Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,648 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,244 results · page 29 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-65905 | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. | CRITICAL 9.8EPSS 0.77% | 25 August 2026 |
| CVE-2026-65637 | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. | CRITICAL 9.8EPSS 0.75% | 25 August 2026 |
| CVE-2026-65182 | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. | CRITICAL 9.1EPSS 0.59% | 25 August 2026 |
| CVE-2026-62862 | In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. | CRITICAL 9.1EPSS 0.51% | 25 August 2026 |
| CVE-2026-80104 | A remote attacker holding no account can therefore write attacker-controlled bytes to any path the server process can write, place a new Python module inside the application package or replace one the application already imports, and obtain code… | CRITICAL 9.3EPSS 0.71% | 25 August 2026 |
| CVE-2026-79290 | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79282 | Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 25 August 2026 |
| CVE-2026-79275 | Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 25 August 2026 |
| CVE-2026-79257 | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79235 | Use after free in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79232 | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79200 | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79189 | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79188 | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 25 August 2026 |
| CVE-2026-79152 | Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. | CRITICAL 9.8EPSS 0.24% | 25 August 2026 |
| CVE-2026-79150 | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 25 August 2026 |
| CVE-2026-79149 | Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 25 August 2026 |
| CVE-2026-79148 | Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially read memory inside the sandbox via a crafted Chrome extension. | CRITICAL 9.1EPSS 0.26% | 25 August 2026 |
| CVE-2026-79140 | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 25 August 2026 |
| CVE-2026-79138 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79131 | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 25 August 2026 |
| CVE-2026-79130 | Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.42% | 25 August 2026 |
| CVE-2026-79129 | Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. | CRITICAL 9.6EPSS 0.34% | 25 August 2026 |
| CVE-2026-79128 | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79111 | Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79091 | Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.34% | 25 August 2026 |
| CVE-2026-79090 | Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. | CRITICAL 9.8EPSS 0.39% | 25 August 2026 |
| CVE-2026-79078 | Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-79064 | Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. | CRITICAL 9.6EPSS 0.39% | 25 August 2026 |
| CVE-2026-79058 | Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. | CRITICAL 9.1EPSS 0.32% | 25 August 2026 |
| CVE-2026-79056 | Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.40% | 25 August 2026 |
| CVE-2026-79052 | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.44% | 25 August 2026 |
| CVE-2026-79047 | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.43% | 25 August 2026 |
| CVE-2026-79043 | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.43% | 25 August 2026 |
| CVE-2026-79026 | Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. | CRITICAL 9.6EPSS 0.43% | 25 August 2026 |
| CVE-2026-79019 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 25 August 2026 |
| CVE-2026-79012 | Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.55% | 25 August 2026 |
| CVE-2026-78989 | Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.55% | 25 August 2026 |
| CVE-2026-78985 | Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.59% | 25 August 2026 |
| CVE-2026-78964 | Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 25 August 2026 |
| CVE-2026-78951 | Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 25 August 2026 |
| CVE-2026-78948 | Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 25 August 2026 |
| CVE-2026-78945 | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-78939 | Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-78937 | Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.37% | 25 August 2026 |
| CVE-2026-78935 | Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.51% | 25 August 2026 |
| CVE-2026-78909 | Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.43% | 25 August 2026 |
| CVE-2026-78904 | Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 25 August 2026 |
| CVE-2026-78900 | Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.43% | 25 August 2026 |
| CVE-2026-65098 | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. | CRITICAL 9.8EPSS 0.67% | 25 August 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.