SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,163 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,321 results · page 141 of 787

CVESummaryPriorityPublished
CVE-2026-3823EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.CRITICAL 9.3EPSS 0.73%9 March 2026
CVE-2026-3630Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.CRITICAL 9.8EPSS 0.96%9 March 2026
CVE-2026-30909Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encrypt_afternm and seal functions do not check that output size will be less than SIZE_MAX, which could lead to integer wraparound causing…CRITICAL 9.8EPSS 0.53%8 March 2026
CVE-2026-30863This allows an attacker to use a validly signed JWT issued for a different application to authenticate as any user on the target Parse Server.CRITICAL 9.3EPSS 0.53%7 March 2026
CVE-2026-30860Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality.CRITICAL 9.8EPSS 0.54%7 March 2026
CVE-2026-30832The initial batch request is blind (the response from a metadata endpoint won't parse as valid LFS JSON), but an attacker hosting a fake LFS server can chain this into full read access to internal services by returning download URLs that point at…CRITICAL 9.1EPSS 0.33%7 March 2026
CVE-2026-29191From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint.CRITICAL 9.3EPSS 0.40%7 March 2026
CVE-2026-29186Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution.CRITICAL 9.8EPSS 0.78%7 March 2026
CVE-2026-29067From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2.CRITICAL 9.3EPSS 0.32%7 March 2026
CVE-2026-25070XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands.CRITICAL 9.3EPSS 3.00%7 March 2026
CVE-2026-30847Wekan is an open source kanban tool built with Meteor.CRITICAL 9.3EPSS 0.24%6 March 2026
CVE-2026-30844Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL loading.CRITICAL 9.3EPSS 0.24%6 March 2026
CVE-2026-30843Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which could allow unauthorized users to modify custom fields across boards through its custom fields update endpoints, potentially leading to unauthorized data…CRITICAL 9.3EPSS 0.22%6 March 2026
CVE-2026-28514Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocket.Chat's account service used in the ddp-streamer micro service that allows an attacker to log in to the service as…CRITICAL 9.3EPSS 0.50%6 March 2026
CVE-2026-29075In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner.CRITICAL 9.8EPSS 0.37%6 March 2026
CVE-2026-26288WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.64%6 March 2026
CVE-2026-26051WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.87%6 March 2026
CVE-2026-2331An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions.CRITICAL 9.8EPSS 0.89%6 March 2026
CVE-2026-2330An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement.CRITICAL 9.4EPSS 0.66%6 March 2026
CVE-2026-29058Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter.CRITICAL 9.8EPSS 2.13%6 March 2026
CVE-2026-2446The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin usersCRITICAL 9.8EPSS 0.40%6 March 2026
CVE-2026-28794Prior to version 1.13.6, a prototype pollution vulnerability exists in the RPC JSON deserializer of the @orpc/client package.CRITICAL 9.3EPSS 0.91%6 March 2026
CVE-2026-28787This violates the WebAuthn specification (W3C Web Authentication Level 2, §13.4.3) and allows an attacker who has obtained a valid WebAuthn assertion (e.g., via XSS, MitM, or log exposure) to replay it indefinitely, completely bypassing the…CRITICAL 9.0EPSS 0.28%6 March 2026
CVE-2026-28785Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the database.CRITICAL 9.3EPSS 0.37%6 March 2026
CVE-2026-28680Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services.CRITICAL 9.3EPSS 0.23%6 March 2026
CVE-2026-28508Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoint to be trivially bypassed by any unauthenticated remote attacker.CRITICAL 9.2EPSS 0.63%6 March 2026
CVE-2026-29093An attacker who can reach port 11211 can read, modify, or flush session data — enabling session hijacking, admin impersonation, and mass session destruction without any application-level authentication.CRITICAL 9.8EPSS 0.49%6 March 2026
CVE-2026-29046This can enable header value confusion across parser boundaries and may create unsafe data in the CGI execution context.CRITICAL 9.2EPSS 0.39%6 March 2026
CVE-2026-28502Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo related to the plugin upload/import functionality.CRITICAL 9.3EPSS 0.67%6 March 2026
CVE-2026-28501Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components.CRITICAL 9.8EPSS 1.51%6 March 2026
CVE-2026-28497Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allows an unauthenticated remote attacker to bypass Content-Length restrictions and perform HTTP Request Smuggling.CRITICAL 9.3EPSS 0.47%6 March 2026
CVE-2025-59543Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability.CRITICAL 9.0EPSS 0.25%6 March 2026
CVE-2025-59542Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability.CRITICAL 9.0EPSS 0.30%6 March 2026
CVE-2025-55289Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject arbitrary JavaScript into the platform’s social network and internal messaging features.CRITICAL 9.0EPSS 0.30%6 March 2026
CVE-2026-28710Sensitive information disclosure and manipulation due to improper authentication.CRITICAL 9.8EPSS 0.41%6 March 2026
CVE-2026-22552WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.89%6 March 2026
CVE-2026-26125Payment Orchestrator Service Elevation of Privilege VulnerabilityCRITICAL 9.8EPSS 1.17%5 March 2026
CVE-2026-21536Microsoft Devices Pricing Program Remote Code Execution VulnerabilityCRITICAL 9.8EPSS 1.60%5 March 2026
CVE-2026-28474OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists.CRITICAL 9.3EPSS 0.48%5 March 2026
CVE-2026-28472OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated.CRITICAL 9.2EPSS 0.35%5 March 2026
CVE-2026-28470OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by injecting command substitution syntax.CRITICAL 9.2EPSS 0.47%5 March 2026
CVE-2026-28466OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run commands.CRITICAL 9.4EPSS 0.42%5 March 2026
CVE-2026-28446OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict…CRITICAL 9.2EPSS 0.65%5 March 2026
CVE-2026-28391OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approval restrictions.CRITICAL 9.2EPSS 0.50%5 March 2026
CVE-2026-21622Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover.CRITICAL 9.5EPSS 0.39%5 March 2026
CVE-2026-0848NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module.CRITICAL 10.0EPSS 0.81%5 March 2026
CVE-2025-70948A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.CRITICAL 9.3EPSS 0.35%5 March 2026
CVE-2025-55208Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`.CRITICAL 9.0EPSS 0.31%5 March 2026
CVE-2026-28353Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities.CRITICAL 10.0EPSS 0.45%5 March 2026
CVE-2025-29165An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample componentCRITICAL 9.8EPSS 0.63%5 March 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.