SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,669 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,246 results · page 47 of 785

CVESummaryPriorityPublished
CVE-2026-17197IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.CRITICAL 9.8EPSS 0.35%13 August 2026
CVE-2026-73649The getReferences() flow called getAttributes(), whose property access allowed an attacker-controlled template to traverse constructor.constructor to the JavaScript Function constructor.CRITICAL 9.8EPSS 0.64%13 August 2026
CVE-2026-73644OpenDJ is an LDAPv3 compliant directory service.CRITICAL 9.6EPSS 0.29%13 August 2026
CVE-2026-73567An attacker who can observe the process's Math.random() outputs and estimate the key-generation time can reconstruct the seed, recover generated SM2 private keys, and predict signing ephemeral scalars used to forge signatures.CRITICAL 9.1EPSS 0.32%13 August 2026
CVE-2026-67614CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port…CRITICAL 9.3EPSS 0.55%13 August 2026
CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)CRITICAL 9.1EPSS 0.27%13 August 2026
CVE-2026-58443Public-only repository tokens can update private PR head branchesCRITICAL 9.1EPSS 0.58%13 August 2026
CVE-2026-58433Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization settingCRITICAL 9.1EPSS 0.28%13 August 2026
CVE-2026-56750Gitea Remember-Me Token Theft Not Invalidating Attacker SessionCRITICAL 9.1EPSS 0.34%13 August 2026
CVE-2026-56654Privilege Escalation via Access Token Scope Escalation in APICRITICAL 9.8EPSS 0.42%13 August 2026
CVE-2026-56443Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118CRITICAL 9.6EPSS 0.36%13 August 2026
CVE-2026-55982OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token ScopesCRITICAL 9.1EPSS 0.37%13 August 2026
CVE-2026-13051Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs…CRITICAL 9.1EPSS 0.45%13 August 2026
CVE-2022-4993HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.…CRITICAL 9.1EPSS 0.49%13 August 2026
CVE-2026-73533Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server.CRITICAL 9.3EPSS 0.45%13 August 2026
CVE-2026-73532Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server.CRITICAL 9.3EPSS 0.46%13 August 2026
CVE-2026-70460rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options.CRITICAL 9.2EPSS 0.45%13 August 2026
CVE-2026-70452rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation.CRITICAL 9.1EPSS 0.46%13 August 2026
CVE-2026-53793rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./…CRITICAL 9.1EPSS 0.39%13 August 2026
CVE-2026-53791rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address.CRITICAL 9.1EPSS 0.50%13 August 2026
CVE-2026-53790rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon…CRITICAL 9.2EPSS 0.52%13 August 2026
CVE-2026-66691Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.CRITICAL 9.8EPSS 0.32%13 August 2026
CVE-2026-66478Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.CRITICAL 9.3EPSS 0.28%13 August 2026
CVE-2026-66472Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.CRITICAL 9.3EPSS 0.28%13 August 2026
CVE-2026-66465Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.CRITICAL 9.8EPSS 0.39%13 August 2026
CVE-2026-66458Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.CRITICAL 9.3EPSS 0.28%13 August 2026
CVE-2026-66453Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.CRITICAL 9.8EPSS 0.39%13 August 2026
CVE-2026-66446Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.CRITICAL 9.3EPSS 0.37%13 August 2026
CVE-2026-66436Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.CRITICAL 9.3EPSS 0.28%13 August 2026
CVE-2026-66424Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.CRITICAL 9.8EPSS 0.32%13 August 2026
CVE-2026-61969Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.CRITICAL 9.3EPSS 0.28%13 August 2026
CVE-2026-61967Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.CRITICAL 9.8EPSS 0.33%13 August 2026
CVE-2026-61966Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.CRITICAL 9.3EPSS 0.37%13 August 2026
CVE-2026-61962Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.CRITICAL 10.0EPSS 0.46%13 August 2026
CVE-2026-28185Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.CRITICAL 9.8EPSS 0.20%13 August 2026
CVE-2026-28149Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.CRITICAL 9.8EPSS 0.38%13 August 2026
CVE-2026-28148Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.CRITICAL 9.8EPSS 0.24%13 August 2026
CVE-2026-28142Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.CRITICAL 9.3EPSS 0.28%13 August 2026
CVE-2026-28008Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.CRITICAL 9.8EPSS 0.40%13 August 2026
CVE-2026-28001Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.CRITICAL 9.3EPSS 0.28%13 August 2026
CVE-2026-27544Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.CRITICAL 10.0EPSS 0.57%13 August 2026
CVE-2026-49827WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry.CRITICAL 9.8EPSS 0.48%13 August 2026
CVE-2026-73608SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint.CRITICAL 9.2EPSS 0.24%13 August 2026
CVE-2026-73602Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass.CRITICAL 9.0EPSS 0.84%13 August 2026
CVE-2026-73601Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command…CRITICAL 9.0EPSS 0.88%13 August 2026
CVE-2026-73487Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection.CRITICAL 9.0EPSS 0.96%13 August 2026
CVE-2026-73486Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code.CRITICAL 9.0EPSS 0.68%13 August 2026
CVE-2026-73485Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques.CRITICAL 9.0EPSS 0.63%13 August 2026
CVE-2026-73483An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the…CRITICAL 9.4EPSS 0.62%13 August 2026
CVE-2026-59507: Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).CRITICAL 9.3EPSS 0.24%13 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.