SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,283 results · page 94 of 786

CVESummaryPriorityPublished
CVE-2025-71325picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection.CRITICAL 9.3EPSS 0.47%17 June 2026
CVE-2025-71323picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory.CRITICAL 9.3EPSS 0.76%17 June 2026
CVE-2025-71321picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file.CRITICAL 9.3EPSS 0.62%17 June 2026
CVE-2025-71320picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks.CRITICAL 9.3EPSS 0.62%17 June 2026
CVE-2026-55743The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.CRITICAL 9.4EPSS 0.39%17 June 2026
CVE-2026-54812Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection.CRITICAL 9.3EPSS 0.28%17 June 2026
CVE-2026-47103Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely.CRITICAL 9.3EPSS 1.36%17 June 2026
CVE-2026-42530NGINX Open Source has a vulnerability in the ngx_http_v3_module module.CRITICAL 9.2EPSS 3.82%17 June 2026
CVE-2026-42055NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules.CRITICAL 9.2EPSS 6.54%17 June 2026
CVE-2026-54819Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc.CRITICAL 9.3EPSS 0.23%17 June 2026
CVE-2026-54815Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection.CRITICAL 9.3EPSS 0.23%17 June 2026
CVE-2026-54809Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection.CRITICAL 9.3EPSS 0.23%17 June 2026
CVE-2026-54808Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection.CRITICAL 9.3EPSS 0.31%17 June 2026
CVE-2026-49108Unauthenticated PHP Object Injection in Moderno < 1.43 versions.CRITICAL 9.8EPSS 0.30%17 June 2026
CVE-2025-69127Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.CRITICAL 9.8EPSS 0.39%17 June 2026
CVE-2025-69111Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.CRITICAL 9.8EPSS 0.39%17 June 2026
CVE-2025-60236Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection.CRITICAL 9.8EPSS 0.31%17 June 2026
CVE-2025-60231Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection.CRITICAL 9.8EPSS 0.31%17 June 2026
CVE-2025-60230Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection.CRITICAL 9.8EPSS 0.43%17 June 2026
CVE-2025-60229Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection.CRITICAL 9.8EPSS 0.43%17 June 2026
CVE-2025-59554Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.CRITICAL 9.3EPSS 0.40%17 June 2026
CVE-2026-54811Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.CRITICAL 9.3EPSS 0.28%17 June 2026
CVE-2026-54807Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.CRITICAL 9.8EPSS 0.44%17 June 2026
CVE-2026-54806Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.CRITICAL 9.8EPSS 0.70%17 June 2026
CVE-2026-54803Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.CRITICAL 9.8EPSS 0.45%17 June 2026
CVE-2026-54194Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.CRITICAL 9.8EPSS 0.38%17 June 2026
CVE-2026-54187Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.CRITICAL 9.3EPSS 0.28%17 June 2026
CVE-2026-54186Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.CRITICAL 9.3EPSS 0.29%17 June 2026
CVE-2026-52706Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.CRITICAL 9.8EPSS 0.47%17 June 2026
CVE-2026-52705Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.CRITICAL 9.0EPSS 0.29%17 June 2026
CVE-2026-50203A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names.CRITICAL 9.1EPSS 0.63%17 June 2026
CVE-2026-49767Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.CRITICAL 9.8EPSS 0.55%17 June 2026
CVE-2026-49107Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.CRITICAL 9.8EPSS 0.38%17 June 2026
CVE-2026-49084Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.CRITICAL 9.3EPSS 0.28%17 June 2026
CVE-2026-49080Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.CRITICAL 9.3EPSS 0.31%17 June 2026
CVE-2026-49079Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.CRITICAL 9.3EPSS 0.35%17 June 2026
CVE-2026-49076Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.CRITICAL 9.3EPSS 0.37%17 June 2026
CVE-2026-49075Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.CRITICAL 9.8EPSS 0.38%17 June 2026
CVE-2026-49058Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.CRITICAL 9.8EPSS 0.32%17 June 2026
CVE-2026-48875Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.CRITICAL 9.3EPSS 0.37%17 June 2026
CVE-2026-48797In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push.CRITICAL 9.3EPSS 0.32%17 June 2026
CVE-2026-48781In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from…CRITICAL 9.9EPSS 0.21%17 June 2026
CVE-2026-48745In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server.CRITICAL 9.3EPSS 0.32%17 June 2026
CVE-2026-48616Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files.CRITICAL 9.3EPSS 0.33%17 June 2026
CVE-2026-48055In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic.CRITICAL 10.0EPSS 0.62%17 June 2026
CVE-2026-42380Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.CRITICAL 9.8EPSS 0.51%17 June 2026
CVE-2026-40783Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.CRITICAL 9.9EPSS 0.54%17 June 2026
CVE-2026-40749Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.CRITICAL 9.9EPSS 0.43%17 June 2026
CVE-2026-40748Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.CRITICAL 9.9EPSS 0.43%17 June 2026
CVE-2026-40747Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.CRITICAL 9.9EPSS 0.43%17 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.