SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,163 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,321 results · page 145 of 787

CVESummaryPriorityPublished
CVE-2025-30044In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlogstat2.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl", the parameters are not sufficiently…CRITICAL 9.4EPSS 0.54%2 March 2026
CVE-2025-30042The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used for access verification.CRITICAL 9.0EPSS 0.09%2 March 2026
CVE-2025-30035The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any other credentials.CRITICAL 9.0EPSS 0.21%2 March 2026
CVE-2026-2584A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system.CRITICAL 9.3EPSS 0.41%2 March 2026
CVE-2026-3422U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.CRITICAL 9.3EPSS 0.76%2 March 2026
CVE-2026-3000IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.CRITICAL 9.3EPSS 0.51%2 March 2026
CVE-2026-2999IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.CRITICAL 9.3EPSS 0.51%2 March 2026
CVE-2026-3010Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2.CRITICAL 9.3EPSS 0.15%28 February 2026
CVE-2026-2844Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.CRITICAL 9.3EPSS 0.25%28 February 2026
CVE-2026-28517openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php.CRITICAL 9.3EPSS 5.65%27 February 2026
CVE-2026-28516openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter.CRITICAL 9.3EPSS 0.97%27 February 2026
CVE-2026-28515openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php.CRITICAL 9.3EPSS 1.16%27 February 2026
CVE-2026-28411Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts.CRITICAL 9.8EPSS 2.32%27 February 2026
CVE-2026-28408A malicious user could make a request through tools like Postman or the file's URL on the web to access features exclusive to employees.CRITICAL 9.8EPSS 0.51%27 February 2026
CVE-2026-28268Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely.CRITICAL 9.8EPSS 0.67%27 February 2026
CVE-2026-27947Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote Code Execution vulnerability in the TNEF attachment processing flow.CRITICAL 9.4EPSS 0.73%27 February 2026
CVE-2026-27707Starting in version 2.0.0 and prior to version 3.1.0, an authentication guard logic flaw in `POST /api/v1/auth/jellyfin` allows an unauthenticated attacker to register a new Seerr account on any Plex-configured instance by authenticating with an…CRITICAL 9.8EPSS 0.51%27 February 2026
CVE-2026-27755SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies.CRITICAL 9.3EPSS 0.40%27 February 2026
CVE-2026-27751SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface.CRITICAL 9.3EPSS 0.45%27 February 2026
CVE-2026-2750Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.CRITICAL 9.8EPSS 0.30%27 February 2026
CVE-2026-2751Blind SQL Injection via unsanitized array keys in Service Dependencies deletion.CRITICAL 9.8EPSS 0.27%27 February 2026
CVE-2025-15498Pro3W CMS if vulnerable to SQL injection attacks.CRITICAL 9.3EPSS 0.47%27 February 2026
CVE-2025-11252Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc.CRITICAL 9.8EPSS 0.39%27 February 2026
CVE-2025-11251Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc.CRITICAL 9.8EPSS 0.40%27 February 2026
CVE-2026-2251Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE.CRITICAL 9.8EPSS 0.39%27 February 2026
CVE-2026-1626An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic.CRITICAL 9.1EPSS 0.20%27 February 2026
CVE-2025-12981The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6.CRITICAL 9.8EPSS 0.57%27 February 2026
CVE-2026-28370In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under.CRITICAL 9.1EPSS 0.76%27 February 2026
CVE-2026-22877An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the system, and potentially causing a denial-of-service attack.CRITICAL 9.1EPSS 0.55%27 February 2026
CVE-2026-20797A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.CRITICAL 9.8EPSS 0.78%27 February 2026
CVE-2026-27028WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.52%27 February 2026
CVE-2026-25085A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass.CRITICAL 9.8EPSS 0.49%27 February 2026
CVE-2026-24663An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting…CRITICAL 9.8EPSS 2.14%27 February 2026
CVE-2026-21718An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system.CRITICAL 9.8EPSS 0.43%27 February 2026
CVE-2026-27772WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.53%27 February 2026
CVE-2026-27767WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.51%27 February 2026
CVE-2026-25851WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.64%27 February 2026
CVE-2026-24731WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.56%27 February 2026
CVE-2026-20781WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend.CRITICAL 9.3EPSS 0.52%27 February 2026
CVE-2026-28215Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials and SMTP settings by sending a single HTTP POST request with no…CRITICAL 9.1EPSS 0.46%26 February 2026
CVE-2026-28213Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality.CRITICAL 9.8EPSS 0.45%26 February 2026
CVE-2026-22207OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted.CRITICAL 9.3EPSS 0.43%26 February 2026
CVE-2025-50857ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php.CRITICAL 9.8EPSS 2.29%26 February 2026
CVE-2026-27969This is a common path traversal security issue.CRITICAL 9.3EPSS 0.40%26 February 2026
CVE-2026-27966Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`).CRITICAL 9.8EPSS 33.7%26 February 2026
CVE-2026-27952In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator.CRITICAL 9.9EPSS 0.50%26 February 2026
CVE-2026-27941Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from forked pull requests.CRITICAL 9.9EPSS 0.40%26 February 2026
CVE-2026-27837The prototype pollution guard introduced in commit `7d3aee1` only validates the first segment of a dot-separated path, allowing an attacker to bypass the protection by placing `__proto__` at any position other than the first.CRITICAL 9.8EPSS 0.30%26 February 2026
CVE-2026-27804Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated attacker can forge a Google authentication token with `alg: "none"` to log in as any user linked to a Google account, without knowing their credentials.CRITICAL 9.3EPSS 0.18%26 February 2026
CVE-2026-27613A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI parameter security controls.CRITICAL 10.0EPSS 0.75%25 February 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.