Home/Threat brief
Brief

Threat brief - top critical CVEs of the last 30 days

Top critical CVEs ranked by exploitation risk
This brief ranks recent critical and high-severity CVEs by a composite score combining CVSS, KEV status, EPSS probability, SSVC decision points (exploitation, automatable, impact), public exploit availability, and known actor exploitation. Default window is 14 days. Override window with ?days=N (1-60). Note: ordering is by NVD publication date, not the CVE ID year - a CVE reserved years ago (e.g. CVE-2020-xxxxx) but only disclosed now is genuinely new, so it can appear here.
1

CVE-2026-20182

CRITICAL · CVSS 10

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection ha...

EPSS 0.80539 SSVC exploitation active Automatable yes Published to NVD 2026-05-14T17:16:19.387 Priority score 52
2

CVE-2026-44523

CRITICAL · CVSS 10

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets ...

EPSS 9e-05 SSVC exploitation poc Automatable yes Published to NVD 2026-05-14T19:16:37.470 Priority score 36
3

CVE-2026-44006

CRITICAL · CVSS 10

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.

EPSS 0.00061 SSVC exploitation poc Automatable yes Published to NVD 2026-05-13T18:16:17.387 Priority score 36
4

CVE-2026-44005

CRITICAL · CVSS 10

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and o...

EPSS 0.00108 SSVC exploitation poc Automatable yes Published to NVD 2026-05-13T18:16:17.257 Priority score 36
5

CVE-2026-43997

CRITICAL · CVSS 10

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to ob...

EPSS 0.00022 SSVC exploitation poc Automatable yes Published to NVD 2026-05-13T18:16:16.177 Priority score 36
6

CVE-2026-42288

CRITICAL · CVSS 10

ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard via unsanitized DB_PASSWORD remains fully...

EPSS 0.00328 SSVC exploitation poc Automatable yes Published to NVD 2026-05-12T23:16:17.600 Priority score 36
7

CVE-2026-42869

CRITICAL · CVSS 10

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships ...

EPSS 0.00142 SSVC exploitation poc Automatable yes Published to NVD 2026-05-11T20:25:43.347 Priority score 36
8

CVE-2026-7411

CRITICAL · CVSS 10

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted f...

EPSS 0.00133 SSVC exploitation poc Automatable yes Published to NVD 2026-05-05T16:16:18.360 Priority score 36
9

CVE-2026-25244

CRITICAL · CVSS 9.8

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orches...

EPSS 0.0015 SSVC exploitation poc Automatable yes Published to NVD 2026-05-18T21:16:39.547 Priority score 35
10

CVE-2018-25332

CRITICAL · CVSS 9.8

GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. Attackers can brute-forc...

EPSS 0.00199 SSVC exploitation poc Automatable yes Published to NVD 2026-05-17T13:16:44.840 Priority score 35
11

CVE-2018-25320

CRITICAL · CVSS 9.8

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious Power...

EPSS 0.00128 SSVC exploitation poc Automatable yes Published to NVD 2026-05-17T13:16:43.270 Priority score 35
12

CVE-2021-47952

CRITICAL · CVSS 9.8

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/...

EPSS 0.004 SSVC exploitation poc Automatable yes Published to NVD 2026-05-16T16:16:21.520 Priority score 35
13

CVE-2020-37239

CRITICAL · CVSS 9.8

libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without ...

EPSS 0.00112 SSVC exploitation poc Automatable yes Published to NVD 2026-05-16T16:16:20.097 Priority score 35
14

CVE-2020-37228

CRITICAL · CVSS 9.8

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login en...

EPSS 0.00095 SSVC exploitation poc Automatable yes Published to NVD 2026-05-16T16:16:18.667 Priority score 35
15

CVE-2021-47965

CRITICAL · CVSS 9.8

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files thr...

EPSS 0.00319 SSVC exploitation poc Automatable yes Published to NVD 2026-05-15T19:16:56.163 Priority score 35
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin