SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,283 results · page 98 of 786

CVESummaryPriorityPublished
CVE-2026-35292Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console).CRITICAL 10.0EPSS 0.48%17 June 2026
CVE-2026-35286Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).CRITICAL 9.8EPSS 0.48%17 June 2026
CVE-2026-35285Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.41%17 June 2026
CVE-2026-35284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.41%17 June 2026
CVE-2026-35283Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.41%17 June 2026
CVE-2026-35282Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.40%17 June 2026
CVE-2026-35281Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.48%17 June 2026
CVE-2026-35280Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.9EPSS 0.48%17 June 2026
CVE-2026-35278Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor).CRITICAL 9.8EPSS 0.64%17 June 2026
CVE-2026-35270Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).CRITICAL 9.1EPSS 0.50%17 June 2026
CVE-2026-35268Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core).CRITICAL 9.9EPSS 0.52%17 June 2026
CVE-2026-35263Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core).CRITICAL 9.9EPSS 0.36%17 June 2026
CVE-2026-48777Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields with the trusted d.share.Path BEFORE the…CRITICAL 9.3EPSS 0.45%16 June 2026
CVE-2026-22313The device has a webserver that exposes a REST API authenticated with a token on the management network.CRITICAL 9.1EPSS 0.92%16 June 2026
CVE-2026-0126In WC-Radio, there is a possible out of bounds write due to a missing bounds check.CRITICAL 9.8EPSS 0.28%16 June 2026
CVE-2026-53776Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path.CRITICAL 9.3EPSS 0.36%16 June 2026
CVE-2025-13036An authentication bypass security issue exists within FactoryTalk Historian Site Edition.CRITICAL 9.2EPSS 0.29%16 June 2026
CVE-2026-12316Mitigation bypass in the DOM: Security component.CRITICAL 9.1EPSS 0.24%16 June 2026
CVE-2026-12315Mitigation bypass in the DOM: Security component.CRITICAL 9.1EPSS 0.25%16 June 2026
CVE-2026-12304Same-origin policy bypass in the Networking: Cookies component.CRITICAL 9.1EPSS 0.19%16 June 2026
CVE-2026-12297This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.CRITICAL 9.6EPSS 0.39%16 June 2026
CVE-2026-12296This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.CRITICAL 9.6EPSS 0.39%16 June 2026
CVE-2026-12295This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.CRITICAL 9.6EPSS 0.39%16 June 2026
CVE-2026-12294This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.CRITICAL 9.6EPSS 0.36%16 June 2026
CVE-2026-12293Use-after-free in the Graphics: WebGPU component.CRITICAL 9.8EPSS 0.30%16 June 2026
CVE-2026-40750Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server.CRITICAL 9.9EPSS 0.27%16 June 2026
CVE-2026-52715Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.CRITICAL 9.3EPSS 0.24%16 June 2026
CVE-2026-49774Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion.CRITICAL 9.9EPSS 0.28%16 June 2026
CVE-2026-49772Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection.CRITICAL 9.3EPSS 0.35%16 June 2026
CVE-2026-39574Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.CRITICAL 9.3EPSS 0.23%16 June 2026
CVE-2026-48853Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call…CRITICAL 9.2EPSS 0.57%15 June 2026
CVE-2026-12205Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery.CRITICAL 9.1EPSS 0.29%15 June 2026
CVE-2026-48714In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did not reject dotted variants such as "__proto__.polluted".CRITICAL 9.1EPSS 0.51%15 June 2026
CVE-2026-48713Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input).CRITICAL 9.1EPSS 0.51%15 June 2026
CVE-2026-12087Socket versions before 2.041 for Perl have an out-of-bounds heap read.CRITICAL 9.1EPSS 0.37%15 June 2026
CVE-2026-11832Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce.CRITICAL 9.1EPSS 0.33%15 June 2026
CVE-2026-9691Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.CRITICAL 9.8EPSS 0.48%15 June 2026
CVE-2026-52703Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.CRITICAL 9.6EPSS 0.44%15 June 2026
CVE-2026-52693Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.CRITICAL 9.3EPSS 0.29%15 June 2026
CVE-2026-49781Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.CRITICAL 9.8EPSS 0.50%15 June 2026
CVE-2026-49776Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.CRITICAL 9.3EPSS 0.29%15 June 2026
CVE-2026-49770Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.CRITICAL 9.8EPSS 0.38%15 June 2026
CVE-2026-49769Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.CRITICAL 9.8EPSS 0.38%15 June 2026
CVE-2026-49768Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.CRITICAL 9.8EPSS 0.38%15 June 2026
CVE-2026-49766Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.CRITICAL 9.9EPSS 0.51%15 June 2026
CVE-2026-49765Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.CRITICAL 9.8EPSS 0.38%15 June 2026
CVE-2026-49764Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.CRITICAL 9.8EPSS 0.40%15 June 2026
CVE-2026-49763Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.CRITICAL 9.8EPSS 0.38%15 June 2026
CVE-2026-49109Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.CRITICAL 9.8EPSS 0.38%15 June 2026
CVE-2026-49106Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.CRITICAL 9.8EPSS 0.38%15 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.