SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,241 results · page 16 of 785

CVESummaryPriorityPublished
CVE-2026-78445Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.89%8 September 2026
CVE-2026-77493Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.95%8 September 2026
CVE-2026-73025Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.CRITICAL 9.8EPSS 0.90%8 September 2026
CVE-2026-73010Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.89%8 September 2026
CVE-2026-73009Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.89%8 September 2026
CVE-2026-72983Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.91%8 September 2026
CVE-2026-72982Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.91%8 September 2026
CVE-2026-72979Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.97%8 September 2026
CVE-2026-70296Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.95%8 September 2026
CVE-2026-69910Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.97%8 September 2026
CVE-2026-69854Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.0EPSS 0.64%8 September 2026
CVE-2026-69845Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.93%8 September 2026
CVE-2026-69829Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.03%8 September 2026
CVE-2026-69824Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.00%8 September 2026
CVE-2026-69819Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.93%8 September 2026
CVE-2026-69769Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.91%8 September 2026
CVE-2026-69768Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.93%8 September 2026
CVE-2026-69730Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.05%8 September 2026
CVE-2026-69715Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.00%8 September 2026
CVE-2026-69641Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.CRITICAL 9.1EPSS 0.85%8 September 2026
CVE-2026-69595Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.06%8 September 2026
CVE-2026-69590Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machineCRITICAL 9.8EPSS 0.98%8 September 2026
CVE-2026-69586Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.00%8 September 2026
CVE-2026-69579Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.97%8 September 2026
CVE-2026-69525Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.04%8 September 2026
CVE-2026-69496Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.97%8 September 2026
CVE-2026-69493Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.00%8 September 2026
CVE-2026-69491Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.87%8 September 2026
CVE-2026-69463Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.91%8 September 2026
CVE-2026-69431Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.93%8 September 2026
CVE-2026-69408Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.00%8 September 2026
CVE-2026-69356Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.CRITICAL 9.3EPSS 0.70%8 September 2026
CVE-2026-69276Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.93%8 September 2026
CVE-2026-68839Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.78%8 September 2026
CVE-2026-67643Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.89%8 September 2026
CVE-2026-67636Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.CRITICAL 9.0EPSS 0.51%8 September 2026
CVE-2026-67631Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.67%8 September 2026
CVE-2026-67378Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.CRITICAL 9.0EPSS 0.51%8 September 2026
CVE-2026-65669Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.6EPSS 0.74%8 September 2026
CVE-2026-82533DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP…CRITICAL 9.4EPSS 0.62%8 September 2026
CVE-2026-82067Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup.CRITICAL 9.2EPSS 0.28%8 September 2026
CVE-2026-79570mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data.CRITICAL 9.8EPSS 0.32%8 September 2026
CVE-2026-79569Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore.CRITICAL 9.8EPSS 0.39%8 September 2026
CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin.CRITICAL 9.3EPSS 0.28%8 September 2026
CVE-2026-75156Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attacker creates — passes signature verification, and the username and role assignments are then read…CRITICAL 9.1EPSS 0.27%8 September 2026
CVE-2026-26084A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via…CRITICAL 9.9EPSS 0.24%8 September 2026
CVE-2026-86840The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution.CRITICAL 9.1EPSS 0.24%8 September 2026
CVE-2026-86738Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters.CRITICAL 9.3EPSS 0.27%8 September 2026
CVE-2026-86729WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path.CRITICAL 9.1EPSS 0.22%8 September 2026
CVE-2026-79574An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.CRITICAL 9.8EPSS 0.48%8 September 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.