SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,914 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,282 results · page 93 of 786

CVESummaryPriorityPublished
CVE-2025-62821Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0.CRITICAL 9.1EPSS 1.05%19 June 2026
CVE-2026-56141In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possibleCRITICAL 9.8EPSS 0.52%19 June 2026
CVE-2026-50242In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possibleCRITICAL 9.8EPSS 0.61%19 June 2026
CVE-2026-44939A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious…CRITICAL 9.4EPSS 1.31%19 June 2026
CVE-2026-8713The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3.CRITICAL 9.1EPSS 2.67%19 June 2026
CVE-2026-7515The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter.CRITICAL 9.8EPSS 0.94%19 June 2026
CVE-2026-54414FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover.CRITICAL 9.3EPSS 0.66%19 June 2026
CVE-2026-40624Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.CRITICAL 9.3EPSS 0.83%19 June 2026
CVE-2026-12048Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths.CRITICAL 9.3EPSS 0.27%19 June 2026
CVE-2026-12046Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module missing the @pga_login_required…CRITICAL 9.5EPSS 1.04%19 June 2026
CVE-2026-12045Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role.CRITICAL 9.4EPSS 0.66%19 June 2026
CVE-2026-47647Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.CRITICAL 9.9EPSS 0.78%18 June 2026
CVE-2026-49454A forged SignatureValue carrying an attacker-controlled NameID could be accepted as {:ok}.CRITICAL 9.1EPSS 0.23%18 June 2026
CVE-2026-49257All MCP tools, including SQL query execution, schema creation, and table-config mutation, are reachable by any network-adjacent caller.CRITICAL 10.0EPSS 0.93%18 June 2026
CVE-2026-49252deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale.CRITICAL 9.9EPSS 0.47%18 June 2026
CVE-2026-43994Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm().CRITICAL 9.8EPSS 0.68%18 June 2026
CVE-2026-47846Bitnami Cassandra container images are affected by a retained default superuser vulnerability.CRITICAL 9.8EPSS 0.48%18 June 2026
CVE-2026-54390JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine.CRITICAL 9.3EPSS 0.60%18 June 2026
CVE-2026-56020The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header.CRITICAL 9.2EPSS 0.50%18 June 2026
CVE-2026-55203HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers.CRITICAL 9.0EPSS 0.35%18 June 2026
CVE-2026-54103A remote, unauthenticated attacker could change an arbitrary user's password.CRITICAL 9.3EPSS 0.77%18 June 2026
CVE-2026-38717InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function.CRITICAL 9.8EPSS 2.31%18 June 2026
CVE-2026-38716InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function.CRITICAL 9.8EPSS 2.31%18 June 2026
CVE-2026-38715InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function.CRITICAL 9.8EPSS 2.31%18 June 2026
CVE-2026-38714InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function.CRITICAL 9.8EPSS 2.31%18 June 2026
CVE-2026-8024A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.CRITICAL 9.3EPSS 0.55%18 June 2026
CVE-2026-54419claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities.CRITICAL 9.3EPSS 0.44%18 June 2026
CVE-2026-11718An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.CRITICAL 9.3EPSS 0.18%18 June 2026
CVE-2026-11717An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.CRITICAL 9.3EPSS 0.18%18 June 2026
CVE-2025-10560Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries.CRITICAL 9.3EPSS 0.39%18 June 2026
CVE-2026-55742Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler.CRITICAL 9.4EPSS 0.15%18 June 2026
CVE-2026-28573In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check.CRITICAL 10.0EPSS 0.14%18 June 2026
CVE-2026-55740Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php.CRITICAL 9.3EPSS 0.28%18 June 2026
CVE-2026-12569PTC Windchill and FlexPLM Improper Input Validation VulnerabilityKEVCRITICAL 9.3EPSS 40.6%18 June 2026
CVE-2026-48768As a result, any anonymous visitor to a published bot with a file input can upload attacker-controlled HTML, SVG, or JS to attacker-chosen subpaths, including other tenants’ publicly served result paths, enabling arbitrary content hosting and potential…CRITICAL 9.3EPSS 0.27%18 June 2026
CVE-2026-55200libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field.CRITICAL 9.2EPSS 4.02%17 June 2026
CVE-2026-54388Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.CRITICAL 9.3EPSS 0.44%17 June 2026
CVE-2026-54387Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.CRITICAL 9.3EPSS 0.44%17 June 2026
CVE-2026-48814In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret.CRITICAL 9.1EPSS 0.30%17 June 2026
CVE-2026-55196Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys.CRITICAL 9.1EPSS 0.58%17 June 2026
CVE-2026-53805NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's…CRITICAL 9.3EPSS 0.87%17 June 2026
CVE-2026-3894Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from…CRITICAL 9.2EPSS 0.20%17 June 2026
CVE-2026-2467Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0…CRITICAL 9.2EPSS 0.19%17 June 2026
CVE-2026-20266In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance.CRITICAL 9.1EPSS 0.63%17 June 2026
CVE-2026-53874picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr.CRITICAL 9.3EPSS 0.52%17 June 2026
CVE-2026-53873picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec().CRITICAL 9.3EPSS 0.46%17 June 2026
CVE-2026-3490picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls.CRITICAL 10.0EPSS 0.62%17 June 2026
CVE-2026-36418JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions.CRITICAL 9.1EPSS 0.47%17 June 2026
CVE-2026-20181A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.CRITICAL 9.1EPSS 8.93%17 June 2026
CVE-2025-71325picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection.CRITICAL 9.3EPSS 0.47%17 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.