SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,244 results · page 32 of 785

CVESummaryPriorityPublished
CVE-2026-74608In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_try_adding_channels() cifs_try_adding_channels() takes a temporary reference to an interface before dropping iface_lock.CRITICAL 9.8EPSS 0.48%22 August 2026
CVE-2026-74597In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the quoted inner IPv6 packet, and then passes the clone to icmpv6_send().CRITICAL 9.8EPSS 0.51%22 August 2026
CVE-2026-74591In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index before retrying In __filemap_add_folio()'s split-a-conflict loop, xas_set_order() is applied repeatedly: each application modifies…CRITICAL 9.8EPSS 0.44%22 August 2026
CVE-2026-74588In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list it is queued on __sctp_outq_flush_rtx() moves a gap-acked chunk onto another transport's transmitted list without updating…CRITICAL 9.8EPSS 0.50%22 August 2026
CVE-2026-74587In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk addip_last_asconf caches the outstanding outbound ASCONF chunk.CRITICAL 9.8EPSS 0.50%22 August 2026
CVE-2026-74586In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sctp_process_asconf_param() stores a newly added peer transport in asoc->new_transport.CRITICAL 9.8EPSS 0.50%22 August 2026
CVE-2026-4703The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values.CRITICAL 9.8EPSS 0.62%22 August 2026
CVE-2026-77992Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.CRITICAL 9.5EPSS 0.26%22 August 2026
CVE-2026-76607Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.CRITICAL 10.0EPSS 0.24%22 August 2026
CVE-2026-76606Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.CRITICAL 10.0EPSS 0.33%22 August 2026
CVE-2026-76605Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.CRITICAL 10.0EPSS 0.41%22 August 2026
CVE-2026-76604Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.CRITICAL 10.0EPSS 0.41%22 August 2026
CVE-2026-76602Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.CRITICAL 9.3EPSS 0.25%22 August 2026
CVE-2026-76571Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery().CRITICAL 9.3EPSS 0.27%22 August 2026
CVE-2026-75870Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret.CRITICAL 9.1EPSS 0.49%22 August 2026
CVE-2026-75866Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in the request body, so a client registered for authorization_code alone can ask for…CRITICAL 9.1EPSS 0.53%22 August 2026
CVE-2026-77946A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05.CRITICAL 9.3EPSS 0.62%22 August 2026
CVE-2026-78003The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0.CRITICAL 9.8EPSS 0.87%22 August 2026
CVE-2026-12710A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.CRITICAL 9.3EPSS 0.32%22 August 2026
CVE-2026-77002The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.CRITICAL 9.8EPSS 0.34%22 August 2026
CVE-2026-77001The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to…CRITICAL 9.8EPSS 0.42%22 August 2026
CVE-2026-77000The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including…CRITICAL 9.8EPSS 0.34%22 August 2026
CVE-2026-49849An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php).CRITICAL 9.1EPSS 0.93%21 August 2026
CVE-2026-77415Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code.CRITICAL 9.3EPSS 0.65%21 August 2026
CVE-2026-77414Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check.CRITICAL 9.3EPSS 0.43%21 August 2026
CVE-2026-77413Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members.CRITICAL 9.3EPSS 0.52%21 August 2026
CVE-2026-76904Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains` function; Requires PostGIS 12 or greater with a String…CRITICAL 9.8EPSS 1.79%21 August 2026
CVE-2026-62283An authenticated RoleMember who obtains a live stream UUID from logs, browser history, referer data, or telemetry can attach to another user's terminal or file-manager session, read and write target-server files, and execute shell commands.CRITICAL 9.9EPSS 0.37%21 August 2026
CVE-2026-61539In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py.CRITICAL 10.0EPSS 0.66%21 August 2026
CVE-2026-59989An attacker who can influence Volt template source can place quote-breaking content in a join argument, inject PHP into the compiled cache file, and execute it when Phalcon\Mvc\View\Engine\Volt::render() loads the template.CRITICAL 9.2EPSS 0.31%21 August 2026
CVE-2026-77810In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector.CRITICAL 9.4EPSS 0.35%21 August 2026
CVE-2026-77234Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context.CRITICAL 9.3EPSS 0.12%21 August 2026
CVE-2026-62674An authenticated user with edit access to a session can replace that shared agent bundle through omnigent/server/routes/sessions.py, add a stdio MCP server, and cause later sessions that use the shared agent to launch an attacker-controlled command…CRITICAL 9.0EPSS 0.34%21 August 2026
CVE-2026-74581In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info.CRITICAL 9.8EPSS 0.40%21 August 2026
CVE-2026-75932Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app.CRITICAL 9.2EPSS 0.40%21 August 2026
CVE-2026-69502Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 0.57%21 August 2026
CVE-2026-77812An attacker within BLE range can passively sniff this traffic and recover the credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted identifier UUID.CRITICAL 9.4EPSS 0.06%21 August 2026
CVE-2026-77087Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding.CRITICAL 9.4EPSS 0.40%21 August 2026
CVE-2026-63343Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API.CRITICAL 9.9EPSS 0.27%21 August 2026
CVE-2026-63125Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host.CRITICAL 9.9EPSS 0.50%21 August 2026
CVE-2026-62941Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request.CRITICAL 9.9EPSS 0.31%21 August 2026
CVE-2026-62940Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project restriction enforcement,…CRITICAL 9.9EPSS 0.23%21 August 2026
CVE-2026-62867Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line.CRITICAL 9.9EPSS 0.29%21 August 2026
CVE-2026-48769Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header.CRITICAL 9.9EPSS 0.54%21 August 2026
CVE-2026-48755Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line.CRITICAL 9.9EPSS 0.44%21 August 2026
CVE-2026-48753Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host.CRITICAL 9.9EPSS 0.87%21 August 2026
CVE-2026-48752Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.CRITICAL 9.9EPSS 0.81%21 August 2026
CVE-2026-48751Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`.CRITICAL 9.9EPSS 0.86%21 August 2026
CVE-2026-48750If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary location where the `.stdout` file will contain arbitrary content.CRITICAL 9.9EPSS 0.78%21 August 2026
CVE-2026-48749Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.CRITICAL 9.9EPSS 0.99%21 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.