SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,255 results · page 79 of 786

CVESummaryPriorityPublished
CVE-2026-49798Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.CRITICAL 9.3EPSS 0.36%14 July 2026
CVE-2026-49181Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 1.17%14 July 2026
CVE-2026-49172Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.97%14 July 2026
CVE-2026-49164Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.79%14 July 2026
CVE-2026-48561Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.CRITICAL 9.6EPSS 0.86%14 July 2026
CVE-2026-42990Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.97%14 July 2026
CVE-2026-62644In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.CRITICAL 9.8EPSS 0.50%14 July 2026
CVE-2026-62643In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.CRITICAL 10.0EPSS 0.25%14 July 2026
CVE-2026-60082DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.CRITICAL 9.1EPSS 0.39%14 July 2026
CVE-2026-59836A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>CRITICAL 9.8EPSS 0.22%14 July 2026
CVE-2026-55954Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims.CRITICAL 9.1EPSS 0.70%14 July 2026
CVE-2025-11698A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072.CRITICAL 9.2EPSS 0.43%14 July 2026
CVE-2026-58479Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands…CRITICAL 9.2EPSS 4.40%14 July 2026
CVE-2026-15265A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.CRITICAL 9.4EPSS 0.56%14 July 2026
CVE-2026-10672The Firmware-Update object stores the server-supplied Package URI (/5/0/1) in a 255-byte buffer, so a LwM2M management server (or an on-path attacker on a session lacking strong DTLS) can WRITE a URI of 128-254 characters; only the first 128 bytes are…CRITICAL 9.1EPSS 0.40%14 July 2026
CVE-2025-12012A denial-of-service issue exists in 5380/5480/5580 controllers.CRITICAL 9.2EPSS 0.43%14 July 2026
CVE-2025-12011A denial-of-service issue exists in 5370/5570 controllers.CRITICAL 9.2EPSS 0.43%14 July 2026
CVE-2026-62392Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin.CRITICAL 9.8EPSS 2.48%14 July 2026
CVE-2026-62390Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin.CRITICAL 9.8EPSS 0.69%14 July 2026
CVE-2026-10577The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands.CRITICAL 10.0EPSS 0.41%14 July 2026
CVE-2026-62422In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possibleCRITICAL 9.8EPSS 0.33%14 July 2026
CVE-2026-58319An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service.CRITICAL 9.1EPSS 0.75%14 July 2026
CVE-2026-56451A vulnerability has been identified in Opcenter X (All versions < V2604).CRITICAL 10.0EPSS 0.50%14 July 2026
CVE-2026-15043DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text.CRITICAL 9.8EPSS 0.39%14 July 2026
CVE-2026-59084Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.CRITICAL 9.1EPSS 0.51%14 July 2026
CVE-2026-59083Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.CRITICAL 9.1EPSS 0.37%14 July 2026
CVE-2026-57898In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API.CRITICAL 9.0EPSS 0.68%14 July 2026
CVE-2026-15183Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY…CRITICAL 9.2EPSS 0.31%14 July 2026
CVE-2026-11563The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary…CRITICAL 9.6EPSS 0.25%14 July 2026
CVE-2026-44761If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data.CRITICAL 9.1EPSS 0.50%14 July 2026
CVE-2026-44747SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability.CRITICAL 9.9EPSS 0.56%14 July 2026
CVE-2026-27690Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization.CRITICAL 9.1EPSS 0.68%14 July 2026
CVE-2026-58102Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts.CRITICAL 9.1EPSS 0.34%13 July 2026
CVE-2026-623279Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the…CRITICAL 9.3EPSS 0.64%13 July 2026
CVE-2026-598019Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the…CRITICAL 9.3EPSS 2.91%13 July 2026
CVE-2026-52533An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component fileCRITICAL 9.8EPSS 0.60%13 July 2026
CVE-2026-51821SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpointCRITICAL 9.8EPSS 0.77%13 July 2026
CVE-2026-51541OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size.CRITICAL 9.1EPSS 0.42%13 July 2026
CVE-2026-51540OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData).CRITICAL 9.8EPSS 0.42%13 July 2026
CVE-2026-51538EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions.CRITICAL 9.1EPSS 0.39%13 July 2026
CVE-2026-51537EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets.CRITICAL 9.1EPSS 0.48%13 July 2026
CVE-2026-51536If a maliciously crafted packet with specific length fields is processed, the length parameter can overflow or be truncated into a negative value.CRITICAL 9.1EPSS 0.49%13 July 2026
CVE-2026-58409Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a malicious plugin ZIP archive containing a PHP webshell.CRITICAL 9.1EPSS 0.76%13 July 2026
CVE-2026-6875ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform.CRITICAL 9.5EPSS 77.6%13 July 2026
CVE-2026-61500Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login.CRITICAL 9.3EPSS 0.86%13 July 2026
CVE-2026-61462mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints.CRITICAL 9.2EPSS 0.51%13 July 2026
CVE-2026-57433Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one.CRITICAL 9.8EPSS 0.36%13 July 2026
CVE-2026-13221A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.CRITICAL 9.1EPSS 0.43%13 July 2026
CVE-2026-6847Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function.CRITICAL 9.3EPSS 0.88%13 July 2026
CVE-2026-61498Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start,…CRITICAL 9.3EPSS 4.09%13 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.