SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,321 results · page 140 of 787

CVESummaryPriorityPublished
CVE-2026-30903External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.CRITICAL 9.8EPSS 0.33%11 March 2026
CVE-2026-3826IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.CRITICAL 9.3EPSS 0.52%11 March 2026
CVE-2026-27842Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration.CRITICAL 9.3EPSS 0.56%11 March 2026
CVE-2026-2631The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification.CRITICAL 9.8EPSS 0.58%11 March 2026
CVE-2026-24448Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.CRITICAL 9.3EPSS 0.39%11 March 2026
CVE-2023-27573netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN).CRITICAL 9.8EPSS 0.49%11 March 2026
CVE-2026-29515MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials.CRITICAL 9.3EPSS 0.48%11 March 2026
CVE-2026-23813A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.CRITICAL 9.8EPSS 0.74%11 March 2026
CVE-2026-28806Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update API.CRITICAL 9.4EPSS 0.41%10 March 2026
CVE-2026-30966An attacker can create, read, update, or delete records in any internal relationship table.CRITICAL 10.0EPSS 0.38%10 March 2026
CVE-2026-30965Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other users by exploiting the redirectClassNameForKey query parameter.CRITICAL 9.9EPSS 1.33%10 March 2026
CVE-2026-0124There is a possible out of bounds write due to a missing bounds check.CRITICAL 10.0EPSS 0.14%10 March 2026
CVE-2026-0120This could lead to remote code execution with no additional execution privileges needed.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0116In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0114This could lead to remote code execution with no additional execution privileges needed.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0113This could lead to remote escalation of privilege with no additional execution privileges needed.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0111This could lead to remote escalation of privilege with no additional execution privileges needed.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-0110In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption.CRITICAL 9.8EPSS 0.31%10 March 2026
CVE-2026-29793From 5.0.0 to before 5.0.42, Socket.IO clients can send arbitrary JavaScript objects as the id argument to any service method (get, patch, update, remove).CRITICAL 9.3EPSS 0.46%10 March 2026
CVE-2026-29792From 5.0.0 to before 5.0.42, an unauthenticated attacker can send a crafted GET request directly to /oauth/:provider/callback with a forged profile in the query string.CRITICAL 9.3EPSS 0.52%10 March 2026
CVE-2026-28292`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code…CRITICAL 9.8EPSS 1.30%10 March 2026
CVE-2026-3843Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module.CRITICAL 9.3EPSS 0.76%10 March 2026
CVE-2026-30960The vulnerability exists in the JIT (Just-In-Time) compilation engine, which is fully exposed via the CFFI (Foreign Function Interface).CRITICAL 9.4EPSS 0.21%10 March 2026
CVE-2026-30957Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container.CRITICAL 9.9EPSS 1.15%10 March 2026
CVE-2026-30956Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged is-multi-tenant-query header together with a controlled projectid header.CRITICAL 9.9EPSS 0.49%10 March 2026
CVE-2026-26105Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.CRITICAL 9.3EPSS 1.16%10 March 2026
CVE-2026-23240In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit.CRITICAL 9.8EPSS 0.49%10 March 2026
CVE-2025-69615Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required.CRITICAL 9.1EPSS 0.45%10 March 2026
CVE-2025-69614Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover.CRITICAL 9.4EPSS 0.39%10 March 2026
CVE-2025-56422A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.CRITICAL 9.8EPSS 0.85%10 March 2026
CVE-2025-41709An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.CRITICAL 9.8EPSS 2.15%10 March 2026
CVE-2025-40943This could allow an attacker to inject code through social engineering an authorized user, who has the function right "Read diagnostics", to import a specially crafted trace file.CRITICAL 9.4EPSS 0.46%10 March 2026
CVE-2026-30921Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the oneuptime-probe service.CRITICAL 9.9EPSS 0.45%10 March 2026
CVE-2026-30887Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites.CRITICAL 9.9EPSS 0.39%10 March 2026
CVE-2026-30869Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem.CRITICAL 9.8EPSS 1.03%10 March 2026
CVE-2026-30862Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2).CRITICAL 9.0EPSS 0.31%10 March 2026
CVE-2026-27685SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.CRITICAL 9.1EPSS 0.55%10 March 2026
CVE-2026-0953The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon.CRITICAL 9.8EPSS 0.66%10 March 2026
CVE-2025-11158Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.CRITICAL 9.1EPSS 0.38%10 March 2026
CVE-2026-28431All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that allows bad actors access to data that they ordinarily wouldn't be able to access due to insufficient permission checks and proper input validation.CRITICAL 9.2EPSS 0.25%10 March 2026
CVE-2026-31816In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request.CRITICAL 9.1EPSS 15.3%9 March 2026
CVE-2026-25960The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing behavior between the validation layer and the actual HTTP client.CRITICAL 9.8EPSS 0.54%9 March 2026
CVE-2026-25737In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even though file extension restrictions are configured.CRITICAL 9.0EPSS 0.26%9 March 2026
CVE-2025-70039An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.CRITICAL 9.8EPSS 0.38%9 March 2026
CVE-2025-70046An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master.CRITICAL 9.8EPSS 0.36%9 March 2026
CVE-2025-70042An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.CRITICAL 9.8EPSS 0.33%9 March 2026
CVE-2026-24713Improper Input Validation vulnerability in Apache IoTDB.CRITICAL 9.8EPSS 0.66%9 March 2026
CVE-2026-24015A vulnerability in Apache IoTDB.CRITICAL 9.8EPSS 0.58%9 March 2026
CVE-2025-41765Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data.CRITICAL 9.1EPSS 0.27%9 March 2026
CVE-2025-41764Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates.CRITICAL 9.1EPSS 0.41%9 March 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.