SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,298 results · page 139 of 786

CVESummaryPriorityPublished
CVE-2026-3059SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.CRITICAL 9.8EPSS 1.53%12 March 2026
CVE-2026-3916Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.35%11 March 2026
CVE-2026-32136Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c).CRITICAL 9.8EPSS 0.73%11 March 2026
CVE-2026-27591Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifying the roles / permissions assigned to their account through specially crafted requests to the…CRITICAL 9.9EPSS 0.49%11 March 2026
CVE-2026-32118Prior to 8.0.0.1, stored cross-site scripting (XSS) in the Graphical Pain Map ("clickmap") form allows any authenticated clinician to inject arbitrary JavaScript that executes in the browser of every subsequent user who views the affected encounter form.CRITICAL 9.0EPSS 0.28%11 March 2026
CVE-2025-70041An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.CRITICAL 9.8EPSS 0.45%11 March 2026
CVE-2025-70024An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benkeen generatedata 4.0.14.CRITICAL 9.8EPSS 0.52%11 March 2026
CVE-2025-66956Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachments via a computable URL.CRITICAL 9.9EPSS 0.48%11 March 2026
CVE-2026-31976On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml.CRITICAL 9.3EPSS 0.50%11 March 2026
CVE-2026-31957In this mode, Himmelblau can accept authentication attempts for arbitrary Entra ID domains by dynamically registering providers at runtime.CRITICAL 10.0EPSS 0.50%11 March 2026
CVE-2026-31896Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application.CRITICAL 9.8EPSS 0.35%11 March 2026
CVE-2026-27703This vulnerability allows an attacker to corrupt neighboring stack location, including security-sensitive addresses like the return address, leading to denial of service or arbitrary code execution.CRITICAL 9.8EPSS 0.48%11 March 2026
CVE-2026-27478In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens).CRITICAL 9.1EPSS 0.18%11 March 2026
CVE-2026-31881Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-reset request is active, resulting in full account takeover.CRITICAL 9.8EPSS 0.43%11 March 2026
CVE-2026-31877Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to.CRITICAL 9.3EPSS 0.29%11 March 2026
CVE-2026-31874Taskosaur is an open source project management platform with conversational AI for task execution in-app.CRITICAL 9.8EPSS 0.64%11 March 2026
CVE-2019-25487SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint.CRITICAL 9.3EPSS 7.90%11 March 2026
CVE-2019-25471FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint.CRITICAL 9.3EPSS 0.90%11 March 2026
CVE-2019-25468NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint.CRITICAL 9.3EPSS 0.76%11 March 2026
CVE-2018-25159Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions.CRITICAL 9.3EPSS 0.39%11 March 2026
CVE-2026-31871Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter).CRITICAL 9.3EPSS 0.42%11 March 2026
CVE-2026-31856A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter).CRITICAL 9.3EPSS 0.42%11 March 2026
CVE-2026-31852The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories.CRITICAL 9.8EPSS 0.45%11 March 2026
CVE-2026-31840Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject SQL into the PostgreSQL database through an improper escaping of sub-field values in dot-notation queries.CRITICAL 9.3EPSS 0.41%11 March 2026
CVE-2025-67039The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.CRITICAL 9.3EPSS 0.44%11 March 2026
CVE-2025-67038Lantronix EDS5000 Code Injection VulnerabilityKEVCRITICAL 9.3EPSS 19.3%11 March 2026
CVE-2026-30741A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack.CRITICAL 9.8EPSS 0.80%11 March 2026
CVE-2026-30903External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.CRITICAL 9.8EPSS 0.33%11 March 2026
CVE-2026-3826IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.CRITICAL 9.3EPSS 0.52%11 March 2026
CVE-2026-27842Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration.CRITICAL 9.3EPSS 0.56%11 March 2026
CVE-2026-2631The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification.CRITICAL 9.8EPSS 0.58%11 March 2026
CVE-2026-24448Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.CRITICAL 9.3EPSS 0.39%11 March 2026
CVE-2023-27573netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN).CRITICAL 9.8EPSS 0.49%11 March 2026
CVE-2026-29515MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials.CRITICAL 9.3EPSS 0.48%11 March 2026
CVE-2026-23813A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.CRITICAL 9.8EPSS 0.74%11 March 2026
CVE-2026-28806Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update API.CRITICAL 9.4EPSS 0.41%10 March 2026
CVE-2026-30966An attacker can create, read, update, or delete records in any internal relationship table.CRITICAL 10.0EPSS 0.38%10 March 2026
CVE-2026-30965Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other users by exploiting the redirectClassNameForKey query parameter.CRITICAL 9.9EPSS 1.33%10 March 2026
CVE-2026-0124There is a possible out of bounds write due to a missing bounds check.CRITICAL 10.0EPSS 0.14%10 March 2026
CVE-2026-0120This could lead to remote code execution with no additional execution privileges needed.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0116In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0114This could lead to remote code execution with no additional execution privileges needed.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0113This could lead to remote escalation of privilege with no additional execution privileges needed.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0111This could lead to remote escalation of privilege with no additional execution privileges needed.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0110In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-29793From 5.0.0 to before 5.0.42, Socket.IO clients can send arbitrary JavaScript objects as the id argument to any service method (get, patch, update, remove).CRITICAL 9.3EPSS 0.46%10 March 2026
CVE-2026-29792From 5.0.0 to before 5.0.42, an unauthenticated attacker can send a crafted GET request directly to /oauth/:provider/callback with a forged profile in the query string.CRITICAL 9.3EPSS 0.52%10 March 2026
CVE-2026-28292`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code…CRITICAL 9.8EPSS 1.30%10 March 2026
CVE-2026-3843Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module.CRITICAL 9.3EPSS 0.76%10 March 2026
CVE-2026-30960The vulnerability exists in the JIT (Just-In-Time) compilation engine, which is fully exposed via the CFFI (Foreign Function Interface).CRITICAL 9.4EPSS 0.21%10 March 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.