SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,283 results · page 99 of 786

CVESummaryPriorityPublished
CVE-2026-49105Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.CRITICAL 9.8EPSS 0.48%15 June 2026
CVE-2026-49104Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.CRITICAL 9.8EPSS 0.48%15 June 2026
CVE-2026-49085Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.CRITICAL 9.8EPSS 0.48%15 June 2026
CVE-2026-49067Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.CRITICAL 9.3EPSS 0.29%15 June 2026
CVE-2026-48886Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-48881Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.CRITICAL 9.1EPSS 0.28%15 June 2026
CVE-2026-48836Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.CRITICAL 10.0EPSS 0.57%15 June 2026
CVE-2026-45439Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.CRITICAL 9.3EPSS 0.29%15 June 2026
CVE-2026-42665Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-42639Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-42386Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-42381Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-40798Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-40772Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.CRITICAL 10.0EPSS 0.36%15 June 2026
CVE-2026-40771Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-39591Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.CRITICAL 9.9EPSS 0.46%15 June 2026
CVE-2026-39583Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.CRITICAL 9.8EPSS 0.36%15 June 2026
CVE-2026-39530Unauthenticated SQL Injection in SpeakOut!CRITICAL 9.3EPSS 0.30%15 June 2026
CVE-2026-39519Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-39512Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-39511Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.CRITICAL 9.3EPSS 0.29%15 June 2026
CVE-2026-39502Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.CRITICAL 9.3EPSS 0.29%15 June 2026
CVE-2026-39493Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.CRITICAL 9.3EPSS 0.36%15 June 2026
CVE-2026-39492Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.CRITICAL 9.3EPSS 0.36%15 June 2026
CVE-2026-39465Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.CRITICAL 9.1EPSS 0.68%15 June 2026
CVE-2026-39441Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.CRITICAL 9.3EPSS 0.28%15 June 2026
CVE-2026-34901Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.CRITICAL 9.8EPSS 0.32%15 June 2026
CVE-2026-27053Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.CRITICAL 9.8EPSS 0.39%15 June 2026
CVE-2026-50890Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings.CRITICAL 9.8EPSS 0.32%15 June 2026
CVE-2026-50887A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.CRITICAL 9.1EPSS 0.29%15 June 2026
CVE-2026-50886Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.CRITICAL 9.1EPSS 0.31%15 June 2026
CVE-2026-50883An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.CRITICAL 9.6EPSS 0.37%15 June 2026
CVE-2026-50880An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.CRITICAL 9.8EPSS 0.48%15 June 2026
CVE-2026-50873An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.CRITICAL 9.8EPSS 0.44%15 June 2026
CVE-2026-50872An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP request.CRITICAL 9.8EPSS 0.56%15 June 2026
CVE-2026-50871An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.CRITICAL 9.8EPSS 1.57%15 June 2026
CVE-2026-50869An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.CRITICAL 9.8EPSS 0.72%15 June 2026
CVE-2026-49952X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key…EXPLOITCRITICAL 9.3EPSS 4.72%15 June 2026
CVE-2026-48114Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint.CRITICAL 9.8EPSS 0.37%15 June 2026
CVE-2026-45390In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory.CRITICAL 9.1EPSS 0.37%15 June 2026
CVE-2026-45388In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).CRITICAL 9.1EPSS 0.22%15 June 2026
CVE-2026-39196Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function.CRITICAL 9.8EPSS 0.32%15 June 2026
CVE-2026-39006An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.CRITICAL 9.8EPSS 0.52%15 June 2026
CVE-2026-38812RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint.CRITICAL 9.8EPSS 0.39%15 June 2026
CVE-2026-38329Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin.CRITICAL 9.8EPSS 0.63%15 June 2026
CVE-2026-38065Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.CRITICAL 9.8EPSS 1.34%15 June 2026
CVE-2026-38064Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.CRITICAL 9.8EPSS 1.05%15 June 2026
CVE-2026-38063Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.CRITICAL 9.8EPSS 1.05%15 June 2026
CVE-2026-38062Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.CRITICAL 9.8EPSS 1.05%15 June 2026
CVE-2026-38061Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.CRITICAL 9.8EPSS 1.05%15 June 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.