Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,284 results · page 104 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-11066 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.25% | 4 June 2026 |
| CVE-2026-11065 | Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 4 June 2026 |
| CVE-2026-11063 | Insufficient validation of untrusted input in WebNN in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11061 | Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.25% | 4 June 2026 |
| CVE-2026-11056 | Insufficient validation of untrusted input in SiteIsolation in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11052 | Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.26% | 4 June 2026 |
| CVE-2026-11047 | Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.30% | 4 June 2026 |
| CVE-2026-11043 | Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.30% | 4 June 2026 |
| CVE-2026-11037 | Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. | CRITICAL 9.6EPSS 0.28% | 4 June 2026 |
| CVE-2026-11029 | Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.23% | 4 June 2026 |
| CVE-2026-11021 | Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 4 June 2026 |
| CVE-2026-11009 | Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 4 June 2026 |
| CVE-2026-11002 | Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.30% | 4 June 2026 |
| CVE-2026-10990 | Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.30% | 4 June 2026 |
| CVE-2026-10983 | Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 4 June 2026 |
| CVE-2026-10974 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 4 June 2026 |
| CVE-2026-10972 | Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 4 June 2026 |
| CVE-2026-10971 | Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 4 June 2026 |
| CVE-2026-10966 | Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. | CRITICAL 9.6EPSS 0.30% | 4 June 2026 |
| CVE-2026-10931 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 4 June 2026 |
| CVE-2026-10892 | Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 4 June 2026 |
| CVE-2026-10886 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 4 June 2026 |
| CVE-2026-10881 | Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.39% | 4 June 2026 |
| CVE-2025-71316 | An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. | CRITICAL 9.2EPSS 0.38% | 4 June 2026 |
| CVE-2026-50292 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution | CRITICAL 9.8EPSS 0.31% | 4 June 2026 |
| CVE-2026-25550 | Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. | CRITICAL 9.3EPSS 0.88% | 4 June 2026 |
| CVE-2026-10880 | OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. | CRITICAL 9.8EPSS 0.44% | 4 June 2026 |
| CVE-2025-67447 | The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. | CRITICAL 9.8EPSS 1.03% | 4 June 2026 |
| CVE-2026-50076 | Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke… | CRITICAL 9.1EPSS 0.52% | 4 June 2026 |
| CVE-2025-67446 | Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. | CRITICAL 9.8EPSS 0.45% | 4 June 2026 |
| CVE-2026-43986 | Versions prior to 2.17.1 expose a public `/image/<hash>` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-side image fetch logic used by authenticated image proxying. | CRITICAL 9.9EPSS 0.26% | 4 June 2026 |
| CVE-2026-36182 | GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack. | CRITICAL 9.8EPSS 0.19% | 4 June 2026 |
| CVE-2026-10868 | A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). | CRITICAL 9.0EPSS 0.24% | 4 June 2026 |
| CVE-2026-35906 | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via supplying a crafted HTTP query string. | CRITICAL 9.6EPSS 0.47% | 4 June 2026 |
| CVE-2026-35905 | T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account. | CRITICAL 9.8EPSS 0.42% | 4 June 2026 |
| CVE-2026-35904 | Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via sending a crafted request to a vulnerable CGI component. | CRITICAL 9.8EPSS 0.55% | 4 June 2026 |
| CVE-2026-8037 | Progress LoadMaster Command Injection Vulnerability | KEVCRITICAL 9.8EPSS 99.6% | 4 June 2026 |
| CVE-2019-25741 | Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. | CRITICAL 9.3EPSS 0.64% | 4 June 2026 |
| CVE-2019-25738 | WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. | CRITICAL 9.3EPSS 0.35% | 4 June 2026 |
| CVE-2019-25729 | PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. | CRITICAL 9.3EPSS 0.26% | 4 June 2026 |
| CVE-2019-25727 | WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. | CRITICAL 9.3EPSS 0.46% | 4 June 2026 |
| CVE-2026-4104 | Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. | CRITICAL 9.8EPSS 0.30% | 4 June 2026 |
| CVE-2026-50214 | The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans. | CRITICAL 9.3EPSS 0.17% | 4 June 2026 |
| CVE-2026-50209 | Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker. | CRITICAL 9.3EPSS 0.10% | 4 June 2026 |
| CVE-2026-50208 | Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic. | CRITICAL 9.2EPSS 0.14% | 4 June 2026 |
| CVE-2026-49194 | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface. | CRITICAL 9.4EPSS 0.23% | 4 June 2026 |
| CVE-2026-49191 | The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages. | CRITICAL 9.3EPSS 0.29% | 4 June 2026 |
| CVE-2026-49190 | The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions. | CRITICAL 9.4EPSS 0.43% | 4 June 2026 |
| CVE-2026-49185 | The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection. | CRITICAL 10.0EPSS 0.39% | 4 June 2026 |
| CVE-2026-41283 | OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. | CRITICAL 9.9EPSS 0.73% | 4 June 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.