SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,298 results · page 136 of 786

CVESummaryPriorityPublished
CVE-2026-33716An attacker can redirect token verification to a server they control that always returns `{"error": false}`, completely bypassing authentication.CRITICAL 9.4EPSS 0.44%23 March 2026
CVE-2026-0898An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25.CRITICAL 9.0EPSS 0.32%23 March 2026
CVE-2026-4404Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.CRITICAL 9.4EPSS 0.49%23 March 2026
CVE-2026-33478In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution.CRITICAL 10.0EPSS 13.3%23 March 2026
CVE-2026-33352Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method.CRITICAL 9.8EPSS 0.43%23 March 2026
CVE-2026-33351Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`.CRITICAL 9.1EPSS 0.43%23 March 2026
CVE-2025-41008SQL injection vulnerability in Sinturno.CRITICAL 9.3EPSS 0.25%23 March 2026
CVE-2025-41007SQL Injection in Cuantis.CRITICAL 9.3EPSS 0.31%23 March 2026
CVE-2026-32968Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise.CRITICAL 9.8EPSS 0.55%23 March 2026
CVE-2026-3587An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.CRITICAL 10.0EPSS 0.68%23 March 2026
CVE-2026-4599Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the…CRITICAL 9.3EPSS 0.48%23 March 2026
CVE-2026-4606GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system.CRITICAL 10.0EPSS 0.30%23 March 2026
CVE-2019-25614Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload.CRITICAL 9.3EPSS 0.95%22 March 2026
CVE-2019-25568Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable.CRITICAL 9.3EPSS 0.32%21 March 2026
CVE-2026-24060Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker.CRITICAL 9.1EPSS 0.20%21 March 2026
CVE-2026-33186Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header.CRITICAL 9.1EPSS 1.56%20 March 2026
CVE-2026-29796WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.47%20 March 2026
CVE-2026-25192WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.48%20 March 2026
CVE-2026-21732A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library.CRITICAL 9.6EPSS 0.29%20 March 2026
CVE-2026-3584The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function.CRITICAL 9.8EPSS 7.24%20 March 2026
CVE-2026-32710An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function.CRITICAL 9.9EPSS 0.86%20 March 2026
CVE-2026-22898A missing authentication for critical function vulnerability has been reported to affect QVR Pro.CRITICAL 9.3EPSS 0.68%20 March 2026
CVE-2026-22172OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding.CRITICAL 9.4EPSS 0.56%20 March 2026
CVE-2024-44722SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.CRITICAL 9.8EPSS 0.51%20 March 2026
CVE-2026-33131Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) which allows middleware bypass.CRITICAL 9.1EPSS 0.39%20 March 2026
CVE-2026-33128In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() and formatEventStreamComment().CRITICAL 10.0EPSS 0.57%20 March 2026
CVE-2026-33075In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor.CRITICAL 9.4EPSS 0.30%20 March 2026
CVE-2026-33057Mesop is a Python-based UI framework that allows users to build web applications.CRITICAL 9.8EPSS 5.29%20 March 2026
CVE-2026-33054Mesop is a Python-based UI framework that allows users to build web applications.CRITICAL 9.8EPSS 0.71%20 March 2026
CVE-2026-33024Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpoints getImage.php and getImageMP4.php.CRITICAL 9.3EPSS 0.44%20 March 2026
CVE-2026-33017Langflow Code Injection VulnerabilityKEVEXPLOITCRITICAL 9.3EPSS 96.2%20 March 2026
CVE-2026-4038The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5.CRITICAL 9.8EPSS 0.30%20 March 2026
CVE-2026-32891Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector.CRITICAL 9.0EPSS 0.16%20 March 2026
CVE-2026-32890In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web dashboard's User Mapping dropdown allows any unprivileged Discord user in the configured guild to execute arbitrary JavaScript in the Anchorr admin's browser.CRITICAL 9.6EPSS 0.43%20 March 2026
CVE-2026-21992Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).CRITICAL 9.8EPSS 1.01%20 March 2026
CVE-2026-32817The folder_delete and file_delete action handlers in modules/documents-files.php only perform a VIEW authorization check (getFolderForDownload / getFileForDownload) before calling delete(), and they never validate a CSRF token.CRITICAL 9.1EPSS 0.32%20 March 2026
CVE-2026-32767Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextSearchBlock endpoint.CRITICAL 9.8EPSS 0.54%20 March 2026
CVE-2026-33289Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow.CRITICAL 9.8EPSS 0.66%20 March 2026
CVE-2026-32985Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a crafted ZIP archive containing…CRITICAL 9.3EPSS 1.48%20 March 2026
CVE-2026-32760File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory.CRITICAL 10.0EPSS 0.67%20 March 2026
CVE-2026-22732When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.CRITICAL 9.1EPSS 0.48%19 March 2026
CVE-2026-32754Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates.CRITICAL 9.3EPSS 0.53%19 March 2026
CVE-2026-32194Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.18%19 March 2026
CVE-2026-32038OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network namespace.CRITICAL 9.3EPSS 0.27%19 March 2026
CVE-2026-30872In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS domains (.ip6.arpa) received via multicast DNS on…CRITICAL 9.5EPSS 2.22%19 March 2026
CVE-2026-30871In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function.CRITICAL 9.5EPSS 1.21%19 March 2026
CVE-2026-4428A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks.CRITICAL 9.1EPSS 0.25%19 March 2026
CVE-2026-32749In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, allowing an admin to write files to arbitrary locations outside the…CRITICAL 9.1EPSS 0.43%19 March 2026
CVE-2026-32191Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.79%19 March 2026
CVE-2026-32169Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.55%19 March 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.