SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,238 results · page 8 of 785

CVESummaryPriorityPublished
CVE-2026-73950Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).CRITICAL 9.8EPSS 0.45%15 September 2026
CVE-2026-73948Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer).CRITICAL 9.9EPSS 0.39%15 September 2026
CVE-2026-73947Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).CRITICAL 9.8EPSS 0.33%15 September 2026
CVE-2026-73946Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).CRITICAL 9.1EPSS 0.32%15 September 2026
CVE-2026-73945Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).CRITICAL 9.9EPSS 0.29%15 September 2026
CVE-2026-73944Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).CRITICAL 9.1EPSS 0.31%15 September 2026
CVE-2026-73940Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).CRITICAL 9.8EPSS 0.45%15 September 2026
CVE-2026-73458On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down.CRITICAL 9.2EPSS 0.38%15 September 2026
CVE-2026-71163Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).CRITICAL 9.9EPSS 0.27%15 September 2026
CVE-2026-71133Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).CRITICAL 10.0EPSS 0.33%15 September 2026
CVE-2026-70913Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.33%15 September 2026
CVE-2026-70757Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.33%15 September 2026
CVE-2026-70756Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.45%15 September 2026
CVE-2026-70748Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.8EPSS 0.33%15 September 2026
CVE-2026-69204When ember-server is behind a keep-alive intermediary that forwards both headers and frames by Content-Length, an unauthenticated attacker can smuggle a second request, bypass intermediary access controls, poison caches, or cause a victim request to be…CRITICAL 9.2EPSS 0.33%15 September 2026
CVE-2026-56960In multiple locations, there is a possible use-after-free due to a logic error in the code.CRITICAL 9.8EPSS 0.30%15 September 2026
CVE-2026-55366In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code.CRITICAL 9.8EPSS 0.36%15 September 2026
CVE-2026-19773libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability.CRITICAL 9.8EPSS 0.65%15 September 2026
CVE-2026-61667The injected query can control the returned MetaQuery value, which is passed to Python eval and permits command execution as the account running the DIRAC services.CRITICAL 9.9EPSS 0.65%15 September 2026
CVE-2026-53459Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources causing database access to fail, granting unauthenticated…CRITICAL 9.3EPSS 0.42%15 September 2026
CVE-2026-45579An unrecognized value is resolved against the Request object and evaluated as Python code, allowing a crafted dunder attribute expression to reach operating-system functions and execute commands as the account running the DIRAC services.CRITICAL 9.9EPSS 0.44%15 September 2026
CVE-2026-12351IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT…CRITICAL 9.8EPSS 0.86%15 September 2026
CVE-2026-11928IBM Verify Identity Access is vulnerable to a buffer overflow attack.CRITICAL 9.8EPSS 0.29%15 September 2026
CVE-2026-11921IBM Verify Identity Access containers may not apply management password change operations correctly.CRITICAL 9.1EPSS 0.23%15 September 2026
CVE-2026-89026The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote…CRITICAL 9.3EPSS 0.52%15 September 2026
CVE-2026-89022BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same…CRITICAL 9.1EPSS 0.29%15 September 2026
CVE-2026-53710Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on validate_code checks for literal…CRITICAL 10.0EPSS 0.83%15 September 2026
CVE-2026-46488An unauthenticated attacker who knows a target username and corresponding hash can set the cookies manually or cause them to be loaded by submitting blank credentials through the switch-user authentication flow, after which the server authenticates the…CRITICAL 9.1EPSS 0.27%15 September 2026
CVE-2024-58385Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without…CRITICAL 9.3EPSS 0.38%15 September 2026
CVE-2023-54398Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via…CRITICAL 9.3EPSS 0.64%15 September 2026
CVE-2026-91988atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses.CRITICAL 9.2EPSS 0.25%15 September 2026
CVE-2026-91949FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them.CRITICAL 9.2EPSS 0.45%15 September 2026
CVE-2026-91932Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter.CRITICAL 9.0EPSS 0.82%15 September 2026
CVE-2026-91931Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter.CRITICAL 9.0EPSS 0.63%15 September 2026
CVE-2026-77972Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected.CRITICAL 9.0EPSS 0.32%15 September 2026
CVE-2026-77866Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block.CRITICAL 9.0EPSS 0.46%15 September 2026
CVE-2026-55211Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed.CRITICAL 9.8EPSS 0.54%15 September 2026
CVE-2026-37152TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.CRITICAL 9.8EPSS 0.48%15 September 2026
CVE-2024-14029Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.CRITICAL 9.0EPSS 0.35%15 September 2026
CVE-2023-54397Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters.CRITICAL 9.0EPSS 0.37%15 September 2026
CVE-2026-88617This allows a remote attacker to escalate privileges.CRITICAL 9.8EPSS 0.42%15 September 2026
CVE-2026-63696Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability.CRITICAL 9.1EPSS 0.32%15 September 2026
CVE-2026-63695Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability.CRITICAL 9.8EPSS 0.53%15 September 2026
CVE-2026-61549Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions.CRITICAL 9.0EPSS 0.17%15 September 2026
CVE-2026-59971A network attacker can directly reach execute_sql, or can use DNS rebinding to make a victim's browser relay same-origin requests to a locally bound service, and supply a query that reaches cursor.execute(query).CRITICAL 10.0EPSS 0.39%15 September 2026
CVE-2026-55158Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec.CRITICAL 9.1EPSS 0.45%15 September 2026
CVE-2026-46495Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authentication without a restrictive…CRITICAL 9.2EPSS 0.73%15 September 2026
CVE-2026-39919Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with…CRITICAL 9.3EPSS 0.49%15 September 2026
CVE-2026-77179On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path.CRITICAL 9.4EPSS 0.16%15 September 2026
CVE-2026-92018This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.CRITICAL 9.6EPSS 0.16%15 September 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.