SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,244 results · page 33 of 785

CVESummaryPriorityPublished
CVE-2026-77806SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026.CRITICAL 9.8EPSS 4.20%21 August 2026
CVE-2026-77776The fix introduces a single resolve_memory_identity seam in headroom/proxy/identity.py that honors the header only for loopback or allowlisted callers and otherwise binds the identity to the proxy-token fingerprint or the operating system user.CRITICAL 9.3EPSS 0.34%21 August 2026
CVE-2026-59318Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation.CRITICAL 9.8EPSS 0.19%21 August 2026
CVE-2026-77086SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences.CRITICAL 9.4EPSS 0.65%21 August 2026
CVE-2026-62440Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes.CRITICAL 9.1EPSS 0.30%21 August 2026
CVE-2026-61398Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality.CRITICAL 9.1EPSS 0.32%21 August 2026
CVE-2026-59085Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests.CRITICAL 9.1EPSS 0.33%21 August 2026
CVE-2026-77264The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6.CRITICAL 9.8EPSS 0.57%21 August 2026
CVE-2026-76158External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute…CRITICAL 9.3EPSS 0.41%21 August 2026
CVE-2026-76156OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.CRITICAL 9.4EPSS 0.83%21 August 2026
CVE-2026-76155Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.CRITICAL 9.3EPSS 0.29%21 August 2026
CVE-2026-77651The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.CRITICAL 9.8EPSS 0.45%21 August 2026
CVE-2026-77650The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.CRITICAL 9.8EPSS 0.43%21 August 2026
CVE-2026-77649The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.CRITICAL 9.8EPSS 0.43%21 August 2026
CVE-2026-77647SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026.CRITICAL 9.8EPSS 2.62%20 August 2026
CVE-2026-77645A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM.CRITICAL 9.2EPSS 0.47%20 August 2026
CVE-2026-77644A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.CRITICAL 9.3EPSS 0.31%20 August 2026
CVE-2026-77642tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type.CRITICAL 9.3EPSS 0.20%20 August 2026
CVE-2026-72843Customer uuids are exposed through order confirmation email links and administrative URLs.CRITICAL 9.3EPSS 0.59%20 August 2026
CVE-2026-69851Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.CRITICAL 9.9EPSS 0.43%20 August 2026
CVE-2026-69836Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.CRITICAL 10.0EPSS 1.55%20 August 2026
CVE-2026-69555Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 0.44%20 August 2026
CVE-2026-69400Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.6EPSS 0.56%20 August 2026
CVE-2026-68789Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.CRITICAL 9.9EPSS 0.53%20 August 2026
CVE-2026-68782Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.CRITICAL 9.9EPSS 0.54%20 August 2026
CVE-2026-66309Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.CRITICAL 9.1EPSS 0.47%20 August 2026
CVE-2026-65816Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 0.52%20 August 2026
CVE-2026-65801Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 0.51%20 August 2026
CVE-2026-65770Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.CRITICAL 10.0EPSS 0.56%20 August 2026
CVE-2026-62834Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.29%20 August 2026
CVE-2026-55769A role holding DATABASE OWNER could create overloaded built-in operators in the public schema and change the database or role search_path, causing instance-manager introspection queries such as SELECT COUNT(*) > 0 FROM pg_catalog.pg_extension WHERE…CRITICAL 9.4EPSS 0.68%20 August 2026
CVE-2026-19437IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.CRITICAL 9.8EPSS 0.47%20 August 2026
CVE-2026-18835IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.CRITICAL 9.9EPSS 0.58%20 August 2026
CVE-2026-18832IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.CRITICAL 9.8EPSS 0.59%20 August 2026
CVE-2026-18716IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.CRITICAL 9.1EPSS 0.29%20 August 2026
CVE-2026-18670IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.CRITICAL 9.1EPSS 0.37%20 August 2026
CVE-2026-17436IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.CRITICAL 9.8EPSS 0.59%20 August 2026
CVE-2026-17423IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.CRITICAL 9.1EPSS 0.33%20 August 2026
CVE-2026-17160IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.CRITICAL 9.8EPSS 0.55%20 August 2026
CVE-2026-17157IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.CRITICAL 9.8EPSS 0.56%20 August 2026
CVE-2026-17152IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.CRITICAL 9.8EPSS 0.56%20 August 2026
CVE-2026-17145IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.CRITICAL 9.8EPSS 0.51%20 August 2026
CVE-2026-17142IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.CRITICAL 9.8EPSS 0.59%20 August 2026
CVE-2026-17141IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.CRITICAL 9.8EPSS 0.56%20 August 2026
CVE-2026-17138IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.CRITICAL 9.8EPSS 0.47%20 August 2026
CVE-2026-17136IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.CRITICAL 9.8EPSS 0.60%20 August 2026
CVE-2026-17122IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.CRITICAL 9.8EPSS 0.56%20 August 2026
CVE-2026-17118IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.CRITICAL 9.8EPSS 0.44%20 August 2026
CVE-2026-17060IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read.CRITICAL 9.1EPSS 0.37%20 August 2026
CVE-2026-17040IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.CRITICAL 9.8EPSS 0.46%20 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.