SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,248 results · page 71 of 785

CVESummaryPriorityPublished
CVE-2026-60205Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60204Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60202Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60200Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60199Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60198Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60197Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60173Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-60168Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS).CRITICAL 9.1EPSS 0.45%21 July 2026
CVE-2026-47731In versions prior to 2.6.1 and in version 3.1.0, the Binary Stream Capture (BSC) component exposes an unauthenticated HTTP API for dynamically creating packet capture "handlers." Because the code blindly trusts path‑related form fields, a remote client…CRITICAL 9.1EPSS 0.86%21 July 2026
CVE-2026-47056Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service).CRITICAL 10.0EPSS 0.51%21 July 2026
CVE-2026-47040Vulnerability in the Oracle Net Services component of Oracle Database Server.CRITICAL 9.1EPSS 0.47%21 July 2026
CVE-2026-47036Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-46994Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen).CRITICAL 9.8EPSS 0.36%21 July 2026
CVE-2026-46989Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework).CRITICAL 9.1EPSS 0.24%21 July 2026
CVE-2026-46983Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-46982Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal).CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-46924Vulnerability in Oracle Application Testing Suite.CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-46876Vulnerability in Oracle Application Testing Suite.CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-35290Vulnerability in Oracle Application Testing Suite.CRITICAL 9.8EPSS 0.51%21 July 2026
CVE-2026-8983Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints.CRITICAL 10.0EPSS 0.43%21 July 2026
CVE-2026-8982The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.CRITICAL 10.0EPSS 0.38%21 July 2026
CVE-2026-65057Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint.CRITICAL 9.2EPSS 0.43%21 July 2026
CVE-2026-52472SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml fileCRITICAL 9.8EPSS 0.56%21 July 2026
CVE-2026-52470SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml fileCRITICAL 9.8EPSS 0.56%21 July 2026
CVE-2026-52469SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml fileCRITICAL 9.8EPSS 0.56%21 July 2026
CVE-2026-47708An attacker can inject arbitrary Stata commands (including `shell`, `python`, `erase`, etc.) by crafting a malicious `log_file_name` containing quotes, newlines, or Stata command separators.CRITICAL 9.3EPSS 0.53%21 July 2026
CVE-2026-30631An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.CRITICAL 9.8EPSS 0.73%21 July 2026
CVE-2026-64879A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.CRITICAL 9.4EPSS 2.26%21 July 2026
CVE-2026-64878Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.CRITICAL 9.4EPSS 0.80%21 July 2026
CVE-2026-59147Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find.CRITICAL 9.8EPSS 0.55%21 July 2026
CVE-2026-59145Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find.CRITICAL 9.1EPSS 0.54%21 July 2026
CVE-2026-59144Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq.CRITICAL 9.8EPSS 0.60%21 July 2026
CVE-2026-50755An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header valueCRITICAL 9.8EPSS 0.62%21 July 2026
CVE-2026-64877An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.CRITICAL 9.4EPSS 0.32%21 July 2026
CVE-2026-59142Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy.CRITICAL 9.1EPSS 0.54%21 July 2026
CVE-2026-59141Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked.CRITICAL 9.1EPSS 0.54%21 July 2026
CVE-2026-59140Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths.CRITICAL 9.1EPSS 0.54%21 July 2026
CVE-2026-59139Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked.CRITICAL 9.1EPSS 0.54%21 July 2026
CVE-2016-20096Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint.CRITICAL 9.3EPSS 0.67%21 July 2026
CVE-2026-47416Versions prior to 0.1.4 are vulnerable to vertical privilege escalation.CRITICAL 9.6EPSS 0.36%21 July 2026
CVE-2026-47413Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection.CRITICAL 9.6EPSS 0.36%21 July 2026
CVE-2026-47410Versions prior to 0.1.4 have an insecure default cryptographic key.CRITICAL 9.8EPSS 0.64%21 July 2026
CVE-2026-47407Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_member(workspace_id)` FastAPI dependency.CRITICAL 9.4EPSS 0.41%21 July 2026
CVE-2026-64825Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window.CRITICAL 9.0EPSS 0.58%21 July 2026
CVE-2026-64824Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a…CRITICAL 9.3EPSS 0.80%21 July 2026
CVE-2026-47396Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured.CRITICAL 9.8EPSS 0.64%21 July 2026
CVE-2026-47393Users who follow the documented quickstart (`praisonai deploy --type api`) get a server that binds to `0.0.0.0` per the recommended sample YAML, exposes `/chat` and `/agents` endpoints, runs `praisonai.run()` on user-supplied JSON input — LLM…CRITICAL 9.8EPSS 0.78%21 July 2026
CVE-2026-47392Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real…CRITICAL 9.9EPSS 0.88%21 July 2026
CVE-2026-47391Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` tool implemented with Python `eval()`.CRITICAL 9.8EPSS 1.17%21 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.