SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,291 results · page 135 of 786

CVESummaryPriorityPublished
CVE-2026-4724This vulnerability was fixed in Firefox 149 and Thunderbird 149.CRITICAL 9.1EPSS 0.32%24 March 2026
CVE-2026-4723Use-after-free in the JavaScript Engine component.CRITICAL 9.8EPSS 0.39%24 March 2026
CVE-2026-4721Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.42%24 March 2026
CVE-2026-4720Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.42%24 March 2026
CVE-2026-4717Privilege escalation in the Netmonitor component.CRITICAL 9.8EPSS 0.42%24 March 2026
CVE-2026-4716This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.CRITICAL 9.1EPSS 0.41%24 March 2026
CVE-2026-4715This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.CRITICAL 9.1EPSS 0.43%24 March 2026
CVE-2026-4711Use-after-free in the Widget: Cocoa component.CRITICAL 9.8EPSS 0.40%24 March 2026
CVE-2026-4710This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.CRITICAL 9.8EPSS 0.41%24 March 2026
CVE-2026-4705This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.CRITICAL 9.8EPSS 0.42%24 March 2026
CVE-2026-4702This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.CRITICAL 9.8EPSS 0.47%24 March 2026
CVE-2026-4701Use-after-free in the JavaScript Engine component.CRITICAL 9.8EPSS 0.46%24 March 2026
CVE-2026-4700Mitigation bypass in the Networking: HTTP component.CRITICAL 9.8EPSS 0.46%24 March 2026
CVE-2026-4698This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.CRITICAL 9.8EPSS 0.76%24 March 2026
CVE-2026-4696Use-after-free in the Layout: Text and Fonts component.CRITICAL 9.8EPSS 0.48%24 March 2026
CVE-2026-4692This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.CRITICAL 10.0EPSS 0.49%24 March 2026
CVE-2026-4691Use-after-free in the CSS Parsing and Computation component.CRITICAL 9.8EPSS 0.48%24 March 2026
CVE-2026-4689Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component.CRITICAL 10.0EPSS 0.66%24 March 2026
CVE-2026-4688Sandbox escape due to use-after-free in the Disability Access APIs component.CRITICAL 10.0EPSS 0.53%24 March 2026
CVE-2026-33475An unauthenticated remote shell injection vulnerability exists in multiple GitHub Actions workflows in the Langflow repository prior to version 1.9.0.CRITICAL 9.1EPSS 2.96%24 March 2026
CVE-2026-33309Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `LocalStorageService` remaining unresolved.CRITICAL 9.9EPSS 11.1%24 March 2026
CVE-2019-25646Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter.CRITICAL 9.3EPSS 0.91%24 March 2026
CVE-2019-25628Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs.CRITICAL 9.3EPSS 0.80%24 March 2026
CVE-2026-4755CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.CRITICAL 9.8EPSS 0.28%24 March 2026
CVE-2026-4753Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.CRITICAL 9.1EPSS 0.42%24 March 2026
CVE-2026-4750Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.CRITICAL 9.1EPSS 0.40%24 March 2026
CVE-2026-33854Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.CRITICAL 9.8EPSS 0.24%24 March 2026
CVE-2026-4746Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules).CRITICAL 10.0EPSS 0.28%24 March 2026
CVE-2026-4745Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules).CRITICAL 10.0EPSS 0.29%24 March 2026
CVE-2026-4283The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38.CRITICAL 9.1EPSS 0.43%24 March 2026
CVE-2026-4744Out-of-bounds Read vulnerability in rizonesoft Notepad3 (‎scintilla/oniguruma/src modules).CRITICAL 9.3EPSS 0.13%24 March 2026
CVE-2026-4739Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (‎Modules/ThirdParty/Expat/src/expat modules).This issue affects ITK: before 2.7.1.CRITICAL 9.4EPSS 0.28%24 March 2026
CVE-2026-4738Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules).CRITICAL 9.4EPSS 0.28%24 March 2026
CVE-2026-4734Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt/openmpt-trunk/include/premake/contrib/curl/lib modules).CRITICAL 9.4EPSS 0.28%24 March 2026
CVE-2026-4001The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within…CRITICAL 9.8EPSS 0.71%24 March 2026
CVE-2026-33286Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface.CRITICAL 9.1EPSS 0.63%24 March 2026
CVE-2026-33211Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter.CRITICAL 9.6EPSS 0.57%24 March 2026
CVE-2026-4681A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM.CRITICAL 9.3EPSS 0.76%23 March 2026
CVE-2026-33634Aquasecurity Trivy Embedded Malicious Code VulnerabilityKEVCRITICAL 9.4EPSS 59.2%23 March 2026
CVE-2025-60949Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments.CRITICAL 9.3EPSS 0.40%23 March 2026
CVE-2026-3055Citrix NetScaler Out-of-Bounds Read VulnerabilityKEVCRITICAL 9.3EPSS 87.2%23 March 2026
CVE-2026-30849Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter.CRITICAL 9.3EPSS 1.46%23 March 2026
CVE-2026-2298Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation.CRITICAL 9.4EPSS 0.41%23 March 2026
CVE-2026-33716An attacker can redirect token verification to a server they control that always returns `{"error": false}`, completely bypassing authentication.CRITICAL 9.4EPSS 0.44%23 March 2026
CVE-2026-0898An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25.CRITICAL 9.0EPSS 0.32%23 March 2026
CVE-2026-4404Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.CRITICAL 9.4EPSS 0.49%23 March 2026
CVE-2026-33478In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution.CRITICAL 10.0EPSS 13.3%23 March 2026
CVE-2026-33352Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method.CRITICAL 9.8EPSS 0.43%23 March 2026
CVE-2026-33351Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`.CRITICAL 9.1EPSS 0.43%23 March 2026
CVE-2025-41008SQL injection vulnerability in Sinturno.CRITICAL 9.3EPSS 0.25%23 March 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.