Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026
39,238 results · page 6 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-91718 | Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.33% | 15 September 2026 |
| CVE-2026-91716 | Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.31% | 15 September 2026 |
| CVE-2026-91710 | Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. | CRITICAL 9.6EPSS 0.31% | 15 September 2026 |
| CVE-2026-68491 | An insufficient check allowed for the overwrite of arbitrary files via a symlink. | CRITICAL 9.4EPSS 0.33% | 15 September 2026 |
| CVE-2026-66890 | The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable. | CRITICAL 9.4EPSS 0.20% | 15 September 2026 |
| CVE-2026-66887 | The affected products are missing authorization on state-changing CGIs and session checks are not performed. | CRITICAL 9.4EPSS 0.20% | 15 September 2026 |
| CVE-2026-61568 | Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. | CRITICAL 9.6EPSS 0.32% | 15 September 2026 |
| CVE-2026-61559 | The server validates that the value is a well-formed URL (`new URL(dynamicApiUrl)`) but applies no allowlist or hostname restriction. | CRITICAL 9.6EPSS 0.27% | 15 September 2026 |
| CVE-2026-54337 | Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. | CRITICAL 9.8EPSS 0.44% | 15 September 2026 |
| CVE-2026-89040 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. | CRITICAL 9.3EPSS 0.93% | 15 September 2026 |
| CVE-2026-87230 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 10.0EPSS 0.38% | 15 September 2026 |
| CVE-2026-87223 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.1EPSS 0.30% | 15 September 2026 |
| CVE-2026-87217 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.1EPSS 0.38% | 15 September 2026 |
| CVE-2026-87214 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.1EPSS 0.32% | 15 September 2026 |
| CVE-2026-87189 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.1EPSS 0.46% | 15 September 2026 |
| CVE-2026-87188 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.8EPSS 0.36% | 15 September 2026 |
| CVE-2026-87186 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.6EPSS 0.19% | 15 September 2026 |
| CVE-2026-87184 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-87176 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.1EPSS 0.40% | 15 September 2026 |
| CVE-2026-87175 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.1EPSS 0.31% | 15 September 2026 |
| CVE-2026-87173 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.1EPSS 0.40% | 15 September 2026 |
| CVE-2026-87172 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.9EPSS 0.31% | 15 September 2026 |
| CVE-2026-87170 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). | CRITICAL 9.1EPSS 0.40% | 15 September 2026 |
| CVE-2026-87129 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). | CRITICAL 9.1EPSS 0.31% | 15 September 2026 |
| CVE-2026-87128 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). | CRITICAL 9.1EPSS 0.40% | 15 September 2026 |
| CVE-2026-83462 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83452 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83355 | Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). | CRITICAL 9.8EPSS 0.36% | 15 September 2026 |
| CVE-2026-83339 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83327 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). | CRITICAL 9.8EPSS 0.48% | 15 September 2026 |
| CVE-2026-83283 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). | CRITICAL 9.8EPSS 0.45% | 15 September 2026 |
| CVE-2026-83282 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). | CRITICAL 9.9EPSS 0.29% | 15 September 2026 |
| CVE-2026-83269 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). | CRITICAL 9.8EPSS 0.36% | 15 September 2026 |
| CVE-2026-83268 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). | CRITICAL 9.1EPSS 0.34% | 15 September 2026 |
| CVE-2026-83261 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). | CRITICAL 9.8EPSS 0.36% | 15 September 2026 |
| CVE-2026-83260 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Event Java PX). | CRITICAL 9.1EPSS 0.46% | 15 September 2026 |
| CVE-2026-83232 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer). | CRITICAL 9.8EPSS 0.33% | 15 September 2026 |
| CVE-2026-83229 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). | CRITICAL 9.1EPSS 0.34% | 15 September 2026 |
| CVE-2026-83202 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). | CRITICAL 9.1EPSS 0.40% | 15 September 2026 |
| CVE-2026-83201 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). | CRITICAL 9.1EPSS 0.31% | 15 September 2026 |
| CVE-2026-83197 | Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). | CRITICAL 9.1EPSS 0.37% | 15 September 2026 |
| CVE-2026-83196 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). | CRITICAL 9.1EPSS 0.34% | 15 September 2026 |
| CVE-2026-83154 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). | CRITICAL 9.1EPSS 0.31% | 15 September 2026 |
| CVE-2026-83151 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | CRITICAL 9.8EPSS 0.36% | 15 September 2026 |
| CVE-2026-83149 | Vulnerability in Oracle Application Testing Suite. | CRITICAL 9.1EPSS 0.26% | 15 September 2026 |
| CVE-2026-83108 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 9.8EPSS 0.45% | 15 September 2026 |
| CVE-2026-83107 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 9.1EPSS 0.44% | 15 September 2026 |
| CVE-2026-83105 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 9.0EPSS 0.36% | 15 September 2026 |
| CVE-2026-83104 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 9.1EPSS 0.40% | 15 September 2026 |
| CVE-2026-83103 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). | CRITICAL 9.1EPSS 0.44% | 15 September 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.