SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,276 results · page 84 of 786

CVESummaryPriorityPublished
CVE-2026-43867Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.CRITICAL 9.8EPSS 0.93%6 July 2026
CVE-2026-40047Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component.CRITICAL 9.1EPSS 2.43%6 July 2026
CVE-2026-24014If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory.CRITICAL 9.8EPSS 0.69%6 July 2026
CVE-2026-24013Authentication Bypass by Spoofing vulnerability in Apache IoTDB.CRITICAL 9.1EPSS 0.64%6 July 2026
CVE-2026-6382The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a…CRITICAL 9.1EPSS 1.40%6 July 2026
CVE-2026-14808Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.CRITICAL 9.3EPSS 0.69%6 July 2026
CVE-2026-14807ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.CRITICAL 9.3EPSS 0.63%6 July 2026
CVE-2026-59509An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search.CRITICAL 9.2EPSS 1.43%5 July 2026
CVE-2026-14535In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe.CRITICAL 9.8EPSS 0.56%4 July 2026
CVE-2026-58426Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state writeCRITICAL 9.6EPSS 0.30%3 July 2026
CVE-2026-58422Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accountsCRITICAL 9.8EPSS 0.62%3 July 2026
CVE-2026-57983Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.CRITICAL 10.0EPSS 0.65%3 July 2026
CVE-2026-27780Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.CRITICAL 9.8EPSS 0.64%3 July 2026
CVE-2026-26292Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.CRITICAL 9.8EPSS 0.65%3 July 2026
CVE-2026-26247Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.CRITICAL 9.1EPSS 0.50%3 July 2026
CVE-2026-26232Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.CRITICAL 9.1EPSS 0.50%3 July 2026
CVE-2026-25718Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.CRITICAL 9.1EPSS 0.56%3 July 2026
CVE-2026-22874Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.CRITICAL 9.6EPSS 0.46%3 July 2026
CVE-2026-22547Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.CRITICAL 9.1EPSS 0.52%3 July 2026
CVE-2026-20896Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.CRITICAL 9.8EPSS 2.76%3 July 2026
CVE-2026-20706Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.CRITICAL 9.1EPSS 0.56%3 July 2026
CVE-2026-12481A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer.CRITICAL 9.8EPSS 0.72%3 July 2026
CVE-2026-56015Net::IP::LPM versions before 1.11 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width. addPrefixToTrie() then walks…CRITICAL 9.1EPSS 0.65%3 July 2026
CVE-2026-4321Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection.CRITICAL 9.8EPSS 0.47%3 July 2026
CVE-2026-14544This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution.CRITICAL 9.8EPSS 0.93%3 July 2026
CVE-2026-9079libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.CRITICAL 9.8EPSS 0.58%3 July 2026
CVE-2026-8927Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.CRITICAL 9.1EPSS 0.50%3 July 2026
CVE-2026-8926When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc`…CRITICAL 9.1EPSS 0.44%3 July 2026
CVE-2026-8925The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.CRITICAL 9.8EPSS 0.67%3 July 2026
CVE-2026-8924A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check.CRITICAL 9.1EPSS 0.66%3 July 2026
CVE-2026-11856Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the…CRITICAL 9.8EPSS 0.69%3 July 2026
CVE-2026-11564libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup.CRITICAL 9.1EPSS 0.36%3 July 2026
CVE-2026-10536A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with…CRITICAL 9.8EPSS 0.60%3 July 2026
CVE-2026-9725The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which…CRITICAL 9.1EPSS 1.17%3 July 2026
CVE-2026-13768Gardyn devices expose a privileged iothubowner key.CRITICAL 9.5EPSS 0.65%3 July 2026
CVE-2026-13368WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2.CRITICAL 9.2EPSS 1.01%3 July 2026
CVE-2026-41106Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.CRITICAL 9.3EPSS 0.72%2 July 2026
CVE-2026-26145Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.CRITICAL 9.8EPSS 0.70%2 July 2026
CVE-2026-52830A remote HTTP client can therefore authenticate as the default legacy session with a token such as ../fast-mcp-telegram/telegram when the documented default session file ~/.config/fast-mcp-telegram/telegram.session exists.CRITICAL 9.4EPSS 0.65%2 July 2026
CVE-2026-38971ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().CRITICAL 9.1EPSS 0.68%2 July 2026
CVE-2026-38968ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.CRITICAL 9.8EPSS 0.55%2 July 2026
CVE-2026-59099Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime.CRITICAL 9.3EPSS 0.55%2 July 2026
CVE-2026-58466AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the…CRITICAL 9.3EPSS 0.80%2 July 2026
CVE-2026-44935Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.CRITICAL 9.9EPSS 0.49%2 July 2026
CVE-2024-14037Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint.CRITICAL 9.3EPSS 1.28%2 July 2026
CVE-2022-50973Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and…CRITICAL 9.3EPSS 1.52%2 July 2026
CVE-2026-58455Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with…CRITICAL 9.2EPSS 8.04%2 July 2026
CVE-2026-56004A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious servicesCRITICAL 10.0EPSS 0.66%2 July 2026
CVE-2026-55116A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.CRITICAL 9.8EPSS 0.41%2 July 2026
CVE-2026-55115A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.CRITICAL 9.9EPSS 0.47%2 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.