SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,674 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,246 results · page 55 of 785

CVESummaryPriorityPublished
CVE-2026-68079In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality.CRITICAL 9.8EPSS 0.40%6 August 2026
CVE-2026-65583Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens.CRITICAL 9.1EPSS 0.26%6 August 2026
CVE-2026-63687Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters.CRITICAL 9.1EPSS 0.27%6 August 2026
CVE-2026-61466In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist.CRITICAL 9.1EPSS 0.42%6 August 2026
CVE-2026-66909Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place.CRITICAL 9.8EPSS 0.67%6 August 2026
CVE-2026-64597In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer.CRITICAL 9.8EPSS 0.36%6 August 2026
CVE-2026-5430This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.CRITICAL 10.0EPSS 0.32%6 August 2026
CVE-2026-1728Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.CRITICAL 9.8EPSS 0.30%6 August 2026
CVE-2025-15039This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.CRITICAL 9.4EPSS 0.40%6 August 2026
CVE-2026-16054The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete…CRITICAL 9.1EPSS 0.27%6 August 2026
CVE-2026-12713The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.CRITICAL 9.1EPSS 0.26%6 August 2026
CVE-2026-67873A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path.CRITICAL 9.8EPSS 0.40%6 August 2026
CVE-2026-67870A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.CRITICAL 9.8EPSS 0.57%6 August 2026
CVE-2026-67531Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own property, the ECMAScript Proxy invariants force the security…CRITICAL 9.3EPSS 0.57%6 August 2026
CVE-2026-52466Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control.CRITICAL 9.8EPSS 0.27%6 August 2026
CVE-2026-71319Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin.CRITICAL 9.6EPSS 0.36%5 August 2026
CVE-2025-63823My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.CRITICAL 9.8EPSS 0.44%5 August 2026
CVE-2026-9205IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.CRITICAL 9.8EPSS 0.23%5 August 2026
CVE-2026-8470The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.CRITICAL 9.1EPSS 0.11%5 August 2026
CVE-2026-48168In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation.CRITICAL 10.0EPSS 0.91%5 August 2026
CVE-2026-70426In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization…CRITICAL 9.0EPSS 0.31%5 August 2026
CVE-2026-20310This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.CRITICAL 9.1EPSS 0.41%5 August 2026
CVE-2026-20304This review resulted in a software hardening release that address multiple internally discovered vulnerabilities.CRITICAL 9.9EPSS 0.28%5 August 2026
CVE-2026-20303This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.CRITICAL 9.9EPSS 0.32%5 August 2026
CVE-2026-20272This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.CRITICAL 9.8EPSS 0.41%5 August 2026
CVE-2026-20267This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.CRITICAL 9.0EPSS 0.26%5 August 2026
CVE-2026-17617IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.CRITICAL 9.8EPSS 0.23%5 August 2026
CVE-2026-9195A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's…CRITICAL 9.3EPSS 0.44%5 August 2026
CVE-2026-9193An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations…CRITICAL 9.9EPSS 0.31%5 August 2026
CVE-2026-9192An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known…CRITICAL 9.8EPSS 0.52%5 August 2026
CVE-2026-9190An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials.CRITICAL 9.1EPSS 0.43%5 August 2026
CVE-2026-8709An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged…CRITICAL 9.9EPSS 0.31%5 August 2026
CVE-2026-8400IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of…CRITICAL 9.8EPSS 0.27%5 August 2026
CVE-2026-7557An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user,…CRITICAL 9.1EPSS 0.32%5 August 2026
CVE-2026-7329An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator.CRITICAL 9.9EPSS 0.37%5 August 2026
CVE-2026-60053Insufficient Session Expiration vulnerability in Apache Answer.CRITICAL 9.1EPSS 0.35%5 August 2026
CVE-2026-39923Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint.CRITICAL 9.2EPSS 0.26%5 August 2026
CVE-2026-16442This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.CRITICAL 9.8EPSS 0.20%5 August 2026
CVE-2026-15587Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.CRITICAL 9.4EPSS 0.16%5 August 2026
CVE-2026-10025IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability.CRITICAL 9.8EPSS 0.35%5 August 2026
CVE-2026-16443This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.CRITICAL 9.1EPSS 0.18%5 August 2026
CVE-2026-71289The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN,…CRITICAL 9.8EPSS 0.45%5 August 2026
CVE-2026-71278rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field.CRITICAL 9.8EPSS 0.36%5 August 2026
CVE-2026-71277Any request carrying an arbitrary non-empty Authorization header (e.g. ) satisfies the guard, granting access to every endpoint protected only by this request guard.CRITICAL 9.1EPSS 0.24%5 August 2026
CVE-2026-71268OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content to with no validation that file_path stays within the ./core directory.CRITICAL 9.9EPSS 0.36%5 August 2026
CVE-2026-71267microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than…CRITICAL 9.8EPSS 0.31%5 August 2026
CVE-2026-71263The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c).CRITICAL 9.1EPSS 0.28%5 August 2026
CVE-2026-71262IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in…CRITICAL 9.8EPSS 0.35%5 August 2026
CVE-2026-71256nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_device_identification_res in nanomodbus.c.CRITICAL 9.8EPSS 0.31%5 August 2026
CVE-2026-71254nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in nanomodbus.c.CRITICAL 9.8EPSS 0.31%5 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.