SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,276 results · page 88 of 786

CVESummaryPriorityPublished
CVE-2026-48281ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 10.0EPSS 1.42%30 June 2026
CVE-2026-48277ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 10.0EPSS 1.29%30 June 2026
CVE-2026-48276ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 10.0EPSS 1.26%30 June 2026
CVE-2026-14241Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.CRITICAL 9.8EPSS 0.43%30 June 2026
CVE-2026-6556Applications that use path-scoped middleware for authentication, authorization, rate limiting, or auditing on routes inside a prefixed scope can be bypassed by sending a request to the prefixed route, because Fastify still matches the route but the…CRITICAL 9.1EPSS 0.52%30 June 2026
CVE-2026-58116LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces.CRITICAL 9.3EPSS 0.90%30 June 2026
CVE-2026-58016This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.CRITICAL 9.1EPSS 0.55%30 June 2026
CVE-2026-44946A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,CRITICAL 9.5EPSS 0.39%30 June 2026
CVE-2026-8402Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc.CRITICAL 9.8EPSS 0.47%30 June 2026
CVE-2026-53690An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint.CRITICAL 9.3EPSS 0.51%30 June 2026
CVE-2026-14162Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.CRITICAL 9.3EPSS 0.63%30 June 2026
CVE-2026-13766DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers.CRITICAL 9.8EPSS 0.55%30 June 2026
CVE-2026-9711The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter…CRITICAL 9.8EPSS 0.54%30 June 2026
CVE-2026-12076Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.CRITICAL 9.3EPSS 0.53%30 June 2026
CVE-2026-12819Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated interaction with security-sensitive PLC functions.CRITICAL 9.3EPSS 0.54%30 June 2026
CVE-2026-12818Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service.CRITICAL 9.3EPSS 0.43%30 June 2026
CVE-2026-12073The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5.CRITICAL 9.8EPSS 0.53%30 June 2026
CVE-2026-55276Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.CRITICAL 9.1EPSS 0.56%29 June 2026
CVE-2026-53434Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.CRITICAL 9.1EPSS 0.59%29 June 2026
CVE-2026-57498However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parameters without any team ownership validation, allowing cross-team resource deployment.CRITICAL 9.6EPSS 0.38%29 June 2026
CVE-2026-39868An app may be able to cause unexpected system termination or corrupt kernel memory.CRITICAL 9.1EPSS 1.21%29 June 2026
CVE-2026-37637An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php componentCRITICAL 9.1EPSS 0.66%29 June 2026
CVE-2026-56782Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration.CRITICAL 9.3EPSS 3.56%29 June 2026
CVE-2026-11720A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox.CRITICAL 9.3EPSS 0.53%29 June 2026
CVE-2026-13751Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery.CRITICAL 9.6EPSS 0.20%29 June 2026
CVE-2026-41052Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.CRITICAL 9.4EPSS 0.42%29 June 2026
CVE-2026-57331Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.CRITICAL 9.9EPSS 0.55%29 June 2026
CVE-2026-56290Joomlack Page Builder Improper Access Control VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 30.9%29 June 2026
CVE-2026-58053Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options…CRITICAL 9.4EPSS 0.44%28 June 2026
CVE-2026-12415The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0.CRITICAL 9.8EPSS 0.80%27 June 2026
CVE-2026-31928The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation.CRITICAL 9.3EPSS 0.57%26 June 2026
CVE-2026-28701Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.CRITICAL 9.3EPSS 0.68%26 June 2026
CVE-2026-53576Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addresses its…CRITICAL 10.0EPSS 3.19%26 June 2026
CVE-2026-49869Kestra OSS OS Command Injection VulnerabilityKEVCRITICAL 10.0EPSS 1.92%26 June 2026
CVE-2026-54352This vulnerability is fixed in 3.39.9.CRITICAL 9.6EPSS 0.49%26 June 2026
CVE-2026-54351Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters.CRITICAL 9.6EPSS 0.46%26 June 2026
CVE-2026-54350A parameter value containing a closing quote and additional keys lifts attacker-controlled fields into the parsed filter object.CRITICAL 9.8EPSS 0.54%26 June 2026
CVE-2026-53309In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs-remote region comparison loop uses '<=' instead of '<', causing it to read one entry past the valid range…CRITICAL 9.8EPSS 0.40%26 June 2026
CVE-2026-52785Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality.CRITICAL 9.9EPSS 0.38%26 June 2026
CVE-2026-52782Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources.CRITICAL 9.9EPSS 0.45%26 June 2026
CVE-2026-52780Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (RCE).CRITICAL 9.6EPSS 0.39%26 June 2026
CVE-2026-46386Combined with cookies_serializer = :marshal, this gives any logged-in user a deterministic Marshal-deserialization path reachable via the /my/two_factor_devices cookie reader This vulnerability is fixed in .CRITICAL 9.9EPSS 0.49%26 June 2026
CVE-2026-33646Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution.CRITICAL 9.6EPSS 0.69%26 June 2026
CVE-2026-54636An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user.CRITICAL 9.9EPSS 0.53%26 June 2026
CVE-2026-45408When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an unquoted heredoc (<<EOF instead of <<'EOF') in fn-git-create-hook() at plugins/git/internal-functions:378.CRITICAL 9.0EPSS 0.42%26 June 2026
CVE-2026-12411Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when…CRITICAL 9.6EPSS 0.29%26 June 2026
CVE-2026-0685Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.CRITICAL 9.8EPSS 0.93%26 June 2026
CVE-2025-11919The `-init` file for the the JVM initialization exists in the vulnerable directory during the startup of the JVM.CRITICAL 9.6EPSS 0.41%26 June 2026
CVE-2026-57658Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.CRITICAL 9.1EPSS 0.50%26 June 2026
CVE-2026-56070Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.CRITICAL 9.3EPSS 0.40%26 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.