SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,244 results · page 29 of 785

CVESummaryPriorityPublished
CVE-2026-65905Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator.CRITICAL 9.8EPSS 0.77%25 August 2026
CVE-2026-65637Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.CRITICAL 9.8EPSS 0.75%25 August 2026
CVE-2026-65182Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.CRITICAL 9.1EPSS 0.59%25 August 2026
CVE-2026-62862In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover.CRITICAL 9.1EPSS 0.51%25 August 2026
CVE-2026-80104A remote attacker holding no account can therefore write attacker-controlled bytes to any path the server process can write, place a new Python module inside the application package or replace one the application already imports, and obtain code…CRITICAL 9.3EPSS 0.71%25 August 2026
CVE-2026-79290Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79282Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.40%25 August 2026
CVE-2026-79275Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.47%25 August 2026
CVE-2026-79257Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79235Use after free in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79232Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79200Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79189Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79188Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.47%25 August 2026
CVE-2026-79152Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app.CRITICAL 9.8EPSS 0.24%25 August 2026
CVE-2026-79150Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.47%25 August 2026
CVE-2026-79149Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.47%25 August 2026
CVE-2026-79148Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially read memory inside the sandbox via a crafted Chrome extension.CRITICAL 9.1EPSS 0.26%25 August 2026
CVE-2026-79140Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.47%25 August 2026
CVE-2026-79138Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79131Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.47%25 August 2026
CVE-2026-79130Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.42%25 August 2026
CVE-2026-79129Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction.CRITICAL 9.6EPSS 0.34%25 August 2026
CVE-2026-79128Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79111Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79091Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.34%25 August 2026
CVE-2026-79090Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page.CRITICAL 9.8EPSS 0.39%25 August 2026
CVE-2026-79078Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-79064Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension.CRITICAL 9.6EPSS 0.39%25 August 2026
CVE-2026-79058Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page.CRITICAL 9.1EPSS 0.32%25 August 2026
CVE-2026-79056Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.40%25 August 2026
CVE-2026-79052Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.44%25 August 2026
CVE-2026-79047Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.43%25 August 2026
CVE-2026-79043Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.43%25 August 2026
CVE-2026-79026Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension.CRITICAL 9.6EPSS 0.43%25 August 2026
CVE-2026-79019Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.47%25 August 2026
CVE-2026-79012Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.55%25 August 2026
CVE-2026-78989Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.55%25 August 2026
CVE-2026-78985Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.59%25 August 2026
CVE-2026-78964Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.49%25 August 2026
CVE-2026-78951Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.49%25 August 2026
CVE-2026-78948Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.49%25 August 2026
CVE-2026-78945Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-78939Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-78937Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.37%25 August 2026
CVE-2026-78935Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.51%25 August 2026
CVE-2026-78909Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.43%25 August 2026
CVE-2026-78904Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.47%25 August 2026
CVE-2026-78900Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.43%25 August 2026
CVE-2026-65098NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.CRITICAL 9.8EPSS 0.67%25 August 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.