SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,631 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,241 results · page 20 of 785

CVESummaryPriorityPublished
CVE-2026-84834Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.CRITICAL 9.8EPSS 0.32%3 September 2026
CVE-2026-84814Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.CRITICAL 9.8EPSS 0.36%3 September 2026
CVE-2026-84813Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.CRITICAL 9.3EPSS 0.24%3 September 2026
CVE-2026-84768Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.CRITICAL 9.3EPSS 0.24%3 September 2026
CVE-2026-84753Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.CRITICAL 9.8EPSS 0.31%3 September 2026
CVE-2026-84238Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.CRITICAL 9.8EPSS 0.27%3 September 2026
CVE-2026-85216MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials.CRITICAL 9.5EPSS 0.50%3 September 2026
CVE-2026-85183Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications.CRITICAL 9.3EPSS 0.15%3 September 2026
CVE-2026-85181CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline.CRITICAL 9.3EPSS 0.38%3 September 2026
CVE-2026-82180Authorisation is reduced to two string comparisons on attacker-supplied data: the DN-qualifier must equal "sy" or "op", and the cloud-name part of the CN must match the server's.CRITICAL 9.5EPSS 0.22%3 September 2026
CVE-2026-85154WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account.CRITICAL 9.3EPSS 0.34%3 September 2026
CVE-2026-80726In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.invalid when deriving a child shadow page's role from its parent to harden against bugs…CRITICAL 9.3EPSS 0.18%3 September 2026
CVE-2026-78080Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.CRITICAL 9.3EPSS 0.28%3 September 2026
CVE-2026-78069Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s `appTask` delegation path instantiates app-plugin controllers with no ACL check…CRITICAL 9.5EPSS 0.24%3 September 2026
CVE-2026-76178A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification.CRITICAL 9.2EPSS 0.27%3 September 2026
CVE-2026-76174Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint.CRITICAL 9.4EPSS 0.49%3 September 2026
CVE-2026-19117Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user.CRITICAL 9.8EPSS 0.28%2 September 2026
CVE-2026-66786A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives.CRITICAL 9.1EPSS 0.74%2 September 2026
CVE-2026-53671An attacker can craft an eBPF program that overwrites a context field (e.g., ctx->data), reload that field typed as T_PACKET, and dereference an attacker-controlled address — and prevail will report the program as safe.CRITICAL 9.3EPSS 0.29%2 September 2026
CVE-2026-53670Subsequent bounds checks use the stale offset and accept out-of-bounds memory accesses, so a crafted BPF program passes verification even though it would corrupt memory at runtime.CRITICAL 9.3EPSS 0.29%2 September 2026
CVE-2026-53649Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy.CRITICAL 9.6EPSS 0.21%2 September 2026
CVE-2026-20279This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.CRITICAL 9.8EPSS 0.30%2 September 2026
CVE-2026-20274This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.CRITICAL 9.8EPSS 0.73%2 September 2026
CVE-2026-20212A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges.CRITICAL 9.8EPSS 0.53%2 September 2026
CVE-2026-78689Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method.CRITICAL 9.2EPSS 0.45%2 September 2026
CVE-2026-53611Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a…CRITICAL 9.8EPSS 1.05%2 September 2026
CVE-2026-82955In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through…CRITICAL 9.0EPSS 0.14%2 September 2026
CVE-2026-77009The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.CRITICAL 9.9EPSS 0.29%2 September 2026
CVE-2026-4357The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.CRITICAL 10.0EPSS 0.30%2 September 2026
CVE-2025-9314The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload componentCRITICAL 9.8EPSS 0.30%2 September 2026
CVE-2026-73475Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing.CRITICAL 9.1EPSS 0.23%2 September 2026
CVE-2026-84795Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts.CRITICAL 9.2EPSS 0.28%2 September 2026
CVE-2026-81294Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.CRITICAL 9.8EPSS 0.33%2 September 2026
CVE-2026-81286Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.CRITICAL 9.3EPSS 0.29%2 September 2026
CVE-2026-78657The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11.CRITICAL 9.8EPSS 0.72%2 September 2026
CVE-2026-9055The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2.CRITICAL 9.8EPSS 0.29%2 September 2026
CVE-2026-84699Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.CRITICAL 9.3EPSS 0.37%2 September 2026
CVE-2026-84696Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms.CRITICAL 9.3EPSS 0.15%2 September 2026
CVE-2026-84695BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection.CRITICAL 9.3EPSS 0.26%2 September 2026
CVE-2026-84354Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.27%2 September 2026
CVE-2026-84353Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.31%2 September 2026
CVE-2026-84352Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.31%2 September 2026
CVE-2026-84333Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.28%2 September 2026
CVE-2026-84325Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app.CRITICAL 9.8EPSS 0.25%2 September 2026
CVE-2026-84324Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic.CRITICAL 9.0EPSS 0.29%2 September 2026
CVE-2026-84480WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely.CRITICAL 9.3EPSS 0.29%1 September 2026
CVE-2026-84479The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret.CRITICAL 9.3EPSS 0.32%1 September 2026
CVE-2026-84639This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.CRITICAL 9.1EPSS 0.32%1 September 2026
CVE-2026-84637Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections.CRITICAL 9.8EPSS 0.34%1 September 2026
CVE-2026-84372Attacker-controlled keys or values containing CRLF sequences can therefore be interpreted by Command::deserializeCommand() as additional commands.CRITICAL 9.8EPSS 0.41%1 September 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.