SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,247 results · page 62 of 785

CVESummaryPriorityPublished
CVE-2026-14900The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function.CRITICAL 9.8EPSS 0.69%29 July 2026
CVE-2026-14488The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0.CRITICAL 9.1EPSS 0.31%29 July 2026
CVE-2026-59243The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an…CRITICAL 9.8EPSS 0.45%29 July 2026
CVE-2026-58179The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.CRITICAL 9.2EPSS 0.37%29 July 2026
CVE-2026-58161Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.CRITICAL 9.2EPSS 0.44%29 July 2026
CVE-2025-10656The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function.CRITICAL 9.8EPSS 0.36%29 July 2026
CVE-2026-58155Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.CRITICAL 9.2EPSS 0.40%29 July 2026
CVE-2026-58154Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.CRITICAL 9.2EPSS 0.40%29 July 2026
CVE-2026-18191VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.CRITICAL 9.3EPSS 0.38%29 July 2026
CVE-2026-63234A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location,…CRITICAL 9.9EPSS 0.29%29 July 2026
CVE-2026-63233A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location,…CRITICAL 9.9EPSS 0.29%29 July 2026
CVE-2026-63232A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location,…CRITICAL 9.9EPSS 0.29%29 July 2026
CVE-2026-63230A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account…CRITICAL 9.1EPSS 0.30%29 July 2026
CVE-2026-63229A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information,…CRITICAL 9.1EPSS 0.30%29 July 2026
CVE-2026-63227An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.CRITICAL 9.9EPSS 0.33%29 July 2026
CVE-2026-13423The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing…CRITICAL 9.8EPSS 0.54%29 July 2026
CVE-2026-18072The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7.CRITICAL 9.8EPSS 3.23%29 July 2026
CVE-2026-64863Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T.CRITICAL 9.1EPSS 0.36%28 July 2026
CVE-2026-62325From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access.CRITICAL 9.1EPSS 0.34%28 July 2026
CVE-2026-54658Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and…CRITICAL 9.8EPSS 0.46%28 July 2026
CVE-2026-6881A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.CRITICAL 9.4EPSS 0.20%28 July 2026
CVE-2026-14976IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.CRITICAL 9.8EPSS 0.30%28 July 2026
CVE-2026-14974IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.CRITICAL 9.8EPSS 0.38%28 July 2026
CVE-2026-14973IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.CRITICAL 9.3EPSS 0.30%28 July 2026
CVE-2026-14512IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.CRITICAL 9.8EPSS 0.57%28 July 2026
CVE-2026-14446IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.CRITICAL 9.8EPSS 0.33%28 July 2026
CVE-2026-16184IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.CRITICAL 9.8EPSS 0.32%28 July 2026
CVE-2026-50737When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber.CRITICAL 9.0EPSS 0.24%28 July 2026
CVE-2026-50736The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL…CRITICAL 9.0EPSS 0.24%28 July 2026
CVE-2026-16498The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users.CRITICAL 10.0EPSS 0.46%28 July 2026
CVE-2026-67174Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities.CRITICAL 9.2EPSS 0.39%28 July 2026
CVE-2026-66713Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) allows an…CRITICAL 9.8EPSS 1.03%28 July 2026
CVE-2026-65880Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.CRITICAL 10.0EPSS 0.46%28 July 2026
CVE-2026-16462This allows a remote unauthenticated attacker to execute arbitrary SQL commands.CRITICAL 9.3EPSS 0.48%28 July 2026
CVE-2026-11841An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions.CRITICAL 9.4EPSS 0.49%28 July 2026
CVE-2026-15014The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter.CRITICAL 9.8EPSS 0.46%28 July 2026
CVE-2026-11756A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.CRITICAL 10.0EPSS 0.45%28 July 2026
CVE-2026-14545The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an…CRITICAL 9.8EPSS 0.29%28 July 2026
CVE-2021-32088This protection can be bypassed by removing the kboxid cookie.CRITICAL 9.8EPSS 0.29%27 July 2026
CVE-2021-32086It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases.CRITICAL 9.8EPSS 0.19%27 July 2026
CVE-2021-32084If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.CRITICAL 9.8EPSS 0.33%27 July 2026
CVE-2026-66824A stored cross-site scripting vulnerability existed in the capture tree visualization page.CRITICAL 9.2EPSS 0.28%27 July 2026
CVE-2026-64775A memory initialization issue was addressed with improved memory handling.CRITICAL 9.8EPSS 0.56%27 July 2026
CVE-2026-64774An integer overflow was addressed with improved input validation.CRITICAL 9.8EPSS 0.65%27 July 2026
CVE-2026-64772An out-of-bounds write issue was addressed with improved input validation.CRITICAL 9.8EPSS 0.63%27 July 2026
CVE-2026-64771A buffer overflow was addressed with improved bounds checking.CRITICAL 9.8EPSS 0.70%27 July 2026
CVE-2026-64770An out-of-bounds write issue was addressed with improved bounds checking.CRITICAL 9.8EPSS 0.65%27 July 2026
CVE-2026-64769An out-of-bounds write issue was addressed with improved bounds checking.CRITICAL 9.8EPSS 0.65%27 July 2026
CVE-2026-64767A buffer overflow was addressed with improved bounds checking.CRITICAL 9.8EPSS 0.68%27 July 2026
CVE-2026-64762An out-of-bounds read was addressed with improved bounds checking.CRITICAL 9.8EPSS 0.53%27 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.