SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,598 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,238 results · page 4 of 785

CVESummaryPriorityPublished
CVE-2026-92749SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline.CRITICAL 9.2EPSS 0.52%16 September 2026
CVE-2026-76460Cisco Identity Services Engine Incorrect Use of Privileged APIs VulnerabilityKEVCRITICAL 10.0EPSS 0.78%16 September 2026
CVE-2026-75513From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterization.CRITICAL 9.1EPSS 0.35%16 September 2026
CVE-2026-20332This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common…CRITICAL 9.9EPSS 0.30%16 September 2026
CVE-2026-20284A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks.CRITICAL 9.1EPSS 0.39%16 September 2026
CVE-2025-56563A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0.CRITICAL 9.8EPSS 0.40%16 September 2026
CVE-2026-92808A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server.CRITICAL 10.0EPSS 0.32%16 September 2026
CVE-2026-89083HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.CRITICAL 9.3EPSS 0.51%16 September 2026
CVE-2026-89082HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.CRITICAL 9.3EPSS 0.51%16 September 2026
CVE-2026-88592kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF).CRITICAL 9.1EPSS 0.18%16 September 2026
CVE-2026-76423A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device.CRITICAL 10.0EPSS 0.55%16 September 2026
CVE-2026-20341A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges.CRITICAL 9.1EPSS 0.45%16 September 2026
CVE-2026-20330This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-20330 are related to improper neutralization issues that are grouped under the Common…CRITICAL 9.9EPSS 0.34%16 September 2026
CVE-2026-20329This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-20329 are related to issues concerning improper handling of exceptional conditions that…CRITICAL 9.9EPSS 0.45%16 September 2026
CVE-2026-20326This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 9.8EPSS 0.39%16 September 2026
CVE-2026-20325This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 9.9EPSS 0.34%16 September 2026
CVE-2026-20324A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root.CRITICAL 9.9EPSS 0.44%16 September 2026
CVE-2026-20322This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 9.9EPSS 0.27%16 September 2026
CVE-2026-20242A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.CRITICAL 9.8EPSS 0.64%16 September 2026
CVE-2026-20237This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 9.1EPSS 0.33%16 September 2026
CVE-2026-20211A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.CRITICAL 9.1EPSS 0.56%16 September 2026
CVE-2026-20194This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 9.1EPSS 0.45%16 September 2026
CVE-2026-20192This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 10.0EPSS 0.43%16 September 2026
CVE-2026-20176A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.CRITICAL 9.1EPSS 0.78%16 September 2026
CVE-2026-20130This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 10.0EPSS 0.40%16 September 2026
CVE-2026-91106HP has identified and remediated multiple externally reported vulnerabilities within HPLIP.CRITICAL 9.3EPSS 0.67%16 September 2026
CVE-2026-91104HP has identified and remediated multiple externally reported vulnerabilities within HPLIP.CRITICAL 9.3EPSS 0.71%16 September 2026
CVE-2026-73456Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full…CRITICAL 9.2EPSS 0.75%16 September 2026
CVE-2026-68536Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core.CRITICAL 9.8EPSS 0.47%16 September 2026
CVE-2026-92720Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs.CRITICAL 9.3EPSS 0.47%16 September 2026
CVE-2026-92717Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token.CRITICAL 9.3EPSS 0.36%16 September 2026
CVE-2026-51990An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe componentCRITICAL 9.8EPSS 1.00%16 September 2026
CVE-2026-76420A vulnerability in the internal configuration of the Apache JServ Protocol (AJP)&nbsp;connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device.CRITICAL 9.0EPSS 0.37%16 September 2026
CVE-2026-20331This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20331 are related to the failure of protection mechanisms issues that are grouped under…CRITICAL 9.6EPSS 0.23%16 September 2026
CVE-2026-20307A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.CRITICAL 9.9EPSS 0.95%16 September 2026
CVE-2026-20306A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.CRITICAL 9.1EPSS 1.37%16 September 2026
CVE-2026-20305A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to&nbsp;root.CRITICAL 9.1EPSS 1.37%16 September 2026
CVE-2026-20234This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.CRITICAL 9.9EPSS 0.37%16 September 2026
CVE-2026-90999Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment.CRITICAL 9.8EPSS 0.51%16 September 2026
CVE-2026-70416Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability.CRITICAL 10.0EPSS 0.91%16 September 2026
CVE-2025-59953In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitization, hence resulting in a remote code execution vulnerability by this RPC server.CRITICAL 9.8EPSS 0.68%16 September 2026
CVE-2026-92395Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit…CRITICAL 9.1EPSS 0.30%16 September 2026
CVE-2026-77411A malicious or compromised broker can provide an oversized longstr in a table field and desynchronize subsequent AMQP parsing, causing attacker-controlled trailing bytes to be interpreted as later fields or frames and disrupting connection integrity and…CRITICAL 9.5EPSS 0.41%16 September 2026
CVE-2026-77408The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing.CRITICAL 9.1EPSS 0.41%16 September 2026
CVE-2026-77405A network attacker able to influence TLS negotiation with such a legacy build may weaken transport protection for AMQP messages and credentials.CRITICAL 9.4EPSS 0.23%16 September 2026
CVE-2026-91843A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.CRITICAL 9.8EPSS 0.50%16 September 2026
CVE-2026-73172Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a…CRITICAL 9.3EPSS 1.73%16 September 2026
CVE-2026-58147WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality.CRITICAL 9.3EPSS 1.20%16 September 2026
CVE-2026-58146WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability.CRITICAL 9.4EPSS 2.12%16 September 2026
CVE-2026-40855WNC T-Mobile 5G Box IDU router is vulnerable to a command injection.CRITICAL 9.3EPSS 1.13%16 September 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.