SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,255 results · page 82 of 786

CVESummaryPriorityPublished
CVE-2026-12116A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.CRITICAL 9.8EPSS 0.70%9 July 2026
CVE-2026-56291Balbooa Forms Unrestricted Upload of File with Dangerous Type VulnerabilityKEVCRITICAL 10.0EPSS 14.9%9 July 2026
CVE-2026-5955Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection.CRITICAL 9.8EPSS 0.47%9 July 2026
CVE-2026-2342Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd.CRITICAL 9.3EPSS 0.39%9 July 2026
CVE-2026-15158The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function.CRITICAL 9.8EPSS 1.07%9 July 2026
CVE-2026-14245The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1.CRITICAL 9.8EPSS 1.07%9 July 2026
CVE-2026-47840A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return…CRITICAL 9.3EPSS 0.22%9 July 2026
CVE-2026-54782Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker…CRITICAL 10.0EPSS 0.41%8 July 2026
CVE-2026-15113Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%8 July 2026
CVE-2026-52200An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apkCRITICAL 9.8EPSS 0.93%8 July 2026
CVE-2026-44024Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in file configurations such as the path parameter of the out_file plugin allows attackers sending untrusted tags…CRITICAL 9.8EPSS 1.08%8 July 2026
CVE-2026-31309Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST…CRITICAL 9.8EPSS 0.62%8 July 2026
CVE-2026-58192Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path sanitization, allowing an unauthenticated remote client to…CRITICAL 10.0EPSS 0.45%8 July 2026
CVE-2026-54527From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in…CRITICAL 9.3EPSS 0.53%8 July 2026
CVE-2026-8801Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules).CRITICAL 9.8EPSS 0.34%8 July 2026
CVE-2026-8649Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).CRITICAL 9.8EPSS 0.26%8 July 2026
CVE-2026-60104Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access…CRITICAL 9.3EPSS 0.37%8 July 2026
CVE-2026-9074IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.CRITICAL 9.8EPSS 0.51%8 July 2026
CVE-2026-59873Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU.CRITICAL 9.2EPSS 0.56%8 July 2026
CVE-2026-59702repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests.CRITICAL 9.2EPSS 0.44%8 July 2026
CVE-2026-3144IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.CRITICAL 9.8EPSS 0.41%8 July 2026
CVE-2026-15062SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege users to execute SQL beyond their authorization scope.CRITICAL 9.6EPSS 0.39%8 July 2026
CVE-2026-58480Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through…EXPLOITCRITICAL 9.2EPSS 3.57%8 July 2026
CVE-2026-54061Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization.CRITICAL 9.1EPSS 0.58%8 July 2026
CVE-2026-8307Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection.CRITICAL 9.8EPSS 0.47%8 July 2026
CVE-2026-14454An attacker could craft an image with EXIF data that terminates a worker process.CRITICAL 9.8EPSS 0.66%8 July 2026
CVE-2026-41042Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter.CRITICAL 9.1EPSS 1.51%8 July 2026
CVE-2026-56000Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.CRITICAL 9.0EPSS 0.22%8 July 2026
CVE-2026-9695An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.CRITICAL 9.8EPSS 0.61%8 July 2026
CVE-2026-12153The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8.CRITICAL 9.8EPSS 0.67%8 July 2026
CVE-2026-9701The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2.CRITICAL 9.8EPSS 0.48%8 July 2026
CVE-2026-14487The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13.CRITICAL 9.1EPSS 1.17%8 July 2026
CVE-2026-60002ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange.CRITICAL 9.4EPSS 0.30%8 July 2026
CVE-2026-56843Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is…CRITICAL 9.9EPSS 0.66%8 July 2026
CVE-2026-59705mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without authentication middleware.CRITICAL 9.3EPSS 0.80%7 July 2026
CVE-2026-37271Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation.CRITICAL 9.8EPSS 0.64%7 July 2026
CVE-2026-37270Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.CRITICAL 9.8EPSS 0.68%7 July 2026
CVE-2026-14740DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment.CRITICAL 9.1EPSS 0.39%7 July 2026
CVE-2026-14739DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders.CRITICAL 9.8EPSS 0.41%7 July 2026
CVE-2026-59706mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter.CRITICAL 9.2EPSS 0.44%7 July 2026
CVE-2026-46354Coder allows organizations to provision remote development environments via Terraform.CRITICAL 9.1EPSS 0.32%7 July 2026
CVE-2026-59707LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs.CRITICAL 9.2EPSS 0.48%7 July 2026
CVE-2026-58473Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs no admin or…CRITICAL 9.3EPSS 0.51%7 July 2026
CVE-2026-598009Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied).CRITICAL 9.2EPSS 2.04%7 July 2026
CVE-2026-13020A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes.CRITICAL 9.8EPSS 0.27%7 July 2026
CVE-2026-13019Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.CRITICAL 9.8EPSS 0.43%7 July 2026
CVE-2026-53483Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability.CRITICAL 9.8EPSS 0.63%7 July 2026
CVE-2026-53481Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a…CRITICAL 9.8EPSS 0.63%7 July 2026
CVE-2011-10043Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded.CRITICAL 9.8EPSS 0.78%7 July 2026
CVE-2026-33264A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code…CRITICAL 9.8EPSS 1.03%7 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.