SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,605 CVEs1,716 in CISA KEV17,391 with EPSS ≥ 10%25,049 with a public exploitUpdated 20 September 2026

39,238 results · page 6 of 785

CVESummaryPriorityPublished
CVE-2026-91718Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.33%15 September 2026
CVE-2026-91716Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.31%15 September 2026
CVE-2026-91710Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.CRITICAL 9.6EPSS 0.31%15 September 2026
CVE-2026-68491An insufficient check allowed for the overwrite of arbitrary files via a symlink.CRITICAL 9.4EPSS 0.33%15 September 2026
CVE-2026-66890The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.CRITICAL 9.4EPSS 0.20%15 September 2026
CVE-2026-66887The affected products are missing authorization on state-changing CGIs and session checks are not performed.CRITICAL 9.4EPSS 0.20%15 September 2026
CVE-2026-61568Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist.CRITICAL 9.6EPSS 0.32%15 September 2026
CVE-2026-61559The server validates that the value is a well-formed URL (`new URL(dynamicApiUrl)`) but applies no allowlist or hostname restriction.CRITICAL 9.6EPSS 0.27%15 September 2026
CVE-2026-54337Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files.CRITICAL 9.8EPSS 0.44%15 September 2026
CVE-2026-89040Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device.CRITICAL 9.3EPSS 0.93%15 September 2026
CVE-2026-87230Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 10.0EPSS 0.38%15 September 2026
CVE-2026-87223Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.1EPSS 0.30%15 September 2026
CVE-2026-87217Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.1EPSS 0.38%15 September 2026
CVE-2026-87214Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.1EPSS 0.32%15 September 2026
CVE-2026-87189Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.1EPSS 0.46%15 September 2026
CVE-2026-87188Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.8EPSS 0.36%15 September 2026
CVE-2026-87186Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.6EPSS 0.19%15 September 2026
CVE-2026-87184Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.8EPSS 0.48%15 September 2026
CVE-2026-87176Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.1EPSS 0.40%15 September 2026
CVE-2026-87175Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.1EPSS 0.31%15 September 2026
CVE-2026-87173Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.1EPSS 0.40%15 September 2026
CVE-2026-87172Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.9EPSS 0.31%15 September 2026
CVE-2026-87170Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).CRITICAL 9.1EPSS 0.40%15 September 2026
CVE-2026-87129Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).CRITICAL 9.1EPSS 0.31%15 September 2026
CVE-2026-87128Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).CRITICAL 9.1EPSS 0.40%15 September 2026
CVE-2026-83462Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server).CRITICAL 9.8EPSS 0.48%15 September 2026
CVE-2026-83452Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations).CRITICAL 9.8EPSS 0.48%15 September 2026
CVE-2026-83355Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics).CRITICAL 9.8EPSS 0.36%15 September 2026
CVE-2026-83339Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL 9.8EPSS 0.48%15 September 2026
CVE-2026-83327Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization).CRITICAL 9.8EPSS 0.48%15 September 2026
CVE-2026-83283Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).CRITICAL 9.8EPSS 0.45%15 September 2026
CVE-2026-83282Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).CRITICAL 9.9EPSS 0.29%15 September 2026
CVE-2026-83269Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).CRITICAL 9.8EPSS 0.36%15 September 2026
CVE-2026-83268Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).CRITICAL 9.1EPSS 0.34%15 September 2026
CVE-2026-83261Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core).CRITICAL 9.8EPSS 0.36%15 September 2026
CVE-2026-83260Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Event Java PX).CRITICAL 9.1EPSS 0.46%15 September 2026
CVE-2026-83232Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer).CRITICAL 9.8EPSS 0.33%15 September 2026
CVE-2026-83229Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console).CRITICAL 9.1EPSS 0.34%15 September 2026
CVE-2026-83202Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).CRITICAL 9.1EPSS 0.40%15 September 2026
CVE-2026-83201Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).CRITICAL 9.1EPSS 0.31%15 September 2026
CVE-2026-83197Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts).CRITICAL 9.1EPSS 0.37%15 September 2026
CVE-2026-83196Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).CRITICAL 9.1EPSS 0.34%15 September 2026
CVE-2026-83154Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI).CRITICAL 9.1EPSS 0.31%15 September 2026
CVE-2026-83151Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).CRITICAL 9.8EPSS 0.36%15 September 2026
CVE-2026-83149Vulnerability in Oracle Application Testing Suite.CRITICAL 9.1EPSS 0.26%15 September 2026
CVE-2026-83108Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).CRITICAL 9.8EPSS 0.45%15 September 2026
CVE-2026-83107Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).CRITICAL 9.1EPSS 0.44%15 September 2026
CVE-2026-83105Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).CRITICAL 9.0EPSS 0.36%15 September 2026
CVE-2026-83104Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).CRITICAL 9.1EPSS 0.40%15 September 2026
CVE-2026-83103Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).CRITICAL 9.1EPSS 0.44%15 September 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.