SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,801 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,255 results · page 83 of 786

CVESummaryPriorityPublished
CVE-2026-4375The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org…CRITICAL 9.0EPSS 0.42%7 July 2026
CVE-2026-14345The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter.CRITICAL 9.8EPSS 1.39%7 July 2026
CVE-2026-12375The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants…CRITICAL 9.8EPSS 0.55%7 July 2026
CVE-2026-34048Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers.CRITICAL 9.9EPSS 0.80%7 July 2026
CVE-2026-34047Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware, allowing an authenticated user to access terminal functionality for resources outside the authorized scope and potentially execute…CRITICAL 9.9EPSS 0.71%7 July 2026
CVE-2026-34037Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups, allowing an authenticated user to clone resources into destinations owned…CRITICAL 9.9EPSS 0.44%7 July 2026
CVE-2026-57572An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's runtime user.CRITICAL 10.0EPSS 0.94%6 July 2026
CVE-2026-57571Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement.CRITICAL 9.6EPSS 0.81%6 July 2026
CVE-2026-42341Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint.CRITICAL 9.2EPSS 0.27%6 July 2026
CVE-2026-34038Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through…CRITICAL 9.9EPSS 2.54%6 July 2026
CVE-2026-11405The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification…CRITICAL 9.8EPSS 0.77%6 July 2026
CVE-2026-9182Esri ArcGIS Server contains an unrestricted file upload vulnerability.CRITICAL 9.8EPSS 0.62%6 July 2026
CVE-2026-48614An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.CRITICAL 9.9EPSS 0.58%6 July 2026
CVE-2026-48316ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 10.0EPSS 1.13%6 July 2026
CVE-2026-40139A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support.CRITICAL 9.2EPSS 0.75%6 July 2026
CVE-2026-40138A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access.CRITICAL 9.2EPSS 0.46%6 July 2026
CVE-2026-5268An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed.CRITICAL 9.1EPSS 0.66%6 July 2026
CVE-2025-53830Versions of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSRF).CRITICAL 9.1EPSS 0.46%6 July 2026
CVE-2025-53827In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function.CRITICAL 9.1EPSS 0.61%6 July 2026
CVE-2026-6900Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL.CRITICAL 9.1EPSS 0.22%6 July 2026
CVE-2026-12686An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted within the same subdomain environment.CRITICAL 9.3EPSS 0.37%6 July 2026
CVE-2026-56140Improper Input Validation vulnerability in Apache Camel AWS SNS component.CRITICAL 9.8EPSS 0.74%6 July 2026
CVE-2026-53913Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.CRITICAL 9.8EPSS 1.08%6 July 2026
CVE-2026-48205Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.CRITICAL 9.1EPSS 0.60%6 July 2026
CVE-2026-48204Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component.CRITICAL 9.8EPSS 0.73%6 July 2026
CVE-2026-48203Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel Solr component.CRITICAL 9.1EPSS 0.60%6 July 2026
CVE-2026-46456Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component.CRITICAL 9.8EPSS 0.79%6 July 2026
CVE-2026-46455Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component.CRITICAL 9.8EPSS 0.69%6 July 2026
CVE-2026-46454Improper Input Validation vulnerability in Apache Camel Cometd Component.CRITICAL 9.8EPSS 0.83%6 July 2026
CVE-2026-43867Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.CRITICAL 9.8EPSS 0.93%6 July 2026
CVE-2026-40047Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component.CRITICAL 9.1EPSS 2.43%6 July 2026
CVE-2026-24014If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory.CRITICAL 9.8EPSS 0.69%6 July 2026
CVE-2026-24013Authentication Bypass by Spoofing vulnerability in Apache IoTDB.CRITICAL 9.1EPSS 0.64%6 July 2026
CVE-2026-6382The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a…CRITICAL 9.1EPSS 1.40%6 July 2026
CVE-2026-14808Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.CRITICAL 9.3EPSS 0.69%6 July 2026
CVE-2026-14807ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.CRITICAL 9.3EPSS 0.63%6 July 2026
CVE-2026-59509An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search.CRITICAL 9.2EPSS 1.43%5 July 2026
CVE-2026-14535In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe.CRITICAL 9.8EPSS 0.56%4 July 2026
CVE-2026-58426Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state writeCRITICAL 9.6EPSS 0.30%3 July 2026
CVE-2026-58422Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accountsCRITICAL 9.8EPSS 0.62%3 July 2026
CVE-2026-57983Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.CRITICAL 10.0EPSS 0.65%3 July 2026
CVE-2026-27780Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.CRITICAL 9.8EPSS 0.64%3 July 2026
CVE-2026-26292Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.CRITICAL 9.8EPSS 0.65%3 July 2026
CVE-2026-26247Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.CRITICAL 9.1EPSS 0.50%3 July 2026
CVE-2026-26232Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.CRITICAL 9.1EPSS 0.50%3 July 2026
CVE-2026-25718Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.CRITICAL 9.1EPSS 0.56%3 July 2026
CVE-2026-22874Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.CRITICAL 9.6EPSS 0.46%3 July 2026
CVE-2026-22547Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.CRITICAL 9.1EPSS 0.52%3 July 2026
CVE-2026-20896Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.CRITICAL 9.8EPSS 2.76%3 July 2026
CVE-2026-20706Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.CRITICAL 9.1EPSS 0.56%3 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.