SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,283 results · page 95 of 786

CVESummaryPriorityPublished
CVE-2026-40746Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.CRITICAL 9.9EPSS 0.43%17 June 2026
CVE-2026-40725Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.CRITICAL 9.8EPSS 0.38%17 June 2026
CVE-2026-39596Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.CRITICAL 9.3EPSS 0.37%17 June 2026
CVE-2026-39589Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.CRITICAL 9.9EPSS 0.45%17 June 2026
CVE-2026-39529Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.CRITICAL 9.8EPSS 0.38%17 June 2026
CVE-2026-39438Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.CRITICAL 9.3EPSS 0.37%17 June 2026
CVE-2026-32967Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.CRITICAL 9.1EPSS 0.34%17 June 2026
CVE-2026-32966DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.CRITICAL 9.8EPSS 0.39%17 June 2026
CVE-2026-28615In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass.CRITICAL 10.0EPSS 0.12%17 June 2026
CVE-2026-28587In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check.CRITICAL 10.0EPSS 0.11%17 June 2026
CVE-2026-28576In Contacts Provider, there is a possible way to access the contacts database due to SQL injection.CRITICAL 10.0EPSS 0.15%17 June 2026
CVE-2026-28575This could lead to local denial of service with no additional execution privileges needed.CRITICAL 10.0EPSS 0.13%17 June 2026
CVE-2026-27429Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.CRITICAL 9.8EPSS 0.56%17 June 2026
CVE-2026-27395Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.CRITICAL 9.8EPSS 0.34%17 June 2026
CVE-2026-27041Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.CRITICAL 9.9EPSS 0.32%17 June 2026
CVE-2026-25470Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.CRITICAL 10.0EPSS 0.65%17 June 2026
CVE-2026-25446Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.CRITICAL 9.9EPSS 0.43%17 June 2026
CVE-2026-24611Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.CRITICAL 9.1EPSS 0.44%17 June 2026
CVE-2026-22340Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.CRITICAL 9.3EPSS 0.37%17 June 2026
CVE-2026-22332Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.CRITICAL 9.3EPSS 0.28%17 June 2026
CVE-2026-22327Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.CRITICAL 9.9EPSS 0.46%17 June 2026
CVE-2026-12440Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.25%17 June 2026
CVE-2026-10094A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitrary files on the server.CRITICAL 9.8EPSS 0.38%17 June 2026
CVE-2026-0092In Package Manager, there is a possible device lock controller bypass due to a missing permission check.CRITICAL 10.0EPSS 0.22%17 June 2026
CVE-2026-0083In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition.CRITICAL 10.0EPSS 0.12%17 June 2026
CVE-2026-0082In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value.CRITICAL 10.0EPSS 0.17%17 June 2026
CVE-2026-0081In NFC, there is a possible way to spoof an NFC event due to a missing permission check.CRITICAL 10.0EPSS 0.15%17 June 2026
CVE-2026-0071In SettingsLib, there is a possible missing permission check due to a logic error in the code.CRITICAL 10.0EPSS 0.15%17 June 2026
CVE-2026-0068This could lead to local escalation of privilege if a user can install a malicious app with no additional execution privileges needed.CRITICAL 10.0EPSS 0.12%17 June 2026
CVE-2026-0064In multiple places, there is a possible persistent denial of service due to resource exhaustion.CRITICAL 10.0EPSS 0.12%17 June 2026
CVE-2026-0063In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the code.CRITICAL 10.0EPSS 0.15%17 June 2026
CVE-2025-69179Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.CRITICAL 9.8EPSS 0.45%17 June 2026
CVE-2025-69129Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.CRITICAL 10.0EPSS 0.43%17 June 2026
CVE-2025-69122Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.CRITICAL 9.8EPSS 0.53%17 June 2026
CVE-2025-69108Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.CRITICAL 9.8EPSS 0.53%17 June 2026
CVE-2025-60218Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.CRITICAL 9.9EPSS 0.45%17 June 2026
CVE-2025-60205Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.CRITICAL 9.8EPSS 0.53%17 June 2026
CVE-2025-59872HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to…CRITICAL 9.8EPSS 0.45%17 June 2026
CVE-2024-52488Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.CRITICAL 9.9EPSS 0.47%17 June 2026
CVE-2026-48776Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations.CRITICAL 9.1EPSS 0.22%17 June 2026
CVE-2026-46978Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon).CRITICAL 10.0EPSS 0.31%17 June 2026
CVE-2026-46964Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration).CRITICAL 9.9EPSS 0.40%17 June 2026
CVE-2026-46963Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration).CRITICAL 9.9EPSS 0.40%17 June 2026
CVE-2026-46949Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.1EPSS 0.40%17 June 2026
CVE-2026-46946Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.1EPSS 0.46%17 June 2026
CVE-2026-46945Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.1EPSS 0.46%17 June 2026
CVE-2026-46944Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.1EPSS 0.45%17 June 2026
CVE-2026-46933Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.9EPSS 0.41%17 June 2026
CVE-2026-46930Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.1EPSS 0.40%17 June 2026
CVE-2026-46919Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).CRITICAL 9.8EPSS 0.36%17 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.