SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,298 results · page 137 of 786

CVESummaryPriorityPublished
CVE-2026-30924Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials: true, effectively allowing any external webpage to make authenticated requests on behalf of a logged-in user.CRITICAL 9.0EPSS 0.26%19 March 2026
CVE-2026-30836Step CA is an online certificate authority for secure, automated certificate management for DevOps.CRITICAL 10.0EPSS 0.30%19 March 2026
CVE-2026-27953Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validation by injecting "__pk_only__": true into a JSON request body.CRITICAL 9.8EPSS 1.19%19 March 2026
CVE-2026-26138Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 0.57%19 March 2026
CVE-2026-26137Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.CRITICAL 9.9EPSS 0.54%19 March 2026
CVE-2026-23658Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.78%19 March 2026
CVE-2026-32238Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers.CRITICAL 9.1EPSS 1.89%19 March 2026
CVE-2026-30694An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter componentCRITICAL 9.8EPSS 0.68%19 March 2026
CVE-2025-67114Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/root credentials from the device's…CRITICAL 9.8EPSS 0.52%19 March 2026
CVE-2025-67113OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint to execute arbitrary commands as root via a crafted…CRITICAL 9.8EPSS 1.22%19 March 2026
CVE-2025-67112Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authenticated users to decrypt, modify, and re-encrypt device…CRITICAL 9.8EPSS 0.40%19 March 2026
CVE-2026-32865An attacker who knows an existing user's email address can reset the user's password and security questions.CRITICAL 9.2EPSS 0.31%19 March 2026
CVE-2026-30402An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection functionCRITICAL 9.8EPSS 0.71%19 March 2026
CVE-2026-2369An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread.CRITICAL 9.1EPSS 0.42%19 March 2026
CVE-2026-22557A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.CRITICAL 10.0EPSS 28.1%19 March 2026
CVE-2006-10003XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.CRITICAL 9.8EPSS 0.55%19 March 2026
CVE-2026-27067Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server.This issue affects Mobile App Editor: from n/a through <= 1.3.1.CRITICAL 9.1EPSS 0.27%19 March 2026
CVE-2026-27065Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress builderpress allows PHP Local File Inclusion.This issue affects BuilderPress: from n/a through <= 2.0.1.CRITICAL 9.8EPSS 0.34%19 March 2026
CVE-2025-60237Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.CRITICAL 9.8EPSS 0.51%19 March 2026
CVE-2025-60233Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.CRITICAL 9.8EPSS 0.39%19 March 2026
CVE-2026-27542Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd.CRITICAL 9.8EPSS 1.74%19 March 2026
CVE-2026-27540Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd.CRITICAL 9.0EPSS 2.32%19 March 2026
CVE-2026-27413Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0.CRITICAL 9.3EPSS 0.38%19 March 2026
CVE-2026-32731Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.createWriteStream(path.join(exportPath, header.name))`. `path.join()` does not resolve or sanitise traversal segments…CRITICAL 9.9EPSS 0.43%18 March 2026
CVE-2025-15031A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries.CRITICAL 9.1EPSS 0.85%18 March 2026
CVE-2026-25873OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests.CRITICAL 9.3EPSS 1.08%18 March 2026
CVE-2026-32633Glances is an open-source system cross-platform monitoring tool.CRITICAL 9.1EPSS 0.47%18 March 2026
CVE-2026-32611The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL operations to use parameterized queries and `psycopg.sql` composable objects.CRITICAL 9.1EPSS 0.33%18 March 2026
CVE-2026-30704The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCBCRITICAL 9.1EPSS 0.31%18 March 2026
CVE-2026-30703A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02).CRITICAL 9.8EPSS 1.05%18 March 2026
CVE-2026-30702The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced browsingCRITICAL 9.8EPSS 0.37%18 March 2026
CVE-2026-30701The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side web pages, including login.shtml and settings.shtml.CRITICAL 9.1EPSS 0.38%18 March 2026
CVE-2026-29859An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.CRITICAL 9.8EPSS 0.51%18 March 2026
CVE-2025-67830Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.CRITICAL 9.8EPSS 0.32%18 March 2026
CVE-2025-67829Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.CRITICAL 9.8EPSS 0.26%18 March 2026
CVE-2026-25449Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1.CRITICAL 9.8EPSS 0.32%18 March 2026
CVE-2026-33265In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.CRITICAL 9.0EPSS 0.23%18 March 2026
CVE-2026-30884The `core_get_fragment` callback `editelement` and the `mod_customcert_save_element` web service both fail to verify that the supplied `elementid` belongs to the authorized context, enabling cross-course information disclosure and data tampering.CRITICAL 9.6EPSS 0.17%18 March 2026
CVE-2026-28500In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mechanism.CRITICAL 9.1EPSS 0.32%18 March 2026
CVE-2026-3856IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.CRITICAL 9.1EPSS 0.15%17 March 2026
CVE-2026-21994Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop).CRITICAL 9.8EPSS 0.45%17 March 2026
CVE-2026-32841Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface.CRITICAL 9.2EPSS 0.60%17 March 2026
CVE-2026-32297The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries.CRITICAL 9.3EPSS 0.53%17 March 2026
CVE-2026-32295JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.CRITICAL 9.3EPSS 0.49%17 March 2026
CVE-2026-32292The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.CRITICAL 9.3EPSS 0.53%17 March 2026
CVE-2026-25769Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data).CRITICAL 9.1EPSS 8.79%17 March 2026
CVE-2026-25534This led to a bypass of the previous CVE (CVE-2025-61916) through the use of carefully crafted URLs.CRITICAL 9.1EPSS 0.25%17 March 2026
CVE-2026-3564A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios.CRITICAL 9.0EPSS 0.36%17 March 2026
CVE-2026-4312GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account.CRITICAL 9.3EPSS 0.45%17 March 2026
CVE-2026-4177YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter.CRITICAL 9.1EPSS 0.43%16 March 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.