SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,626 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,241 results · page 15 of 785

CVESummaryPriorityPublished
CVE-2026-87637Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.32%9 September 2026
CVE-2026-87634Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.40%9 September 2026
CVE-2026-87621Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.32%9 September 2026
CVE-2026-87613Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic.CRITICAL 9.0EPSS 0.35%9 September 2026
CVE-2026-87609Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic.CRITICAL 9.6EPSS 0.39%9 September 2026
CVE-2026-87607Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.42%9 September 2026
CVE-2026-87595Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page.CRITICAL 9.8EPSS 0.31%9 September 2026
CVE-2026-87581Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.42%9 September 2026
CVE-2026-87558Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.40%9 September 2026
CVE-2026-87547Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.43%9 September 2026
CVE-2026-87544Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page.CRITICAL 9.8EPSS 0.20%9 September 2026
CVE-2026-87534Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic.CRITICAL 9.8EPSS 0.21%9 September 2026
CVE-2026-87529Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.46%9 September 2026
CVE-2026-87528Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.35%9 September 2026
CVE-2026-87527Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.47%9 September 2026
CVE-2026-87526Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction.CRITICAL 9.6EPSS 0.36%9 September 2026
CVE-2026-87520Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.40%9 September 2026
CVE-2026-87512Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.49%9 September 2026
CVE-2026-87504Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension.CRITICAL 9.6EPSS 0.39%9 September 2026
CVE-2026-87500Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.34%9 September 2026
CVE-2026-87494Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.34%9 September 2026
CVE-2026-87492Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.33%9 September 2026
CVE-2026-87488Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.49%9 September 2026
CVE-2026-87474Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.49%9 September 2026
CVE-2026-87470Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.40%9 September 2026
CVE-2026-87464Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.59%9 September 2026
CVE-2026-87455Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.42%9 September 2026
CVE-2026-87448Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.49%9 September 2026
CVE-2026-87438Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.55%9 September 2026
CVE-2026-53939OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE).CRITICAL 9.1EPSS 0.20%9 September 2026
CVE-2026-53581Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user.CRITICAL 9.0EPSS 0.33%8 September 2026
CVE-2026-85982The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel.CRITICAL 9.0EPSS 0.22%8 September 2026
CVE-2026-86464In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services.CRITICAL 9.9EPSS 0.35%8 September 2026
CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization VulnerabilityKEVCRITICAL 9.9EPSS 0.69%8 September 2026
CVE-2026-84197In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket…CRITICAL 9.2EPSS 0.20%8 September 2026
CVE-2026-75746ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.1EPSS 1.07%8 September 2026
CVE-2026-49883In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check.CRITICAL 10.0EPSS 0.12%8 September 2026
CVE-2026-48273ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 9.9EPSS 1.90%8 September 2026
CVE-2026-28659In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check.CRITICAL 10.0EPSS 0.13%8 September 2026
CVE-2026-19232Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session.CRITICAL 9.9EPSS 0.57%8 September 2026
CVE-2026-82004Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user.CRITICAL 10.0EPSS 1.44%8 September 2026
CVE-2026-76201Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.CRITICAL 9.3EPSS 0.46%8 September 2026
CVE-2026-76200Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.CRITICAL 9.3EPSS 0.46%8 September 2026
CVE-2026-66302External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.53%8 September 2026
CVE-2026-58822In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting.CRITICAL 9.8EPSS 0.31%8 September 2026
CVE-2026-49921In multiple locations, there is a possible memory safety issue due to a heap buffer overflow.CRITICAL 9.8EPSS 0.32%8 September 2026
CVE-2026-28606This could lead to remote escalation of privilege without user consent with no additional execution privileges needed.CRITICAL 9.8EPSS 0.29%8 September 2026
CVE-2026-81376Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.CRITICAL 9.6EPSS 0.65%8 September 2026
CVE-2026-78510Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.95%8 September 2026
CVE-2026-78509Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.CRITICAL 9.8EPSS 0.95%8 September 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.