SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,255 results · page 80 of 786

CVESummaryPriorityPublished
CVE-2026-60121Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling.CRITICAL 9.3EPSS 2.34%13 July 2026
CVE-2026-12257Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability.CRITICAL 9.3EPSS 0.70%13 July 2026
CVE-2026-14934A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker…CRITICAL 9.4EPSS 0.35%13 July 2026
CVE-2026-59518Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.CRITICAL 9.8EPSS 0.56%13 July 2026
CVE-2026-59515Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4.CRITICAL 9.3EPSS 0.40%13 July 2026
CVE-2026-57813Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.CRITICAL 9.8EPSS 0.48%13 July 2026
CVE-2026-57811Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0.CRITICAL 10.0EPSS 0.56%13 July 2026
CVE-2026-57770Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.CRITICAL 9.8EPSS 0.56%13 July 2026
CVE-2026-57744Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.CRITICAL 9.8EPSS 0.56%13 July 2026
CVE-2026-57739Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a…CRITICAL 9.3EPSS 0.40%13 July 2026
CVE-2026-57738Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.CRITICAL 9.8EPSS 0.56%13 July 2026
CVE-2026-57726Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.CRITICAL 9.3EPSS 0.40%13 July 2026
CVE-2026-57724Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.CRITICAL 9.8EPSS 0.56%13 July 2026
CVE-2026-57719Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.CRITICAL 10.0EPSS 0.52%13 July 2026
CVE-2026-57714Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through <= 5.6.3.CRITICAL 9.3EPSS 0.40%13 July 2026
CVE-2026-57710Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.CRITICAL 9.9EPSS 0.48%13 July 2026
CVE-2026-57707Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from…CRITICAL 9.3EPSS 0.40%13 July 2026
CVE-2026-57702Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.CRITICAL 9.3EPSS 0.45%13 July 2026
CVE-2026-57401Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0.CRITICAL 9.9EPSS 0.55%13 July 2026
CVE-2026-41041URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.CRITICAL 9.1EPSS 0.60%13 July 2026
CVE-2026-22103The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.CRITICAL 9.3EPSS 1.39%13 July 2026
CVE-2026-22102A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations.CRITICAL 9.3EPSS 0.53%13 July 2026
CVE-2026-22098Various sensitive information such as passwords and charging card UIDs are written to log files.CRITICAL 9.2EPSS 0.43%13 July 2026
CVE-2026-22097This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.CRITICAL 9.3EPSS 0.33%13 July 2026
CVE-2026-22096This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.CRITICAL 9.3EPSS 0.55%13 July 2026
CVE-2026-22095The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.CRITICAL 9.3EPSS 1.39%13 July 2026
CVE-2026-22093This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server.CRITICAL 9.5EPSS 0.26%13 July 2026
CVE-2026-13014A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, cron inputs, and…CRITICAL 9.2EPSS 0.70%13 July 2026
CVE-2026-14453This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution.CRITICAL 9.6EPSS 0.84%13 July 2026
CVE-2026-4769During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.CRITICAL 9.3EPSS 0.76%13 July 2026
CVE-2026-11964The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a payment-approved event and activate…CRITICAL 9.1EPSS 0.45%13 July 2026
CVE-2026-10666Because the destination size is never consulted, a crafted address string with a long suffix after the colon (e.g. "1.2.3.4:" followed by hundreds of bytes) causes an out-of-bounds stack write whose length and contents are fully attacker-controlled…CRITICAL 9.8EPSS 0.65%12 July 2026
CVE-2026-61876LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup.EXPLOITCRITICAL 9.4EPSS 1.28%12 July 2026
CVE-2026-56271Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware…CRITICAL 9.3EPSS 0.66%12 July 2026
CVE-2026-61447PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement.EXPLOITCRITICAL 10.0EPSS 2.49%11 July 2026
CVE-2026-61445PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls.CRITICAL 9.4EPSS 0.88%11 July 2026
CVE-2026-60090A caller able to influence collection-creation dimensions can pass a string such as '3); DROP TABLE tenant_secrets; --' to inject SQL/CQL tokens into the statement executed by the database driver.CRITICAL 9.3EPSS 0.70%11 July 2026
CVE-2026-57828Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads…CRITICAL 9.0EPSS 0.54%11 July 2026
CVE-2026-57827Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.CRITICAL 10.0EPSS 2.33%11 July 2026
CVE-2026-20744The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.CRITICAL 9.3EPSS 0.76%10 July 2026
CVE-2026-15089Vulnerability in Drupal Commerce guest registration.CRITICAL 9.1EPSS 0.40%10 July 2026
CVE-2026-11913vulnerability in Drupal Mother May I allows .CRITICAL 9.8EPSS 0.56%10 July 2026
CVE-2026-55884Tilt defines dev environments as code for microservice apps on Kubernetes.CRITICAL 9.2EPSS 0.50%10 July 2026
CVE-2026-12535Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection.CRITICAL 9.8EPSS 0.56%10 July 2026
CVE-2026-10768Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing.CRITICAL 9.8EPSS 2.13%10 July 2026
CVE-2026-9726Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection.CRITICAL 9.8EPSS 0.56%10 July 2026
CVE-2026-57807Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd.CRITICAL 9.8EPSS 0.73%10 July 2026
CVE-2026-57216Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend…CRITICAL 10.0EPSS 0.89%10 July 2026
CVE-2026-57211Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are…CRITICAL 10.0EPSS 0.63%10 July 2026
CVE-2026-55879From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later renders them in the authenticated…CRITICAL 9.3EPSS 0.50%10 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.