SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,247 results · page 65 of 785

CVESummaryPriorityPublished
CVE-2026-64303In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the…CRITICAL 9.8EPSS 0.69%25 July 2026
CVE-2026-64269In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the…CRITICAL 9.1EPSS 0.71%25 July 2026
CVE-2026-64268In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr +…CRITICAL 9.8EPSS 0.71%25 July 2026
CVE-2026-64257In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied…CRITICAL 9.1EPSS 0.66%25 July 2026
CVE-2026-16766Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.CRITICAL 9.8EPSS 1.42%25 July 2026
CVE-2026-16280An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB.CRITICAL 9.8EPSS 0.29%24 July 2026
CVE-2026-61884An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or…CRITICAL 9.3EPSS 0.45%24 July 2026
CVE-2026-48021In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys.CRITICAL 9.1EPSS 0.12%24 July 2026
CVE-2026-64232In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings…CRITICAL 9.8EPSS 0.46%24 July 2026
CVE-2026-64216In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to…CRITICAL 9.8EPSS 0.46%24 July 2026
CVE-2026-58630Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.46%24 July 2026
CVE-2026-58586Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp.CRITICAL 9.8EPSS 0.49%24 July 2026
CVE-2026-57106Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 0.48%24 July 2026
CVE-2026-56163Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.CRITICAL 10.0EPSS 0.49%24 July 2026
CVE-2026-12503Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group…CRITICAL 9.2EPSS 0.14%24 July 2026
CVE-2026-16634TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99.CRITICAL 9.8EPSS 0.51%24 July 2026
CVE-2026-24727An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary…CRITICAL 9.3EPSS 0.67%24 July 2026
CVE-2026-15704In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router.CRITICAL 9.8EPSS 0.37%24 July 2026
CVE-2026-12877The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.CRITICAL 9.1EPSS 0.25%24 July 2026
CVE-2026-62825Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.71%24 July 2026
CVE-2026-58275Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.71%24 July 2026
CVE-2026-56191Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.CRITICAL 10.0EPSS 0.76%24 July 2026
CVE-2026-56165Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.72%24 July 2026
CVE-2026-56160Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.CRITICAL 9.9EPSS 0.58%24 July 2026
CVE-2026-50517Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.CRITICAL 9.9EPSS 1.25%24 July 2026
CVE-2026-42933Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.CRITICAL 10.0EPSS 0.51%23 July 2026
CVE-2026-28698Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.CRITICAL 9.2EPSS 0.42%23 July 2026
CVE-2026-637329router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to…CRITICAL 9.4EPSS 1.01%23 July 2026
CVE-2025-71389Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input.CRITICAL 10.0EPSS 1.20%23 July 2026
CVE-2024-58355Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability.CRITICAL 9.3EPSS 0.41%23 July 2026
CVE-2024-58353Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>).CRITICAL 9.3EPSS 0.41%23 July 2026
CVE-2026-52439An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanismCRITICAL 9.8EPSS 0.52%23 July 2026
CVE-2026-49035The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request.CRITICAL 9.2EPSS 0.61%23 July 2026
CVE-2026-47724Combined with the per-operator CA model from ADR 0002, this gives any non-admin operator API key broad cross-tenant access — instant privilege escalation in the worst case.CRITICAL 9.9EPSS 0.48%23 July 2026
CVE-2026-15981The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4.CRITICAL 9.8EPSS 0.81%23 July 2026
CVE-2026-15967Insufficient session expiration vulnerability in Progress MOVEit Transfer.CRITICAL 9.8EPSS 0.20%23 July 2026
CVE-2026-15966Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.CRITICAL 9.8EPSS 0.20%23 July 2026
CVE-2026-15630A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).CRITICAL 9.9EPSS 0.34%23 July 2026
CVE-2026-10697Improper Authentication vulnerability in Progress MOVEit Transfer.CRITICAL 9.8EPSS 0.29%23 July 2026
CVE-2026-63359The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts,…CRITICAL 9.3EPSS 0.75%23 July 2026
CVE-2026-47670Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE).CRITICAL 9.4EPSS 1.71%23 July 2026
CVE-2026-47669A malicious ZIP with `../` entries writes files anywhere on the filesystem.CRITICAL 9.3EPSS 0.52%23 July 2026
CVE-2026-6516Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.CRITICAL 10.0EPSS 4.86%23 July 2026
CVE-2026-65701SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled…CRITICAL 9.3EPSS 0.69%23 July 2026
CVE-2026-65700h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in…CRITICAL 9.3EPSS 1.52%23 July 2026
CVE-2026-47752Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature.CRITICAL 9.9EPSS 0.52%23 July 2026
CVE-2026-47668In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands.CRITICAL 10.0EPSS 3.88%23 July 2026
CVE-2026-65761Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and…CRITICAL 9.3EPSS 0.93%23 July 2026
CVE-2026-65760Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.CRITICAL 9.2EPSS 0.42%23 July 2026
CVE-2026-15617Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.CRITICAL 9.1EPSS 0.36%23 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.