SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,298 results · page 134 of 786

CVESummaryPriorityPublished
CVE-2026-32523Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2.CRITICAL 9.9EPSS 0.32%25 March 2026
CVE-2026-32520Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4.CRITICAL 9.8EPSS 0.32%25 March 2026
CVE-2026-32519Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2.CRITICAL 9.0EPSS 0.34%25 March 2026
CVE-2026-32512Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-32502Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-32499Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9.CRITICAL 9.3EPSS 0.28%25 March 2026
CVE-2026-32482Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: from n/a through < 1.24.CRITICAL 9.9EPSS 0.32%25 March 2026
CVE-2026-31920Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This issue affects Product Rearrange…CRITICAL 9.3EPSS 0.28%25 March 2026
CVE-2026-27095Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through <=…CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-27084Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11.CRITICAL 9.8EPSS 0.48%25 March 2026
CVE-2026-27083Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-27082Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-27071Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through <= 3.0.7.CRITICAL 9.1EPSS 0.30%25 March 2026
CVE-2026-27051Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.CRITICAL 9.8EPSS 0.32%25 March 2026
CVE-2026-27049Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue affects Jobica Core: from n/a through <= 1.4.2.CRITICAL 9.8EPSS 0.53%25 March 2026
CVE-2026-27044Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.This issue affects Total Poll Lite: from n/a through <= 4.12.0.CRITICAL 9.9EPSS 0.30%25 March 2026
CVE-2026-25447Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affects Widget Wrangler: from n/a through <= 2.3.9.CRITICAL 9.1EPSS 0.31%25 March 2026
CVE-2026-25429Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-25413Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18.CRITICAL 9.9EPSS 0.33%25 March 2026
CVE-2026-25377Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0.CRITICAL 9.3EPSS 0.28%25 March 2026
CVE-2026-25371Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Product Designer: from n/a through < 2.0.9.CRITICAL 9.3EPSS 0.28%25 March 2026
CVE-2026-25366Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1.CRITICAL 9.9EPSS 0.31%25 March 2026
CVE-2026-25345Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SimpLy Gallery: from n/a through <= 3.3.2.CRITICAL 9.9EPSS 0.45%25 March 2026
CVE-2026-25340Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind SQL Injection.This issue affects Jobmonster: from n/a through < 4.8.4.CRITICAL 9.3EPSS 0.28%25 March 2026
CVE-2026-25035Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2.CRITICAL 9.8EPSS 0.42%25 March 2026
CVE-2026-25032Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-25031Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-25030Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-25029Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-24993Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects…CRITICAL 9.3EPSS 0.28%25 March 2026
CVE-2026-24989Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.CRITICAL 9.8EPSS 0.38%25 March 2026
CVE-2026-24971Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.CRITICAL 9.8EPSS 0.32%25 March 2026
CVE-2026-24968Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.CRITICAL 9.8EPSS 0.41%25 March 2026
CVE-2026-24378Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.CRITICAL 9.8EPSS 0.51%25 March 2026
CVE-2026-22507Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6.CRITICAL 9.8EPSS 0.51%25 March 2026
CVE-2026-22500Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <= 1.1.2.CRITICAL 9.8EPSS 0.51%25 March 2026
CVE-2026-22484Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL Injection.This issue affects Lisfinity Core: from n/a through <= 1.5.0.CRITICAL 9.3EPSS 0.38%25 March 2026
CVE-2026-26833thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or…CRITICAL 9.8EPSS 2.31%25 March 2026
CVE-2026-26832In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection.CRITICAL 9.8EPSS 1.71%25 March 2026
CVE-2026-26831textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors.CRITICAL 9.8EPSS 2.42%25 March 2026
CVE-2026-26830pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter.CRITICAL 9.8EPSS 2.49%25 March 2026
CVE-2025-59707In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.CRITICAL 9.8EPSS 0.53%25 March 2026
CVE-2025-59706In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.CRITICAL 9.8EPSS 0.53%25 March 2026
CVE-2025-32991In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.CRITICAL 9.0EPSS 0.34%25 March 2026
CVE-2026-28858A buffer overflow was addressed with improved bounds checking.CRITICAL 9.8EPSS 0.53%25 March 2026
CVE-2026-28827A parsing issue in the handling of directory paths was addressed with improved path validation.CRITICAL 9.3EPSS 0.28%25 March 2026
CVE-2026-20688A path handling issue was addressed with improved validation.CRITICAL 9.3EPSS 0.27%25 March 2026
CVE-2026-24159NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution.CRITICAL 9.8EPSS 0.64%24 March 2026
CVE-2026-24157NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution.CRITICAL 9.8EPSS 0.65%24 March 2026
CVE-2025-33244NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data.CRITICAL 9.0EPSS 0.58%24 March 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.