Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,246 results · page 60 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-47876 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. | CRITICAL 9.3EPSS 0.36% | 30 July 2026 |
| CVE-2026-18363 | A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. | CRITICAL 9.1EPSS 0.30% | 30 July 2026 |
| CVE-2026-7849 | Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root. | CRITICAL 9.3EPSS 0.48% | 30 July 2026 |
| CVE-2026-44108 | Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. | CRITICAL 9.3EPSS 0.51% | 30 July 2026 |
| CVE-2026-44104 | This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise. | CRITICAL 9.3EPSS 0.27% | 30 July 2026 |
| CVE-2026-44101 | Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. | CRITICAL 9.3EPSS 0.43% | 30 July 2026 |
| CVE-2026-44090 | Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. | CRITICAL 9.3EPSS 0.43% | 30 July 2026 |
| CVE-2026-58066 | An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user. | CRITICAL 9.8EPSS 0.23% | 30 July 2026 |
| CVE-2026-58046 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. | CRITICAL 9.9EPSS 0.35% | 30 July 2026 |
| CVE-2026-14602 | The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget… | CRITICAL 9.0EPSS 0.52% | 30 July 2026 |
| CVE-2026-16610 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. | CRITICAL 9.8EPSS 0.58% | 30 July 2026 |
| CVE-2026-48449 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. | CRITICAL 9.8EPSS 0.96% | 30 July 2026 |
| CVE-2026-18015 | Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.20% | 30 July 2026 |
| CVE-2026-18002 | Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.21% | 30 July 2026 |
| CVE-2026-17991 | Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.24% | 30 July 2026 |
| CVE-2026-17990 | Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. | CRITICAL 9.6EPSS 0.22% | 30 July 2026 |
| CVE-2026-17987 | Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. | CRITICAL 9.6EPSS 0.23% | 30 July 2026 |
| CVE-2026-17947 | Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.26% | 30 July 2026 |
| CVE-2026-17940 | Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.26% | 30 July 2026 |
| CVE-2026-17924 | Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.26% | 30 July 2026 |
| CVE-2026-17865 | Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.28% | 30 July 2026 |
| CVE-2026-17856 | Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.28% | 30 July 2026 |
| CVE-2026-17855 | Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.22% | 30 July 2026 |
| CVE-2026-17848 | Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. | CRITICAL 9.6EPSS 0.32% | 30 July 2026 |
| CVE-2026-17847 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.35% | 30 July 2026 |
| CVE-2026-17837 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 30 July 2026 |
| CVE-2026-17834 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 30 July 2026 |
| CVE-2026-17832 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.32% | 30 July 2026 |
| CVE-2026-17804 | Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.41% | 30 July 2026 |
| CVE-2026-17803 | Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. | CRITICAL 9.6EPSS 0.38% | 30 July 2026 |
| CVE-2026-17801 | Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.41% | 30 July 2026 |
| CVE-2026-17768 | Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.41% | 30 July 2026 |
| CVE-2026-17758 | Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.44% | 30 July 2026 |
| CVE-2026-17749 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. | CRITICAL 9.6EPSS 0.29% | 30 July 2026 |
| CVE-2026-17738 | Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.41% | 30 July 2026 |
| CVE-2026-17727 | Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.41% | 30 July 2026 |
| CVE-2026-17726 | Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.41% | 30 July 2026 |
| CVE-2026-17721 | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.42% | 30 July 2026 |
| CVE-2026-17718 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.41% | 30 July 2026 |
| CVE-2026-17717 | Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 30 July 2026 |
| CVE-2026-17713 | Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.48% | 30 July 2026 |
| CVE-2026-17711 | Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.38% | 30 July 2026 |
| CVE-2026-17710 | Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.48% | 30 July 2026 |
| CVE-2026-17709 | Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.39% | 30 July 2026 |
| CVE-2026-17708 | Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 30 July 2026 |
| CVE-2026-17704 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 30 July 2026 |
| CVE-2026-17701 | Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.47% | 30 July 2026 |
| CVE-2026-17697 | Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.53% | 30 July 2026 |
| CVE-2026-17695 | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.48% | 30 July 2026 |
| CVE-2026-17692 | Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CRITICAL 9.6EPSS 0.49% | 30 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.