3 April 2026
CVE-2018-25237Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a…CRITICAL 9.3EPSS 0.82%3 April 2026
CVE-2026-35561Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the…CRITICAL 9.1EPSS 0.47%3 April 2026
CVE-2026-35560Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport…CRITICAL 9.1EPSS 0.26%3 April 2026
CVE-2026-28766A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.CRITICAL 9.2EPSS 0.44%3 April 2026
CVE-2026-25197A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.CRITICAL 9.3EPSS 0.29%3 April 2026
CVE-2017-20237Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges.CRITICAL 9.3EPSS 0.96%3 April 2026
CVE-2026-28798Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an externally reachable domain using a Cloudflare Tunnel) to make requests to internal localhost services.CRITICAL 10.0EPSS 0.39%3 April 2026
CVE-2026-25726Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secret_key, and hash_id_salt.CRITICAL 9.8EPSS 0.38%3 April 2026
CVE-2026-32186Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.70%3 April 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.