SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,246 results · page 57 of 785

CVESummaryPriorityPublished
CVE-2026-69110OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET…CRITICAL 9.3EPSS 0.55%4 August 2026
CVE-2026-69098kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field.CRITICAL 9.3EPSS 0.69%4 August 2026
CVE-2026-25289Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.CRITICAL 9.6EPSS 0.12%4 August 2026
CVE-2026-18801OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values.CRITICAL 9.3EPSS 0.23%4 August 2026
CVE-2026-69251Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts,…CRITICAL 9.0EPSS 3.27%4 August 2026
CVE-2026-61515Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface…CRITICAL 9.3EPSS 1.62%4 August 2026
CVE-2026-61514Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials.CRITICAL 9.3EPSS 0.46%4 August 2026
CVE-2026-60007In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted…CRITICAL 9.1EPSS 0.38%4 August 2026
CVE-2026-15721Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc.CRITICAL 9.8EPSS 0.17%4 August 2026
CVE-2026-14804Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc.CRITICAL 9.1EPSS 0.23%4 August 2026
CVE-2026-14175Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc.CRITICAL 9.8EPSS 0.29%4 August 2026
CVE-2026-18754Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.CRITICAL 9.1EPSS 0.31%4 August 2026
CVE-2026-18753Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.CRITICAL 9.1EPSS 0.31%4 August 2026
CVE-2026-64564In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (==…CRITICAL 9.8EPSS 1.48%4 August 2026
CVE-2026-16618The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated…CRITICAL 9.8EPSS 0.46%4 August 2026
CVE-2026-15958The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download…CRITICAL 9.3EPSS 0.20%4 August 2026
CVE-2026-66321Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.CRITICAL 9.6EPSS 0.55%4 August 2026
CVE-2026-48333Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.CRITICAL 9.8EPSS 0.48%3 August 2026
CVE-2026-48331Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation.CRITICAL 10.0EPSS 0.48%3 August 2026
CVE-2026-48330Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 10.0EPSS 0.69%3 August 2026
CVE-2026-48326Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.9EPSS 0.50%3 August 2026
CVE-2026-48323Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 10.0EPSS 0.70%3 August 2026
CVE-2026-48317Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.6EPSS 0.49%3 August 2026
CVE-2026-18667A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.CRITICAL 9.3EPSS 0.39%3 August 2026
CVE-2026-46713Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid.CRITICAL 9.2EPSS 0.17%3 August 2026
CVE-2026-69240Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle.CRITICAL 9.8EPSS 0.39%3 August 2026
CVE-2026-52102An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.CRITICAL 9.8EPSS 1.76%3 August 2026
CVE-2026-51775SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php componentCRITICAL 9.8EPSS 0.26%3 August 2026
CVE-2026-51190A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user runs "s init" with an attacker-controlled argument.CRITICAL 9.8EPSS 1.30%3 August 2026
CVE-2026-48063In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload.CRITICAL 9.3EPSS 0.16%3 August 2026
CVE-2026-67598Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS…CRITICAL 9.1EPSS 0.21%3 August 2026
CVE-2026-48031In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin roles, and completely bypass authentication on all…CRITICAL 9.1EPSS 0.44%3 August 2026
CVE-2026-38447An attacker can approximate the key generation time and brute-force the key space within a feasible time window.CRITICAL 9.8EPSS 0.46%3 August 2026
CVE-2026-41452Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With:…CRITICAL 9.3EPSS 2.45%3 August 2026
CVE-2026-39932OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP…CRITICAL 9.4EPSS 3.68%3 August 2026
CVE-2026-18248An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one.CRITICAL 9.1EPSS 0.21%3 August 2026
CVE-2026-9487XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the…CRITICAL 9.1EPSS 0.17%3 August 2026
CVE-2026-9390XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified.CRITICAL 9.1EPSS 0.29%3 August 2026
CVE-2026-69085SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding.CRITICAL 9.9EPSS 0.88%3 August 2026
CVE-2026-69084SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions.CRITICAL 9.9EPSS 1.10%3 August 2026
CVE-2026-69083SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens.CRITICAL 9.9EPSS 0.35%3 August 2026
CVE-2026-68587SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks.CRITICAL 9.2EPSS 0.24%3 August 2026
CVE-2026-68586SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc).CRITICAL 9.2EPSS 0.24%3 August 2026
CVE-2026-68584SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary…CRITICAL 9.2EPSS 0.31%3 August 2026
CVE-2026-64827Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from…CRITICAL 9.3EPSS 0.48%3 August 2026
CVE-2026-18108Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and returns…CRITICAL 9.8EPSS 0.22%3 August 2026
CVE-2026-2346Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc.CRITICAL 9.8EPSS 0.29%3 August 2026
CVE-2026-18574An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on…CRITICAL 9.3EPSS 0.99%3 August 2026
CVE-2026-33591A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.CRITICAL 10.0EPSS 0.52%3 August 2026
CVE-2026-18588A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628.CRITICAL 9.3EPSS 0.61%3 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.