SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,841 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,276 results · page 89 of 786

CVESummaryPriorityPublished
CVE-2026-56068Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.CRITICAL 9.3EPSS 0.40%26 June 2026
CVE-2026-56067Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.CRITICAL 9.3EPSS 0.40%26 June 2026
CVE-2026-56062Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.CRITICAL 9.3EPSS 0.40%26 June 2026
CVE-2026-56059Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.CRITICAL 9.9EPSS 0.48%26 June 2026
CVE-2026-56058Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.CRITICAL 9.9EPSS 0.48%26 June 2026
CVE-2026-56057Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.CRITICAL 9.8EPSS 0.56%26 June 2026
CVE-2026-56036Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.CRITICAL 9.3EPSS 0.40%26 June 2026
CVE-2026-56034Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.CRITICAL 9.3EPSS 0.40%26 June 2026
CVE-2026-56033Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.CRITICAL 9.8EPSS 0.48%26 June 2026
CVE-2026-56032Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.CRITICAL 9.8EPSS 0.56%26 June 2026
CVE-2026-56030Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.CRITICAL 9.8EPSS 0.48%26 June 2026
CVE-2026-56028Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions.CRITICAL 9.8EPSS 0.53%26 June 2026
CVE-2026-56027Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.CRITICAL 9.9EPSS 0.32%26 June 2026
CVE-2026-54831Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.CRITICAL 9.3EPSS 0.40%26 June 2026
CVE-2026-54827Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.CRITICAL 9.3EPSS 0.40%26 June 2026
CVE-2026-54825Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.CRITICAL 9.3EPSS 0.40%26 June 2026
CVE-2026-54820Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.CRITICAL 9.3EPSS 0.40%26 June 2026
CVE-2026-57926In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attackCRITICAL 9.8EPSS 0.34%26 June 2026
CVE-2026-53914In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadataCRITICAL 9.8EPSS 0.33%26 June 2026
CVE-2025-64152Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.CRITICAL 9.1EPSS 0.54%26 June 2026
CVE-2025-55017Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.CRITICAL 9.1EPSS 0.54%26 June 2026
CVE-2026-57881An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.CRITICAL 9.8EPSS 0.65%26 June 2026
CVE-2026-57880An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.CRITICAL 9.8EPSS 0.95%26 June 2026
CVE-2026-57879An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.CRITICAL 9.8EPSS 0.95%26 June 2026
CVE-2026-57878An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.CRITICAL 9.8EPSS 0.95%26 June 2026
CVE-2026-2053This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests.CRITICAL 10.0EPSS 0.39%26 June 2026
CVE-2026-48930This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.CRITICAL 9.8EPSS 0.32%26 June 2026
CVE-2026-9222This could allow an attacker, who knows the hash, to authenticate and gain full access.CRITICAL 9.2EPSS 0.41%26 June 2026
CVE-2026-40702WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations.CRITICAL 9.3EPSS 0.65%25 June 2026
CVE-2025-71338Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory.CRITICAL 10.0EPSS 1.16%25 June 2026
CVE-2025-71336Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers.CRITICAL 9.3EPSS 1.15%25 June 2026
CVE-2025-71334Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations.CRITICAL 9.3EPSS 4.36%25 June 2026
CVE-2025-71333Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local.CRITICAL 9.3EPSS 0.90%25 June 2026
CVE-2025-71327Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts.CRITICAL 9.3EPSS 0.68%25 June 2026
CVE-2026-57700Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files.CRITICAL 10.0EPSS 0.52%25 June 2026
CVE-2026-56786RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields.CRITICAL 9.3EPSS 0.71%25 June 2026
CVE-2026-54089Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker who can reach the server directly can impersonate any user - including admin - by sending a single forged HTTP header.CRITICAL 9.1EPSS 0.61%25 June 2026
CVE-2026-54088Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command.CRITICAL 9.3EPSS 0.76%25 June 2026
CVE-2026-50549A malicious agent can create an in-workspace symlink that points outside the workspace and force canonicalization to fail — either because the target does not exist or because read permission is removed from the path — so the agent writes through the…CRITICAL 9.3EPSS 1.01%25 June 2026
CVE-2026-50548A malicious agent could set working_directory to a sensitive location and write arbitrary files outside the workspace under the user's privileges.CRITICAL 9.3EPSS 1.01%25 June 2026
CVE-2026-56123socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser.CRITICAL 9.2EPSS 0.55%25 June 2026
CVE-2026-55413Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace plugin with arbitrary JavaScript that executes server-side with full Node.js access (require, process).CRITICAL 9.4EPSS 0.40%25 June 2026
CVE-2026-54030Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate that the resource parameter from OAuth Protected Resource metadata (RFC 9728) matches the configured MCP server URL, allowing a malicious MCP server to steal access tokens intended…CRITICAL 9.3EPSS 0.17%25 June 2026
CVE-2026-54849Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.CRITICAL 9.3EPSS 0.40%25 June 2026
CVE-2026-54843Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.CRITICAL 9.3EPSS 0.40%25 June 2026
CVE-2026-54836Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection.CRITICAL 9.3EPSS 1.34%25 June 2026
CVE-2026-54823Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.CRITICAL 9.9EPSS 0.79%25 June 2026
CVE-2026-41120Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability.CRITICAL 9.8EPSS 0.39%25 June 2026
CVE-2026-53260In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). syzbot reported a weird reqsk->rsk_refcnt underflow in __inet_csk_reqsk_queue_drop().CRITICAL 9.8EPSS 0.37%25 June 2026
CVE-2026-53247In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown mtk_free_dev() calls metadata_dst_free() which frees the metadata_dst with kfree() immediately, bypassing the RCU…CRITICAL 9.8EPSS 0.47%25 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.