SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,246 results · page 50 of 785

CVESummaryPriorityPublished
CVE-2026-65768Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.63%11 August 2026
CVE-2026-62893Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 2.73%11 August 2026
CVE-2026-62878Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.26%11 August 2026
CVE-2026-62815Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.24%11 August 2026
CVE-2026-59124Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 1.68%11 August 2026
CVE-2026-57104Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.6EPSS 0.81%11 August 2026
CVE-2026-50516Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.4EPSS 0.84%11 August 2026
CVE-2026-48362ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 10.0EPSS 4.31%11 August 2026
CVE-2026-12571An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.CRITICAL 9.8EPSS 1.63%11 August 2026
CVE-2026-73080Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle.CRITICAL 9.3EPSS 0.38%11 August 2026
CVE-2026-73069Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id or the updateOneField GraphQL mutation, causing…CRITICAL 9.1EPSS 0.45%11 August 2026
CVE-2025-31114In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON.CRITICAL 9.3EPSS 0.67%11 August 2026
CVE-2026-72920Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey,…CRITICAL 9.8EPSS 0.41%11 August 2026
CVE-2026-47702An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or insider access) can extract all API tokens and impersonate any user without requiring a password or multi-factor authentication.CRITICAL 9.1EPSS 0.20%11 August 2026
CVE-2026-17061A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.CRITICAL 10.0EPSS 0.56%11 August 2026
CVE-2026-51584An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier…CRITICAL 9.8EPSS 0.42%11 August 2026
CVE-2026-48056Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges.CRITICAL 10.0EPSS 0.48%11 August 2026
CVE-2026-48046Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution.CRITICAL 9.3EPSS 0.35%11 August 2026
CVE-2026-46670Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full…CRITICAL 9.8EPSS 1.91%11 August 2026
CVE-2026-72785Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability.CRITICAL 9.3EPSS 0.19%11 August 2026
CVE-2026-58115A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed).CRITICAL 10.0EPSS 0.65%11 August 2026
CVE-2026-18972An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\".CRITICAL 9.6EPSS 6.06%11 August 2026
CVE-2026-72603An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field.CRITICAL 9.9EPSS 2.13%11 August 2026
CVE-2026-72599An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter.CRITICAL 9.8EPSS 0.34%11 August 2026
CVE-2026-72550An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter.CRITICAL 9.8EPSS 0.50%11 August 2026
CVE-2026-13738CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations.CRITICAL 9.2EPSS 0.63%11 August 2026
CVE-2026-13737CommServe contained an allowlist bypass vulnerability affecting command execution authorization.CRITICAL 9.2EPSS 0.52%11 August 2026
CVE-2026-58231SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.CRITICAL 10.0EPSS 1.71%11 August 2026
CVE-2026-10579A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role.CRITICAL 9.8EPSS 0.32%11 August 2026
CVE-2026-19516Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and read the responses, resulting in server-side request…CRITICAL 9.1EPSS 0.24%11 August 2026
CVE-2026-13716Path traversal in server import and admin file upload in Crafty Controller.CRITICAL 9.1EPSS 0.73%11 August 2026
CVE-2026-19425Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability.CRITICAL 9.3EPSS 0.47%11 August 2026
CVE-2026-44758SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation.CRITICAL 9.1EPSS 0.67%11 August 2026
CVE-2026-34265SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption.CRITICAL 9.8EPSS 0.57%11 August 2026
CVE-2026-48161Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on developer…CRITICAL 9.3EPSS 0.42%10 August 2026
CVE-2026-72911Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted globals including…CRITICAL 9.9EPSS 0.38%10 August 2026
CVE-2026-72904Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied JSON schemas in apps/api/src/lib/extract/helpers/dereference-schema.ts.CRITICAL 9.3EPSS 0.29%10 August 2026
CVE-2026-48160Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 through 949f1a3d6bb1ff7d1a0dec892afd773e742627e8 that executed remote attacker-controlled code on developer…CRITICAL 9.3EPSS 0.40%10 August 2026
CVE-2026-18948The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library.CRITICAL 9.9EPSS 0.74%10 August 2026
CVE-2026-14450This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim.CRITICAL 9.9EPSS 0.46%10 August 2026
CVE-2026-72902Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connected target server because registry.testRegistry and registry.testRegistryById in apps/dokploy/server/api/routers/registry.ts interpolate the…CRITICAL 9.9EPSS 0.54%10 August 2026
CVE-2026-72901Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.create and volumeBackup.runManually is interpolated without quoting in…CRITICAL 9.9EPSS 0.63%10 August 2026
CVE-2026-72886From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin host-schedule gate only in the alternative branch, allowing a…CRITICAL 9.9EPSS 0.46%10 August 2026
CVE-2026-72882In 0.28.8 and earlier, an authenticated user who can create or update file mounts for a service can inject shell metacharacters into filePath, causing Dokploy to execute attacker-controlled commands on the configured remote managed server over SSH.CRITICAL 9.9EPSS 0.36%10 August 2026
CVE-2026-72880An authenticated user with certificate create or delete permission can use certificatePath to write attacker-controlled certificate content outside the intended directory or delete an out-of-root directory.CRITICAL 9.9EPSS 0.30%10 August 2026
CVE-2026-72879An authenticated user with project access can configure malicious registry credentials and trigger a swarm deployment to execute arbitrary OS commands on the Dokploy server, read or modify host files, and access other containers through Docker.CRITICAL 9.4EPSS 0.35%10 August 2026
CVE-2026-72878Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by directly interpolating user-controlled database fields into bash -c "..." and sh -c "..." strings, then executes them via child_process.exec().CRITICAL 9.6EPSS 0.27%10 August 2026
CVE-2026-72877Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() in packages/server/src/utils/providers/docker.ts and is validated only as an optional string.CRITICAL 9.6EPSS 0.40%10 August 2026
CVE-2026-72876Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without an activeOrganizationId ownership check, and getNodeInfo in…CRITICAL 9.9EPSS 0.59%10 August 2026
CVE-2025-15681TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server.CRITICAL 9.2EPSS 0.48%10 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.