Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,241 results · page 15 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-87637 | Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 9 September 2026 |
| CVE-2026-87634 | Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 9 September 2026 |
| CVE-2026-87621 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 9 September 2026 |
| CVE-2026-87613 | Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. | CRITICAL 9.0EPSS 0.35% | 9 September 2026 |
| CVE-2026-87609 | Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. | CRITICAL 9.6EPSS 0.39% | 9 September 2026 |
| CVE-2026-87607 | Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.42% | 9 September 2026 |
| CVE-2026-87595 | Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. | CRITICAL 9.8EPSS 0.31% | 9 September 2026 |
| CVE-2026-87581 | Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.42% | 9 September 2026 |
| CVE-2026-87558 | Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 9 September 2026 |
| CVE-2026-87547 | Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.43% | 9 September 2026 |
| CVE-2026-87544 | Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. | CRITICAL 9.8EPSS 0.20% | 9 September 2026 |
| CVE-2026-87534 | Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. | CRITICAL 9.8EPSS 0.21% | 9 September 2026 |
| CVE-2026-87529 | Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.46% | 9 September 2026 |
| CVE-2026-87528 | Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.35% | 9 September 2026 |
| CVE-2026-87527 | Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 9 September 2026 |
| CVE-2026-87526 | Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. | CRITICAL 9.6EPSS 0.36% | 9 September 2026 |
| CVE-2026-87520 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 9 September 2026 |
| CVE-2026-87512 | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 9 September 2026 |
| CVE-2026-87504 | Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. | CRITICAL 9.6EPSS 0.39% | 9 September 2026 |
| CVE-2026-87500 | Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 9 September 2026 |
| CVE-2026-87494 | Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 9 September 2026 |
| CVE-2026-87492 | Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 9 September 2026 |
| CVE-2026-87488 | Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 9 September 2026 |
| CVE-2026-87474 | Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 9 September 2026 |
| CVE-2026-87470 | Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 9 September 2026 |
| CVE-2026-87464 | Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.59% | 9 September 2026 |
| CVE-2026-87455 | Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.42% | 9 September 2026 |
| CVE-2026-87448 | Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 9 September 2026 |
| CVE-2026-87438 | Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.55% | 9 September 2026 |
| CVE-2026-53939 | OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). | CRITICAL 9.1EPSS 0.20% | 9 September 2026 |
| CVE-2026-53581 | Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. | CRITICAL 9.0EPSS 0.33% | 8 September 2026 |
| CVE-2026-85982 | The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. | CRITICAL 9.0EPSS 0.22% | 8 September 2026 |
| CVE-2026-86464 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. | CRITICAL 9.9EPSS 0.35% | 8 September 2026 |
| CVE-2026-84869 | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | KEVCRITICAL 9.9EPSS 0.69% | 8 September 2026 |
| CVE-2026-84197 | In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket… | CRITICAL 9.2EPSS 0.20% | 8 September 2026 |
| CVE-2026-75746 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.1EPSS 1.07% | 8 September 2026 |
| CVE-2026-49883 | In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. | CRITICAL 10.0EPSS 0.12% | 8 September 2026 |
| CVE-2026-48273 | ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.9EPSS 1.90% | 8 September 2026 |
| CVE-2026-28659 | In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. | CRITICAL 10.0EPSS 0.13% | 8 September 2026 |
| CVE-2026-19232 | Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. | CRITICAL 9.9EPSS 0.57% | 8 September 2026 |
| CVE-2026-82004 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 10.0EPSS 1.44% | 8 September 2026 |
| CVE-2026-76201 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. | CRITICAL 9.3EPSS 0.46% | 8 September 2026 |
| CVE-2026-76200 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. | CRITICAL 9.3EPSS 0.46% | 8 September 2026 |
| CVE-2026-66302 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.53% | 8 September 2026 |
| CVE-2026-58822 | In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. | CRITICAL 9.8EPSS 0.31% | 8 September 2026 |
| CVE-2026-49921 | In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. | CRITICAL 9.8EPSS 0.32% | 8 September 2026 |
| CVE-2026-28606 | This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. | CRITICAL 9.8EPSS 0.29% | 8 September 2026 |
| CVE-2026-81376 | Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | CRITICAL 9.6EPSS 0.65% | 8 September 2026 |
| CVE-2026-78510 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.95% | 8 September 2026 |
| CVE-2026-78509 | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | CRITICAL 9.8EPSS 0.95% | 8 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.