SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,244 results · page 31 of 785

CVESummaryPriorityPublished
CVE-2026-76835GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the skip_auth_routes and skip_auth_regex allow list against the resulting…CRITICAL 9.3EPSS 0.35%24 August 2026
CVE-2026-71921Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface.CRITICAL 9.3EPSS 3.25%24 August 2026
CVE-2026-71914Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component.CRITICAL 9.3EPSS 3.07%24 August 2026
CVE-2026-78329Improper input validation vulnerability in Apache Camel Undertow component.CRITICAL 9.8EPSS 0.43%24 August 2026
CVE-2026-77915rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that…CRITICAL 9.3EPSS 0.40%24 August 2026
CVE-2026-71300Improper input validation vulnerability in Apache Camel Atmosphere Websocket component.CRITICAL 9.8EPSS 0.46%24 August 2026
CVE-2026-66906Relative path traversal vulnerability in Apache Camel Azure Storage Blob component.CRITICAL 9.1EPSS 0.53%24 August 2026
CVE-2025-36939Multiple vulnerabilities exist in OpenThread's handling of MLE packets.CRITICAL 10.0EPSS 0.23%24 August 2026
CVE-2026-76071Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in…CRITICAL 9.3EPSS 1.06%24 August 2026
CVE-2026-76070Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in…CRITICAL 9.3EPSS 1.00%24 August 2026
CVE-2026-78387RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint.CRITICAL 9.4EPSS 0.35%24 August 2026
CVE-2026-19874A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players.CRITICAL 9.1EPSS 0.73%24 August 2026
CVE-2026-78372An unauthenticated or otherwise unauthorized remote attacker can access information associated with private entities through several web views and API endpoints.CRITICAL 9.2EPSS 0.48%24 August 2026
CVE-2026-78370RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private.CRITICAL 9.2EPSS 0.49%24 August 2026
CVE-2026-77995Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The…CRITICAL 10.0EPSS 0.29%24 August 2026
CVE-2026-67602phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism.CRITICAL 9.3EPSS 0.35%24 August 2026
CVE-2026-59568Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.CRITICAL 9.1EPSS 0.38%24 August 2026
CVE-2026-59564An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.CRITICAL 9.1EPSS 0.30%24 August 2026
CVE-2026-78365Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT…CRITICAL 9.3EPSS 0.37%24 August 2026
CVE-2026-66650Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.CRITICAL 9.8EPSS 0.31%24 August 2026
CVE-2026-66648Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.CRITICAL 9.8EPSS 0.27%24 August 2026
CVE-2026-66587Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.CRITICAL 9.8EPSS 0.28%24 August 2026
CVE-2026-32558Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.CRITICAL 9.8EPSS 0.27%24 August 2026
CVE-2026-32551Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.CRITICAL 9.3EPSS 0.24%24 August 2026
CVE-2026-28165Unauthenticated Privilege Escalation in Digits <= 9.2 versions.CRITICAL 9.8EPSS 0.27%24 August 2026
CVE-2026-66897A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root.CRITICAL 9.9EPSS 0.67%24 August 2026
CVE-2026-77994Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.CRITICAL 9.3EPSS 0.23%24 August 2026
CVE-2026-782114MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability.CRITICAL 9.3EPSS 1.54%24 August 2026
CVE-2026-78167A weakness has been identified in EFM ipTIME T16000M 14.20.2.CRITICAL 9.3EPSS 1.03%24 August 2026
CVE-2026-78207exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects.CRITICAL 9.3EPSS 0.44%24 August 2026
CVE-2026-78183DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL.CRITICAL 9.8EPSS 0.55%23 August 2026
CVE-2026-8445While a small set of Markdown metacharacters are escaped, characters such as < and > are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g. &lt;script&gt;) or text from RCDATA/RAWTEXT-parsed elements like…CRITICAL 9.3EPSS 0.38%23 August 2026
CVE-2026-7808justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting.CRITICAL 9.3EPSS 0.35%23 August 2026
CVE-2026-5388Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs, backslash-based relative URLs resolved as remote hosts, markup-breaking programmatic element/attribute names…CRITICAL 9.3EPSS 0.34%23 August 2026
CVE-2026-78155privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privilegesCRITICAL 9.9EPSS 0.29%23 August 2026
CVE-2026-13598The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full…CRITICAL 9.8EPSS 0.30%23 August 2026
CVE-2026-74730In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call Dan Aloni reports that he was able to hit a use-after-free bug if a FREE_STATEID operation gets delayed for whatever reason.CRITICAL 9.8EPSS 0.51%22 August 2026
CVE-2026-74727In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by_id ovpn_nl_peer_set_doit() resolves the target peer via ovpn_peer_get_by_id() before taking ovpn->lock.CRITICAL 9.8EPSS 0.44%22 August 2026
CVE-2026-74723In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid headers [BUG] For a crafted btrfs image, the following KASAN can be triggered when reading an inline lzo compressed file extent: BUG:…CRITICAL 9.8EPSS 0.38%22 August 2026
CVE-2026-74712In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys() We have seen in our CI the following KASAN message: BUG: KASAN: slab-out-of-bounds in cmd_exec+0x550/0xca0 [mlx5_core] Read of size…CRITICAL 9.3EPSS 0.14%22 August 2026
CVE-2026-74705In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head.CRITICAL 10.0EPSS 0.50%22 August 2026
CVE-2026-74688In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being removed sctp_make_heartbeat_ack() caches the destination transport in chunk->transport without taking a reference.CRITICAL 9.8EPSS 0.50%22 August 2026
CVE-2026-74669In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP errors ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the quoted original request before passing it to icmp_send().CRITICAL 9.8EPSS 0.51%22 August 2026
CVE-2026-74665In the Linux kernel, the following vulnerability has been resolved: net: fix skb length accounting after generic XDP frag adjustment Generic XDP exposes non-linear skb fragments through an xdp_buff.CRITICAL 9.1EPSS 0.37%22 August 2026
CVE-2026-74662In the Linux kernel, the following vulnerability has been resolved: inet: frags: publish queues before arming timer inet_frag_create() arms the fragment queue timer before inserting the queue into the fqdir rhashtable.CRITICAL 9.8EPSS 0.51%22 August 2026
CVE-2026-74628In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by its timers The x25 timers are armed with mod_timer() and cancelled with timer_delete(), so a pending timer holds no reference on the socket…CRITICAL 9.8EPSS 0.50%22 August 2026
CVE-2026-74617In the Linux kernel, the following vulnerability has been resolved: dibs: initialise dibs->lock in dibs_dev_alloc() dibs->lock is initialised by dibs_dev_add(), but a dibs device can already take interrupts before that call: ism_probe() runs…CRITICAL 9.8EPSS 0.44%22 August 2026
CVE-2026-74616In the Linux kernel, the following vulnerability has been resolved: xdp: reject clones that overrun skb_shared_info tailroom xdpf_clone() clones broadcast copies into a single page and sets frame_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later…CRITICAL 9.8EPSS 0.51%22 August 2026
CVE-2026-74612In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adjustment veth exposes non-linear skb fragments through an xdp_buff.CRITICAL 10.0EPSS 0.49%22 August 2026
CVE-2026-74611In the Linux kernel, the following vulnerability has been resolved: tls: rx: restore msg_iter before TLS 1.3 optimistic retry tls_decrypt_sg() advances msg->msg_iter when it maps user pages for the optimistic TLS 1.3 zero-copy path.CRITICAL 9.8EPSS 0.44%22 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.