SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,245 results · page 35 of 785

CVESummaryPriorityPublished
CVE-2026-76404In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system.CRITICAL 9.1EPSS 0.56%19 August 2026
CVE-2026-76312In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data…CRITICAL 9.4EPSS 0.36%19 August 2026
CVE-2026-76311In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all…CRITICAL 9.4EPSS 0.37%19 August 2026
CVE-2026-76310The vulnerability is possible because embedded report access does not block Representational State Transfer (REST) API dispatch archive download requests.CRITICAL 9.4EPSS 0.37%19 August 2026
CVE-2026-75595In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the…CRITICAL 9.1EPSS 0.32%19 August 2026
CVE-2026-53548A failed requester-scoped lookup can resolve the host with the owner's context and return the owner's plaintext credential, allowing any authenticated user with a valid JWT to enumerate sequential hosts.id values and retrieve SSH or sudo passwords…CRITICAL 9.6EPSS 0.44%19 August 2026
CVE-2026-53546When no credential is shared with the requester, resolveHostById performs an owner credential fallback, and src/backend/ssh/terminal.ts combines that credential with attacker-controlled ip, port, and username values.CRITICAL 9.6EPSS 0.44%19 August 2026
CVE-2026-53545An authenticated user who can edit a tunnel host field can include a single quote to terminate the pattern and append a shell command, which executes when the tunnel is disconnected.CRITICAL 9.8EPSS 0.54%19 August 2026
CVE-2026-55089A non-admin user with a valid signed token can therefore invoke administrative functions including setHTML, setText, appendText, deletePad, copyPad, movePad, restoreRevision, anonymizeAuthor, listAllPads, and listAuthorsOfPad, allowing disclosure,…CRITICAL 9.9EPSS 0.44%19 August 2026
CVE-2026-55085ImportEtherpad.setPadRaw in src/node/utils/ImportEtherpad.ts accepts attacker-controlled attribute-pool values from a crafted .etherpad import, including list:number1 and a malicious start value.CRITICAL 9.6EPSS 0.45%19 August 2026
CVE-2026-22306Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain.CRITICAL 10.0EPSS 0.16%19 August 2026
CVE-2026-19508Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary…CRITICAL 9.8EPSS 0.81%19 August 2026
CVE-2026-19505Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature.CRITICAL 9.8EPSS 0.39%19 August 2026
CVE-2026-16919IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.CRITICAL 9.8EPSS 0.64%19 August 2026
CVE-2026-16917IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.CRITICAL 9.8EPSS 0.60%19 August 2026
CVE-2026-16913IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.CRITICAL 9.8EPSS 0.62%19 August 2026
CVE-2026-16903IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write.CRITICAL 9.6EPSS 0.29%19 August 2026
CVE-2026-16894IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.CRITICAL 9.8EPSS 0.62%19 August 2026
CVE-2026-16885IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.CRITICAL 9.8EPSS 0.60%19 August 2026
CVE-2026-16882IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.CRITICAL 9.8EPSS 0.55%19 August 2026
CVE-2026-16872IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.CRITICAL 9.8EPSS 0.46%19 August 2026
CVE-2026-16864IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.CRITICAL 9.8EPSS 0.46%19 August 2026
CVE-2026-16862IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.CRITICAL 9.8EPSS 0.49%19 August 2026
CVE-2026-16845IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.CRITICAL 9.8EPSS 0.49%19 August 2026
CVE-2026-16840IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.CRITICAL 9.8EPSS 0.58%19 August 2026
CVE-2026-16839IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to an integer underflow in the IPv4 IP-options parser.CRITICAL 9.4EPSS 0.39%19 August 2026
CVE-2026-16834IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer underflow.CRITICAL 9.8EPSS 0.46%19 August 2026
CVE-2026-16822IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation.CRITICAL 9.3EPSS 0.20%19 August 2026
CVE-2026-70496The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork.CRITICAL 9.9EPSS 0.43%19 August 2026
CVE-2026-18315The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6.CRITICAL 9.8EPSS 0.60%19 August 2026
CVE-2026-16835IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol.CRITICAL 9.6EPSS 0.22%19 August 2026
CVE-2026-16687IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface.CRITICAL 9.6EPSS 0.21%19 August 2026
CVE-2026-72717This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.66%19 August 2026
CVE-2026-72716This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.66%19 August 2026
CVE-2026-71871This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.48%19 August 2026
CVE-2026-71869This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.61%19 August 2026
CVE-2026-71868This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.61%19 August 2026
CVE-2026-71867This permits attacker-controlled JavaScript to be evaluated when the generated mock factory is called by tests or an MSW handler, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.61%19 August 2026
CVE-2026-71866This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.48%19 August 2026
CVE-2026-71865This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.48%19 August 2026
CVE-2026-71864This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.61%19 August 2026
CVE-2026-66794This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks.CRITICAL 9.3EPSS 0.41%19 August 2026
CVE-2026-62682This permits attacker-controlled JavaScript to be evaluated when a generated request or URL-builder function is called, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.62%19 August 2026
CVE-2026-62681This permits attacker-controlled JavaScript to be evaluated when a generated request, URL-builder, or query-key function is called, resulting in code execution in the developer, CI, test, or application environment.CRITICAL 9.3EPSS 0.66%19 August 2026
CVE-2026-32475Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.CRITICAL 9.0EPSS 2.37%19 August 2026
CVE-2025-14600An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access.CRITICAL 9.3EPSS 0.37%19 August 2026
CVE-2026-75143FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer,…CRITICAL 9.3EPSS 0.40%19 August 2026
CVE-2026-72530TrueConf Server Code Injection VulnerabilityKEVCRITICAL 9.5EPSS 1.83%19 August 2026
CVE-2026-72529TrueConf Server Missing Authentication for Critical Function VulnerabilityKEVCRITICAL 9.3EPSS 1.55%19 August 2026
CVE-2026-71470This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation.CRITICAL 9.1EPSS 0.42%19 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.