SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,656 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,245 results · page 36 of 785

CVESummaryPriorityPublished
CVE-2026-49441Replacing ossec.conf can configure root-executed commands and lead to code execution after a service reload.CRITICAL 9.1EPSS 0.52%19 August 2026
CVE-2026-48162From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file value to WAZUH_PATH without canonicalization or confinement.CRITICAL 9.1EPSS 0.57%19 August 2026
CVE-2026-48024A cluster peer holding the shared Fernet key can use traversal in files_metadata.json or a merged-file header to write files such as /var/ossec/etc/ossec.conf.CRITICAL 9.1EPSS 0.72%19 August 2026
CVE-2026-20359This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 9.9EPSS 0.36%19 August 2026
CVE-2026-20358This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 10.0EPSS 0.46%19 August 2026
CVE-2026-20357This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 10.0EPSS 0.55%19 August 2026
CVE-2026-20318This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 9.6EPSS 0.35%19 August 2026
CVE-2026-20317This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 10.0EPSS 0.44%19 August 2026
CVE-2026-20315This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 10.0EPSS 0.41%19 August 2026
CVE-2026-20231This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-20231 are related to improper neutralization of special elements issues that are grouped…CRITICAL 9.9EPSS 0.50%19 August 2026
CVE-2026-20030This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 10.0EPSS 0.55%19 August 2026
CVE-2026-62668Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content.CRITICAL 9.4EPSS 0.42%19 August 2026
CVE-2026-75954Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL.CRITICAL 9.3EPSS 0.28%19 August 2026
CVE-2026-75949Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path…CRITICAL 10.0EPSS 0.31%19 August 2026
CVE-2026-71960Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from…CRITICAL 9.3EPSS 0.54%19 August 2026
CVE-2026-53451Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits an absolute path or…CRITICAL 9.8EPSS 0.86%19 August 2026
CVE-2026-52889An unauthenticated attacker can place Twig syntax in one of these request-controlled inputs when a public form contains an affected Hidden field.CRITICAL 9.8EPSS 0.68%19 August 2026
CVE-2026-47187A victim or victim-side tool that follows such a link through ordinary operations such as cp, rsync, backup tooling, or an editor can disclose readable local files back to the server or write server-controlled content to writable local files,…CRITICAL 9.3EPSS 0.41%19 August 2026
CVE-2026-45272An administrator can submit a crafted SOCIAL_AUTH key name that closes the settings dictionary and injects arbitrary Python statements.CRITICAL 9.4EPSS 0.37%19 August 2026
CVE-2026-16816IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.CRITICAL 9.9EPSS 0.49%19 August 2026
CVE-2026-16656IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.CRITICAL 9.8EPSS 0.42%19 August 2026
CVE-2026-15068IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.CRITICAL 9.9EPSS 1.05%19 August 2026
CVE-2026-15065IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file.CRITICAL 9.1EPSS 0.48%19 August 2026
CVE-2026-76244stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled.CRITICAL 9.1EPSS 0.22%19 August 2026
CVE-2026-76243stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments.CRITICAL 9.2EPSS 0.40%19 August 2026
CVE-2026-76242On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirected, an attacker can register a malicious peer and gain access to or tamper with federation traffic.CRITICAL 9.1EPSS 0.27%19 August 2026
CVE-2026-76214At login the anti-replay comparison is skipped by its own null guard, allowing an attacker who captures a successful WebAuthn assertion to replay it indefinitely and authenticate as the user without any interaction or hardware key.CRITICAL 9.1EPSS 0.29%19 August 2026
CVE-2026-76213phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication.CRITICAL 9.1EPSS 0.33%19 August 2026
CVE-2026-75917SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getLeaf()/movePathTo()) used by the 'move/link to' path-selection dialogs, where document metadata fields…CRITICAL 9.3EPSS 0.16%19 August 2026
CVE-2026-75916SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup.CRITICAL 9.3EPSS 0.16%19 August 2026
CVE-2026-74804Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting…CRITICAL 9.3EPSS 0.28%19 August 2026
CVE-2026-74803Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.CRITICAL 10.0EPSS 0.31%19 August 2026
CVE-2026-51366SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameterCRITICAL 9.9EPSS 0.55%19 August 2026
CVE-2026-16019Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc.CRITICAL 9.8EPSS 0.32%19 August 2026
CVE-2024-58376Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands.CRITICAL 9.3EPSS 1.67%19 August 2026
CVE-2026-73391Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.CRITICAL 9.3EPSS 0.24%19 August 2026
CVE-2026-73390Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.CRITICAL 9.8EPSS 0.27%19 August 2026
CVE-2026-73389Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.CRITICAL 9.8EPSS 0.32%19 August 2026
CVE-2026-73388Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.CRITICAL 9.3EPSS 0.24%19 August 2026
CVE-2026-73364Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.CRITICAL 9.8EPSS 0.31%19 August 2026
CVE-2026-73347Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.CRITICAL 9.8EPSS 0.27%19 August 2026
CVE-2026-73185Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.CRITICAL 9.3EPSS 0.24%19 August 2026
CVE-2026-73183Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.CRITICAL 9.3EPSS 0.24%19 August 2026
CVE-2026-67364Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval().CRITICAL 10.0EPSS 0.29%19 August 2026
CVE-2026-66613Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.CRITICAL 9.8EPSS 0.48%19 August 2026
CVE-2026-19490Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel VulnerabilityKEVCRITICAL 9.3EPSS 5.60%19 August 2026
CVE-2026-72889Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request,…CRITICAL 9.8EPSS 0.35%19 August 2026
CVE-2026-58082Some ISO-2022 variants can require up to 10 bytes per character, in which case conversions can trigger a stack buffer overflow of up to four bytes.CRITICAL 9.8EPSS 0.36%19 August 2026
CVE-2026-58081An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.CRITICAL 9.8EPSS 0.36%19 August 2026
CVE-2026-18937The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary…CRITICAL 9.0EPSS 0.40%19 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.