SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,739 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,248 results · page 76 of 785

CVESummaryPriorityPublished
CVE-2026-9586Sangoma Switchvox SQL Injection VulnerabilityKEVCRITICAL 9.3EPSS 11.8%17 July 2026
CVE-2026-8297Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.CRITICAL 9.8EPSS 0.47%17 July 2026
CVE-2026-54496Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy…CRITICAL 9.3EPSS 0.32%17 July 2026
CVE-2026-12694Missing Authorization vulnerability in Vimesoft Inc.CRITICAL 9.1EPSS 0.44%17 July 2026
CVE-2026-12693Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc.CRITICAL 9.4EPSS 0.46%17 July 2026
CVE-2026-12692Unverified password change vulnerability in Vimesoft Inc.CRITICAL 9.8EPSS 0.64%17 July 2026
CVE-2026-60024Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.CRITICAL 9.8EPSS 0.55%17 July 2026
CVE-2026-51080libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.CRITICAL 9.8EPSS 0.52%17 July 2026
CVE-2024-23564HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response.CRITICAL 9.1EPSS 0.29%17 July 2026
CVE-2026-9810The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP…CRITICAL 9.8EPSS 0.50%17 July 2026
CVE-2026-15982The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4.CRITICAL 9.8EPSS 0.34%17 July 2026
CVE-2026-62241Because GET /api/v1/scans returns scan records containing userId values without authentication, a remote unauthenticated attacker can harvest a victim's userId, forge a valid HS256 cg_session cookie offline using the known secret, and call GET…CRITICAL 9.3EPSS 6.55%17 July 2026
CVE-2026-62232Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window.CRITICAL 9.1EPSS 0.45%17 July 2026
CVE-2026-14956The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6.CRITICAL 9.8EPSS 0.35%17 July 2026
CVE-2026-44182Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm.CRITICAL 10.0EPSS 0.50%16 July 2026
CVE-2026-44181Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm.CRITICAL 10.0EPSS 0.70%16 July 2026
CVE-2026-57075YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.CRITICAL 9.1EPSS 0.37%16 July 2026
CVE-2026-53412Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.CRITICAL 9.8EPSS 0.65%16 July 2026
CVE-2026-44180Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm.CRITICAL 9.8EPSS 0.55%16 July 2026
CVE-2026-38158A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.CRITICAL 9.8EPSS 0.50%16 July 2026
CVE-2026-63089WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of at…CRITICAL 9.0EPSS 0.41%16 July 2026
CVE-2026-15422Since this lookup runs during packet classification (i.e. before SCTP integrity checks or IPsec policy are applied) a remote, unauthenticated attacker can send a crafted SCTP INIT ACK packet with malformed address parameters to cause an out-of-bounds…CRITICAL 9.1EPSS 0.88%16 July 2026
CVE-2026-46515Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup_status, fm_whos_calling, fm_run_saved_query, and fm_diagnose_trunk, exposing AMI manager secrets, outbound dial…CRITICAL 9.3EPSS 0.57%16 July 2026
CVE-2026-46512Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/DialplanApply.php wrote Dialplan/Templates.php output to extensions_custom.conf while only Dialplan/TemplateBase.php:38-42…CRITICAL 9.9EPSS 0.65%16 July 2026
CVE-2026-45336In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session cookies, allowing unauthenticated attackers who know the public source value to forge cookies containing role=admin and user_id values and bypass authentication.CRITICAL 10.0EPSS 0.62%16 July 2026
CVE-2026-63087Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id…CRITICAL 9.3EPSS 0.71%16 July 2026
CVE-2026-57074Truncated strings such as "<a/" can trigger an out-of-bounds read.CRITICAL 9.1EPSS 0.39%16 July 2026
CVE-2026-57073Truncated strings such as "<a/" can trigger an out-of-bounds read.CRITICAL 9.1EPSS 0.65%16 July 2026
CVE-2026-46621Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an authenticated user…CRITICAL 9.1EPSS 1.12%16 July 2026
CVE-2026-46562Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the…CRITICAL 9.8EPSS 0.98%16 July 2026
CVE-2026-45568Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target host and causing requests.request to return a…CRITICAL 9.9EPSS 0.54%16 July 2026
CVE-2026-44632Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the…CRITICAL 9.1EPSS 1.12%16 July 2026
CVE-2026-44596Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote…EXPLOITCRITICAL 9.8EPSS 2.06%16 July 2026
CVE-2026-3031Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library.CRITICAL 9.8EPSS 0.70%16 July 2026
CVE-2026-59866Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate`…CRITICAL 9.3EPSS 1.35%16 July 2026
CVE-2026-59865Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended…CRITICAL 9.3EPSS 4.36%16 July 2026
CVE-2026-59864Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin…CRITICAL 9.3EPSS 1.33%16 July 2026
CVE-2026-54733Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an…CRITICAL 9.3EPSS 0.88%16 July 2026
CVE-2026-45695Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments…CRITICAL 9.8EPSS 1.61%16 July 2026
CVE-2026-14890SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in…CRITICAL 9.1EPSS 1.00%16 July 2026
CVE-2026-56453HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.CRITICAL 9.8EPSS 0.35%16 July 2026
CVE-2026-63306stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation.CRITICAL 9.2EPSS 0.41%16 July 2026
CVE-2026-63305AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping.CRITICAL 9.2EPSS 2.46%16 July 2026
CVE-2026-63304AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping.CRITICAL 9.2EPSS 2.46%16 July 2026
CVE-2026-11386An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).CRITICAL 9.0EPSS 0.53%16 July 2026
CVE-2023-49900An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.CRITICAL 9.8EPSS 0.96%16 July 2026
CVE-2023-49899An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.CRITICAL 9.8EPSS 0.31%16 July 2026
CVE-2026-22752Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.CRITICAL 9.6EPSS 0.48%16 July 2026
CVE-2026-15925Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector.CRITICAL 9.2EPSS 0.29%16 July 2026
CVE-2026-12492The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any…CRITICAL 9.8EPSS 0.50%16 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.