SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,246 results · page 58 of 785

CVESummaryPriorityPublished
CVE-2026-16534The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator…CRITICAL 9.1EPSS 0.23%3 August 2026
CVE-2026-16532The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.CRITICAL 9.1EPSS 0.26%3 August 2026
CVE-2026-16300The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.CRITICAL 9.8EPSS 0.30%3 August 2026
CVE-2026-16250The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading…CRITICAL 9.8EPSS 0.51%3 August 2026
CVE-2026-16060The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public…CRITICAL 9.8EPSS 0.46%3 August 2026
CVE-2026-15930The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary…CRITICAL 9.4EPSS 0.25%3 August 2026
CVE-2026-14557The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by…CRITICAL 9.1EPSS 0.39%3 August 2026
CVE-2026-12965The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.CRITICAL 9.1EPSS 0.35%3 August 2026
CVE-2026-12872The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including…CRITICAL 9.8EPSS 0.75%3 August 2026
CVE-2026-58062In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate.CRITICAL 9.3EPSS 0.34%3 August 2026
CVE-2026-8763In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI.CRITICAL 9.3EPSS 0.43%3 August 2026
CVE-2026-59650In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value.CRITICAL 9.3EPSS 0.27%3 August 2026
CVE-2026-59638In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.CRITICAL 9.3EPSS 0.21%3 August 2026
CVE-2026-65321PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the…CRITICAL 9.3EPSS 0.98%2 August 2026
CVE-2026-68582Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks).CRITICAL 9.3EPSS 0.27%2 August 2026
CVE-2025-71401better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset).CRITICAL 9.3EPSS 0.26%2 August 2026
CVE-2026-16256The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing…CRITICAL 9.8EPSS 0.30%2 August 2026
CVE-2026-8457The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7.CRITICAL 9.8EPSS 0.44%2 August 2026
CVE-2026-67342ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions.CRITICAL 9.3EPSS 0.32%1 August 2026
CVE-2026-67341ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js.CRITICAL 9.3EPSS 0.32%1 August 2026
CVE-2026-67336better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default.CRITICAL 9.4EPSS 0.16%1 August 2026
CVE-2026-67330@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass.CRITICAL 9.4EPSS 0.35%1 August 2026
CVE-2026-67324GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate.CRITICAL 9.3EPSS 0.38%1 August 2026
CVE-2026-67308Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files.CRITICAL 9.3EPSS 0.54%1 August 2026
CVE-2026-67305FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer.CRITICAL 9.4EPSS 0.55%1 August 2026
CVE-2026-67294FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication.CRITICAL 9.3EPSS 0.27%1 August 2026
CVE-2026-67293FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability.CRITICAL 9.3EPSS 0.17%1 August 2026
CVE-2026-67292FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c).CRITICAL 9.3EPSS 0.33%1 August 2026
CVE-2026-67289A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.CRITICAL 9.3EPSS 0.40%1 August 2026
CVE-2026-66402FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names().CRITICAL 9.3EPSS 0.29%1 August 2026
CVE-2026-15964The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0.CRITICAL 9.8EPSS 0.63%1 August 2026
CVE-2026-13596The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.CRITICAL 9.1EPSS 0.26%1 August 2026
CVE-2026-3141The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the…CRITICAL 9.1EPSS 0.56%1 August 2026
CVE-2026-68771ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization.CRITICAL 9.3EPSS 0.78%31 July 2026
CVE-2026-52134An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.CRITICAL 9.8EPSS 0.63%31 July 2026
CVE-2026-68770sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard…CRITICAL 9.3EPSS 0.65%31 July 2026
CVE-2026-51785An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted requestCRITICAL 9.8EPSS 0.66%31 July 2026
CVE-2026-38713TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the ipsec_conn interface.CRITICAL 9.8EPSS 2.62%31 July 2026
CVE-2026-38708TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.setclock interface.CRITICAL 9.8EPSS 2.62%31 July 2026
CVE-2025-69948SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.CRITICAL 9.8EPSS 0.31%31 July 2026
CVE-2025-69946SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id.CRITICAL 9.8EPSS 0.34%31 July 2026
CVE-2026-38711TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.upgrade_check interface.CRITICAL 9.8EPSS 2.62%31 July 2026
CVE-2026-54725vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible.CRITICAL 9.6EPSS 0.41%31 July 2026
CVE-2026-67822Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint.CRITICAL 9.8EPSS 0.31%31 July 2026
CVE-2026-58048Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.CRITICAL 9.4EPSS 0.97%31 July 2026
CVE-2026-52855Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration.CRITICAL 9.9EPSS 0.29%31 July 2026
CVE-2026-17566To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission) validated the query with a hand-written…CRITICAL 9.4EPSS 0.56%31 July 2026
CVE-2026-17351The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ…CRITICAL 9.4EPSS 0.41%31 July 2026
CVE-2026-17349/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared,…CRITICAL 9.3EPSS 0.31%31 July 2026
CVE-2026-16504Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.CRITICAL 9.8EPSS 0.35%31 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.