SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,716 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,248 results · page 72 of 785

CVESummaryPriorityPublished
CVE-2026-28321SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root.CRITICAL 9.1EPSS 0.58%21 July 2026
CVE-2026-28317SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation.CRITICAL 9.1EPSS 0.50%21 July 2026
CVE-2026-28316SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user.CRITICAL 9.1EPSS 2.13%21 July 2026
CVE-2026-28314SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover.CRITICAL 9.1EPSS 0.62%21 July 2026
CVE-2026-28313SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover.CRITICAL 9.1EPSS 0.50%21 July 2026
CVE-2026-28312SolarWinds Serv-U is affected by a privilege escalation vulnerability.CRITICAL 9.1EPSS 0.58%21 July 2026
CVE-2026-28310SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator.CRITICAL 9.1EPSS 0.50%21 July 2026
CVE-2026-28309SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts.CRITICAL 9.1EPSS 0.50%21 July 2026
CVE-2026-28308SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution.CRITICAL 9.1EPSS 0.79%21 July 2026
CVE-2026-28307SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group.CRITICAL 9.1EPSS 0.50%21 July 2026
CVE-2026-28306SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator.CRITICAL 9.1EPSS 0.50%21 July 2026
CVE-2026-28305SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root.CRITICAL 9.1EPSS 0.79%21 July 2026
CVE-2026-28304SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root.CRITICAL 9.1EPSS 0.79%21 July 2026
CVE-2026-28302SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root.CRITICAL 9.1EPSS 0.72%21 July 2026
CVE-2026-65048Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without…CRITICAL 9.3EPSS 0.54%21 July 2026
CVE-2025-66390In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even…CRITICAL 9.8EPSS 0.64%21 July 2026
CVE-2026-16412Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.52%21 July 2026
CVE-2026-16411Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.49%21 July 2026
CVE-2026-16410This vulnerability was fixed in Firefox 153 and Thunderbird 153.CRITICAL 9.8EPSS 0.30%21 July 2026
CVE-2026-16408Integer overflow in the Audio/Video: Playback component.CRITICAL 9.8EPSS 0.43%21 July 2026
CVE-2026-16407Mitigation bypass in the DOM: Service Workers component.CRITICAL 9.8EPSS 0.28%21 July 2026
CVE-2026-16406Mitigation bypass in the Networking component.CRITICAL 9.1EPSS 0.25%21 July 2026
CVE-2026-16402Integer overflow in the Graphics: ImageLib component.CRITICAL 9.8EPSS 0.34%21 July 2026
CVE-2026-16395Integer overflow in the Audio/Video component.CRITICAL 9.8EPSS 0.34%21 July 2026
CVE-2026-16394Mitigation bypass in the DOM: Security component.CRITICAL 9.1EPSS 0.25%21 July 2026
CVE-2026-16393This vulnerability was fixed in Firefox 153 and Thunderbird 153.CRITICAL 9.1EPSS 0.30%21 July 2026
CVE-2026-16392This vulnerability was fixed in Firefox 153 and Thunderbird 153.CRITICAL 9.1EPSS 0.36%21 July 2026
CVE-2026-16390Mitigation bypass in the Enterprise Policies component.CRITICAL 9.1EPSS 0.32%21 July 2026
CVE-2026-16389Incorrect boundary conditions, integer overflow in the Libraries component in NSS.CRITICAL 9.8EPSS 0.56%21 July 2026
CVE-2026-16388This vulnerability was fixed in Firefox 153 and Thunderbird 153.CRITICAL 9.8EPSS 0.38%21 July 2026
CVE-2026-16387This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.CRITICAL 9.8EPSS 0.20%21 July 2026
CVE-2026-16383Mitigation bypass in the DOM: Networking component.CRITICAL 9.8EPSS 0.39%21 July 2026
CVE-2026-16382Mitigation bypass in the DOM: Service Workers component.CRITICAL 9.8EPSS 0.38%21 July 2026
CVE-2026-16381Same-origin policy bypass in the Networking: DNS component.CRITICAL 9.1EPSS 0.17%21 July 2026
CVE-2026-16380Mitigation bypass in the Networking component.CRITICAL 9.1EPSS 0.31%21 July 2026
CVE-2026-16377Mitigation bypass in the PDF Viewer component.CRITICAL 9.8EPSS 0.39%21 July 2026
CVE-2026-16375This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.CRITICAL 9.8EPSS 0.21%21 July 2026
CVE-2026-16370Mitigation bypass in the DOM: Networking component.CRITICAL 9.1EPSS 0.31%21 July 2026
CVE-2026-16369Integer overflow in the JavaScript: WebAssembly component.CRITICAL 9.8EPSS 0.44%21 July 2026
CVE-2026-16368This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.CRITICAL 9.8EPSS 0.39%21 July 2026
CVE-2026-16367This vulnerability was fixed in Firefox 153 and Thunderbird 153.CRITICAL 10.0EPSS 0.38%21 July 2026
CVE-2026-16364This vulnerability was fixed in Firefox 153 and Thunderbird 153.CRITICAL 9.1EPSS 0.31%21 July 2026
CVE-2026-16363This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.CRITICAL 9.8EPSS 0.44%21 July 2026
CVE-2026-16361Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.32%21 July 2026
CVE-2026-16360Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.47%21 July 2026
CVE-2026-16359This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.CRITICAL 9.1EPSS 0.26%21 July 2026
CVE-2026-16358This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.CRITICAL 9.8EPSS 0.22%21 July 2026
CVE-2026-16357This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.CRITICAL 9.8EPSS 0.40%21 July 2026
CVE-2026-16356Sandbox escape due to use-after-free in the Disability Access APIs component.CRITICAL 9.8EPSS 0.39%21 July 2026
CVE-2026-16355This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.CRITICAL 9.8EPSS 0.40%21 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.