SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,276 results · page 86 of 786

CVESummaryPriorityPublished
CVE-2026-58127PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement.CRITICAL 9.3EPSS 1.88%1 July 2026
CVE-2026-58126PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any…CRITICAL 9.3EPSS 1.84%1 July 2026
CVE-2026-57517Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint.CRITICAL 9.3EPSS 0.96%1 July 2026
CVE-2026-24270NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication.CRITICAL 9.8EPSS 0.81%1 July 2026
CVE-2025-23351NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input.CRITICAL 9.0EPSS 0.37%1 July 2026
CVE-2025-23350NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input.CRITICAL 9.0EPSS 0.37%1 July 2026
CVE-2025-15646HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion.CRITICAL 9.8EPSS 0.67%1 July 2026
CVE-2026-23537A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem.CRITICAL 9.1EPSS 1.05%1 July 2026
CVE-2026-57692Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation.CRITICAL 9.8EPSS 0.53%1 July 2026
CVE-2026-53355In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts.CRITICAL 9.8EPSS 0.42%1 July 2026
CVE-2026-13603Our plugin pretix-oppwa did so insecurely by concatenating the parameter form the URL to the base domain of the API without further validation and, critically, without a / at the end of the baseUrl.CRITICAL 9.0EPSS 0.41%1 July 2026
CVE-2026-14198When middleware is used for authentication, authorization, rate limiting, or auditing on parameterized paths, an attacker can reach the protected handler by sending a single crafted URL with an encoded slash in the parameter position.CRITICAL 9.1EPSS 0.52%1 July 2026
CVE-2026-11387The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5.CRITICAL 9.8EPSS 2.21%1 July 2026
CVE-2026-10539Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server.CRITICAL 9.5EPSS 0.42%1 July 2026
CVE-2026-7840UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server.CRITICAL 9.3EPSS 2.63%1 July 2026
CVE-2026-7839UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password.CRITICAL 9.1EPSS 0.66%1 July 2026
CVE-2026-6070The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1.CRITICAL 9.1EPSS 0.76%1 July 2026
CVE-2026-53488This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations.CRITICAL 9.4EPSS 0.18%1 July 2026
CVE-2026-56700Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities.CRITICAL 9.3EPSS 2.53%30 June 2026
CVE-2026-56415Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication.CRITICAL 10.0EPSS 4.36%30 June 2026
CVE-2026-56413Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions.CRITICAL 10.0EPSS 4.19%30 June 2026
CVE-2026-56278Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set…CRITICAL 9.3EPSS 0.53%30 June 2026
CVE-2026-56264Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security…CRITICAL 9.2EPSS 0.49%30 June 2026
CVE-2026-55721Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts.CRITICAL 9.2EPSS 0.55%30 June 2026
CVE-2026-50110Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file.CRITICAL 9.3EPSS 0.18%30 June 2026
CVE-2026-14152Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-14121Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic.CRITICAL 9.8EPSS 0.46%30 June 2026
CVE-2026-14120Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-14113Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.31%30 June 2026
CVE-2026-14109Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-14106Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-14104Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.CRITICAL 9.8EPSS 0.52%30 June 2026
CVE-2026-14101Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.33%30 June 2026
CVE-2026-14097Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.32%30 June 2026
CVE-2026-14095Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.32%30 June 2026
CVE-2026-14093Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.32%30 June 2026
CVE-2026-14056Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file.CRITICAL 9.6EPSS 0.32%30 June 2026
CVE-2026-14055Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-14044Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-14043Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-14038Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.3EPSS 0.33%30 June 2026
CVE-2026-14037Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-14017Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-13934Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-13920Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-13909Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-13901Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.34%30 June 2026
CVE-2026-13883Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.33%30 June 2026
CVE-2026-13882Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.24%30 June 2026
CVE-2026-13880Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.31%30 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.