SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,247 results · page 67 of 785

CVESummaryPriorityPublished
CVE-2026-16232Check Point SmartConsole Improper Authentication VulnerabilityKEVCRITICAL 9.3EPSS 72.1%22 July 2026
CVE-2026-8152Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack.CRITICAL 9.3EPSS 0.41%22 July 2026
CVE-2026-63048Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.CRITICAL 9.4EPSS 0.38%22 July 2026
CVE-2026-56820In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse`…CRITICAL 9.1EPSS 0.22%21 July 2026
CVE-2026-16424Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.28%21 July 2026
CVE-2026-16419Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.26%21 July 2026
CVE-2026-16416Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic.CRITICAL 9.3EPSS 0.14%21 July 2026
CVE-2026-8987Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint.CRITICAL 9.4EPSS 0.51%21 July 2026
CVE-2026-8986Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests.CRITICAL 9.5EPSS 2.29%21 July 2026
CVE-2026-8985Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002.CRITICAL 10.0EPSS 6.60%21 July 2026
CVE-2026-8984Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002.CRITICAL 10.0EPSS 0.77%21 July 2026
CVE-2026-65318Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the…CRITICAL 9.2EPSS 0.60%21 July 2026
CVE-2026-65317Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted…CRITICAL 9.2EPSS 0.64%21 July 2026
CVE-2026-62549Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).CRITICAL 9.6EPSS 0.28%21 July 2026
CVE-2026-62546Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities).CRITICAL 9.1EPSS 0.49%21 July 2026
CVE-2026-61245Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61244Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing).CRITICAL 9.1EPSS 0.43%21 July 2026
CVE-2026-61242Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-61239Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement).CRITICAL 9.9EPSS 0.37%21 July 2026
CVE-2026-61238Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement).CRITICAL 9.1EPSS 0.43%21 July 2026
CVE-2026-61237Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration).CRITICAL 9.9EPSS 0.38%21 July 2026
CVE-2026-61235Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland).CRITICAL 9.1EPSS 0.49%21 July 2026
CVE-2026-61233Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61223Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security).CRITICAL 9.0EPSS 0.39%21 July 2026
CVE-2026-61211Vulnerability in the RDBMS component of Oracle Database Server.CRITICAL 9.9EPSS 0.44%21 July 2026
CVE-2026-61209Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-61207Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status).CRITICAL 9.3EPSS 0.35%21 July 2026
CVE-2026-61204Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration).CRITICAL 9.0EPSS 0.18%21 July 2026
CVE-2026-61203Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses).CRITICAL 9.4EPSS 0.46%21 July 2026
CVE-2026-61201Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects).CRITICAL 9.0EPSS 0.39%21 July 2026
CVE-2026-61197Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).CRITICAL 9.1EPSS 0.43%21 July 2026
CVE-2026-61196Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61186Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).CRITICAL 9.4EPSS 0.41%21 July 2026
CVE-2026-61184Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).CRITICAL 9.1EPSS 0.43%21 July 2026
CVE-2026-61183Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61178Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61175Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).CRITICAL 9.3EPSS 0.44%21 July 2026
CVE-2026-61174Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).CRITICAL 9.0EPSS 0.19%21 July 2026
CVE-2026-61171Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).CRITICAL 9.1EPSS 0.43%21 July 2026
CVE-2026-61167Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61161Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61156Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).CRITICAL 9.1EPSS 0.43%21 July 2026
CVE-2026-61155Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).CRITICAL 9.1EPSS 0.49%21 July 2026
CVE-2026-61154Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61153Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).CRITICAL 9.1EPSS 0.43%21 July 2026
CVE-2026-61146Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).CRITICAL 9.9EPSS 0.43%21 July 2026
CVE-2026-61145Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61140Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).CRITICAL 9.8EPSS 0.48%21 July 2026
CVE-2026-61131Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-61130Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).CRITICAL 9.1EPSS 0.49%21 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.