SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,291 results · page 132 of 786

CVESummaryPriorityPublished
CVE-2026-3300The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12.CRITICAL 9.8EPSS 39.2%31 March 2026
CVE-2026-30880Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer.CRITICAL 9.2EPSS 2.03%31 March 2026
CVE-2026-4257The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36.EXPLOITCRITICAL 9.8EPSS 41.5%30 March 2026
CVE-2026-4789Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.CRITICAL 9.8EPSS 0.70%30 March 2026
CVE-2026-34558Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding.CRITICAL 9.0EPSS 0.31%30 March 2026
CVE-2026-34557Multiple input fields (three distinct group-related fields) can be injected with malicious JavaScript payloads, which are then stored server-side.CRITICAL 9.0EPSS 0.31%30 March 2026
CVE-2026-31946OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication.CRITICAL 9.8EPSS 0.21%30 March 2026
CVE-2026-30313DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective.CRITICAL 9.8EPSS 1.15%30 March 2026
CVE-2026-30308In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all commands.CRITICAL 9.8EPSS 0.51%30 March 2026
CVE-2026-30306In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands.CRITICAL 9.8EPSS 0.68%30 March 2026
CVE-2026-33026Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration.CRITICAL 9.4EPSS 0.33%30 March 2026
CVE-2026-30307Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective.CRITICAL 9.8EPSS 1.15%30 March 2026
CVE-2026-30305Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective.CRITICAL 9.8EPSS 1.15%30 March 2026
CVE-2026-33032In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message.CRITICAL 9.8EPSS 36.3%30 March 2026
CVE-2026-33030In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify, and delete resources belonging to other users.CRITICAL 9.9EPSS 0.28%30 March 2026
CVE-2026-30562A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0.CRITICAL 9.3EPSS 0.32%30 March 2026
CVE-2026-2287CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.CRITICAL 9.8EPSS 0.73%30 March 2026
CVE-2026-2286CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.CRITICAL 9.8EPSS 0.47%30 March 2026
CVE-2026-2275The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.CRITICAL 9.6EPSS 0.44%30 March 2026
CVE-2026-4415Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability.CRITICAL 9.2EPSS 0.99%30 March 2026
CVE-2025-15379A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function.CRITICAL 10.0EPSS 2.39%30 March 2026
CVE-2025-15036A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository.CRITICAL 10.0EPSS 0.58%30 March 2026
CVE-2026-4176Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.CRITICAL 9.8EPSS 0.73%29 March 2026
CVE-2026-0558A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint.CRITICAL 9.8EPSS 1.94%29 March 2026
CVE-2026-32987OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts.CRITICAL 9.3EPSS 0.35%29 March 2026
CVE-2026-32978OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain script runners like tsx and jiti.CRITICAL 9.4EPSS 0.18%29 March 2026
CVE-2026-32922OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scope…CRITICAL 9.4EPSS 0.72%29 March 2026
CVE-2026-32918OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state.CRITICAL 9.2EPSS 0.10%29 March 2026
CVE-2026-32915OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead of their own session tree.CRITICAL 9.3EPSS 0.14%29 March 2026
CVE-2026-4851GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization.CRITICAL 9.8EPSS 0.47%29 March 2026
CVE-2026-3256HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids.CRITICAL 9.8EPSS 0.53%28 March 2026
CVE-2025-15604Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions.CRITICAL 9.8EPSS 0.52%28 March 2026
CVE-2018-25223Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application.CRITICAL 9.3EPSS 0.88%28 March 2026
CVE-2018-25221EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter.CRITICAL 9.3EPSS 0.82%28 March 2026
CVE-2018-25220Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the application.CRITICAL 9.3EPSS 0.64%28 March 2026
CVE-2017-20229MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input.CRITICAL 9.3EPSS 0.60%28 March 2026
CVE-2017-20227JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries.CRITICAL 9.3EPSS 0.67%28 March 2026
CVE-2017-20225TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input.CRITICAL 9.3EPSS 0.80%28 March 2026
CVE-2016-20049JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries.CRITICAL 9.3EPSS 0.67%28 March 2026
CVE-2026-33992Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs without validation, enabling Server-Side Request Forgery (SSRF) attacks.CRITICAL 9.3EPSS 0.40%27 March 2026
CVE-2026-33976Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app.CRITICAL 9.6EPSS 0.71%27 March 2026
CVE-2026-33943In versions 15.10.0 through 20.8.7, a code injection vulnerability in `ECMAScriptModuleCompiler` allows an attacker to achieve Remote Code Execution (RCE) by injecting arbitrary JavaScript expressions inside `export { }` declarations in ES module…CRITICAL 9.8EPSS 0.79%27 March 2026
CVE-2019-25651Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller…CRITICAL 9.0EPSS 0.08%27 March 2026
CVE-2026-33937An attacker who can supply a crafted AST to `compile()` can therefore inject and execute arbitrary JavaScript, leading to Remote Code Execution on the server.CRITICAL 9.8EPSS 1.70%27 March 2026
CVE-2026-33896This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid.CRITICAL 9.1EPSS 0.35%27 March 2026
CVE-2026-33875Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link.CRITICAL 9.3EPSS 0.27%27 March 2026
CVE-2026-33873Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generated Python code during its validation phase.CRITICAL 9.3EPSS 1.43%27 March 2026
CVE-2026-34475Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.CRITICAL 9.8EPSS 0.20%27 March 2026
CVE-2026-34205Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network.CRITICAL 9.6EPSS 0.26%27 March 2026
CVE-2026-34374This vulnerability is distinct from GHSA-pvw4-p2jm-chjm, which covers SQL injection via the `live_schedule_id` parameter in the reminder function.CRITICAL 9.1EPSS 0.34%27 March 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.