SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,641 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,244 results · page 26 of 785

CVESummaryPriorityPublished
CVE-2026-37006A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.CRITICAL 9.8EPSS 0.61%27 August 2026
CVE-2026-37004BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an…CRITICAL 9.8EPSS 0.55%27 August 2026
CVE-2026-37003Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection.CRITICAL 9.8EPSS 1.60%27 August 2026
CVE-2026-35869A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0.CRITICAL 9.8EPSS 1.33%27 August 2026
CVE-2026-35868A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4.CRITICAL 9.8EPSS 1.36%27 August 2026
CVE-2026-30612An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS componentsCRITICAL 9.8EPSS 0.31%27 August 2026
CVE-2026-19092The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.CRITICAL 9.8EPSS 1.50%27 August 2026
CVE-2026-18886ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform.CRITICAL 10.0EPSS 0.25%27 August 2026
CVE-2026-18885ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform.CRITICAL 10.0EPSS 0.43%27 August 2026
CVE-2026-81826This means that if an attacker already possesses a valid session—for example, from prior access or a stolen session token—the victim changing their password does not terminate that attacker’s access.CRITICAL 9.1EPSS 0.33%27 August 2026
CVE-2026-81735The commands server exposes a run_command tool that hands its caller-supplied command string to promisify(child_process.exec), so any unauthenticated client able to reach the port could run arbitrary commands as the user running the server, and the…CRITICAL 10.0EPSS 0.53%27 August 2026
CVE-2026-81719openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import time,…CRITICAL 9.3EPSS 0.30%27 August 2026
CVE-2026-81717openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access).CRITICAL 9.3EPSS 0.09%27 August 2026
CVE-2026-81714An operator who confirms a short (forgeable, ~32-bit) GPG key id could unknowingly enroll an attacker's colliding key as a trusted anchor, which then vouches for malicious plugins under the ENFORCE signature policy.CRITICAL 9.3EPSS 0.14%27 August 2026
CVE-2026-81707openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users.CRITICAL 9.3EPSS 0.41%27 August 2026
CVE-2026-81706openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted.CRITICAL 9.3EPSS 0.13%27 August 2026
CVE-2026-81702openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores.CRITICAL 9.3EPSS 0.14%27 August 2026
CVE-2026-81701openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification.CRITICAL 9.3EPSS 0.29%27 August 2026
CVE-2026-81700openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes.CRITICAL 9.3EPSS 0.24%27 August 2026
CVE-2026-81698openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting.CRITICAL 9.3EPSS 0.28%27 August 2026
CVE-2026-81696Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.CRITICAL 9.3EPSS 0.18%27 August 2026
CVE-2026-81695openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection.CRITICAL 9.3EPSS 0.18%27 August 2026
CVE-2026-81694An attacker can plant filenames containing terminal cursor-movement and erase-line control bytes that repaint a forged PASSED verdict on screen, masking actual tamper detection.CRITICAL 9.3EPSS 0.18%27 August 2026
CVE-2026-81685openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog.CRITICAL 9.3EPSS 0.18%27 August 2026
CVE-2026-81681A user who trusts the branding and places files in the workspace leaves them unencrypted on the removable media, so an attacker with physical access to the media can read the sensitive files.CRITICAL 9.3EPSS 0.13%27 August 2026
CVE-2026-81680openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload.CRITICAL 9.3EPSS 0.14%27 August 2026
CVE-2026-81098The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication…CRITICAL 9.3EPSS 0.51%27 August 2026
CVE-2026-81096The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attribute-lookup builtins available and did not stop a dunder attribute reached…CRITICAL 9.3EPSS 0.57%27 August 2026
CVE-2026-81094The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP…CRITICAL 9.3EPSS 0.42%27 August 2026
CVE-2026-78251DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as…CRITICAL 9.3EPSS 0.39%27 August 2026
CVE-2026-75871GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to…CRITICAL 9.6EPSS 0.19%27 August 2026
CVE-2026-75357An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.CRITICAL 9.8EPSS 0.64%27 August 2026
CVE-2026-57499Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server.CRITICAL 9.1EPSS 0.96%27 August 2026
CVE-2026-26897An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml componentCRITICAL 9.8EPSS 0.74%27 August 2026
CVE-2026-16279An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.CRITICAL 9.3EPSS 0.25%27 August 2026
CVE-2026-81675The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter.CRITICAL 9.3EPSS 0.25%27 August 2026
CVE-2026-81674The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter.CRITICAL 9.3EPSS 0.28%27 August 2026
CVE-2026-81673The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters.CRITICAL 9.3EPSS 0.36%27 August 2026
CVE-2026-81672SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter.CRITICAL 9.3EPSS 0.28%27 August 2026
CVE-2026-74233Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N…CRITICAL 9.3EPSS 2.63%27 August 2026
CVE-2026-74232Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522…CRITICAL 9.3EPSS 0.47%27 August 2026
CVE-2026-78292Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.CRITICAL 9.8EPSS 0.53%27 August 2026
CVE-2026-78288Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.CRITICAL 9.3EPSS 0.38%27 August 2026
CVE-2026-78286Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.CRITICAL 9.8EPSS 0.53%27 August 2026
CVE-2026-78274Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.CRITICAL 9.1EPSS 0.46%27 August 2026
CVE-2026-78260Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.CRITICAL 9.3EPSS 0.38%27 August 2026
CVE-2026-32566Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.CRITICAL 9.8EPSS 0.45%27 August 2026
CVE-2026-32479Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.CRITICAL 9.3EPSS 0.38%27 August 2026
CVE-2026-77991Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl.CRITICAL 9.4EPSS 0.41%27 August 2026
CVE-2026-77016The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to…CRITICAL 9.6EPSS 0.24%27 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.