SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,241 results · page 18 of 785

CVESummaryPriorityPublished
CVE-2026-86148This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin.CRITICAL 9.4EPSS 2.46%5 September 2026
CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command VulnerabilityKEVCRITICAL 9.2EPSS 1.06%5 September 2026
CVE-2026-67276Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue…CRITICAL 9.2EPSS 0.24%5 September 2026
CVE-2026-86190WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is…CRITICAL 9.3EPSS 0.27%5 September 2026
CVE-2026-86189WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter.CRITICAL 9.3EPSS 0.41%5 September 2026
CVE-2026-86184Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production.CRITICAL 9.3EPSS 0.60%5 September 2026
CVE-2026-10196The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the…CRITICAL 9.8EPSS 0.63%5 September 2026
CVE-2026-86124AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root.CRITICAL 9.3EPSS 0.54%5 September 2026
CVE-2026-86123SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts.CRITICAL 9.4EPSS 0.33%5 September 2026
CVE-2026-86121Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands.CRITICAL 9.3EPSS 0.59%5 September 2026
CVE-2026-86119Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset.CRITICAL 9.2EPSS 0.35%5 September 2026
CVE-2026-86117Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities.CRITICAL 9.2EPSS 0.42%5 September 2026
CVE-2024-11080The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file.CRITICAL 9.8EPSS 0.44%5 September 2026
CVE-2026-78362The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress…CRITICAL 9.8EPSS 0.34%5 September 2026
CVE-2026-83627The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php.CRITICAL 9.8EPSS 0.82%5 September 2026
CVE-2026-13447The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function,…CRITICAL 9.8EPSS 0.38%5 September 2026
CVE-2026-52777Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize.CRITICAL 9.4EPSS 0.21%5 September 2026
CVE-2026-52766Combined with YesWiki's allow-by-default action ACL model, any user who has page write access, which is the default for everyone (default_write_acl='*') on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin…CRITICAL 9.1EPSS 0.33%5 September 2026
CVE-2026-75925Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM.CRITICAL 9.4EPSS 0.67%4 September 2026
CVE-2026-50894easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.CRITICAL 9.8EPSS 0.48%4 September 2026
CVE-2025-67066SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging pathCRITICAL 9.8EPSS 0.40%4 September 2026
CVE-2026-79391The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations.CRITICAL 9.8EPSS 0.39%4 September 2026
CVE-2026-71625An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php componentCRITICAL 9.8EPSS 0.40%4 September 2026
CVE-2026-71624An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php componentsCRITICAL 9.8EPSS 0.52%4 September 2026
CVE-2026-81939A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.CRITICAL 9.1EPSS 0.73%4 September 2026
CVE-2026-78328A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.CRITICAL 9.1EPSS 0.50%4 September 2026
CVE-2026-78327An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to…CRITICAL 9.1EPSS 1.55%4 September 2026
CVE-2026-9317Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials.CRITICAL 9.2EPSS 0.68%4 September 2026
CVE-2026-84961undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON.CRITICAL 9.1EPSS 0.15%4 September 2026
CVE-2026-78745An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)CRITICAL 9.8EPSS 0.72%4 September 2026
CVE-2026-75430PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port.CRITICAL 9.8EPSS 0.89%4 September 2026
CVE-2026-31020In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions.CRITICAL 9.8EPSS 0.58%4 September 2026
CVE-2026-18221IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.CRITICAL 9.8EPSS 0.33%4 September 2026
CVE-2026-17207IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.CRITICAL 9.1EPSS 0.34%4 September 2026
CVE-2026-17057IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.CRITICAL 9.1EPSS 0.38%4 September 2026
CVE-2026-77822IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.CRITICAL 9.6EPSS 0.21%4 September 2026
CVE-2026-75431This allows a remote attacker to execute arbitrary code.CRITICAL 9.1EPSS 0.77%4 September 2026
CVE-2026-75429PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layerCRITICAL 9.8EPSS 0.90%4 September 2026
CVE-2026-75171An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.CRITICAL 9.8EPSS 0.42%4 September 2026
CVE-2026-75160An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.CRITICAL 9.1EPSS 0.43%4 September 2026
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without…CRITICAL 9.3EPSS 0.89%4 September 2026
CVE-2026-19274IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped…CRITICAL 9.6EPSS 0.21%4 September 2026
CVE-2026-18658IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection.CRITICAL 9.8EPSS 0.43%4 September 2026
CVE-2026-85696SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping.CRITICAL 9.3EPSS 1.49%4 September 2026
CVE-2026-85695FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery.CRITICAL 9.3EPSS 0.41%4 September 2026
CVE-2026-85694LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content.CRITICAL 9.2EPSS 0.55%4 September 2026
CVE-2026-85688TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints.CRITICAL 9.3EPSS 1.47%4 September 2026
CVE-2026-85672zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities.CRITICAL 9.3EPSS 1.47%4 September 2026
CVE-2026-85667xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline.CRITICAL 9.3EPSS 0.38%4 September 2026
CVE-2026-85663Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation.CRITICAL 9.3EPSS 0.50%4 September 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.