SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,687 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026

39,246 results · page 61 of 785

CVESummaryPriorityPublished
CVE-2026-17691Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.48%30 July 2026
CVE-2026-17688Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.48%30 July 2026
CVE-2026-17687Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.53%30 July 2026
CVE-2026-17684Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.49%30 July 2026
CVE-2026-17682Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.49%30 July 2026
CVE-2026-17681Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.56%30 July 2026
CVE-2026-17680Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.53%30 July 2026
CVE-2026-17676Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.48%30 July 2026
CVE-2026-17675Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.41%30 July 2026
CVE-2026-17673Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.48%30 July 2026
CVE-2026-17672Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.48%30 July 2026
CVE-2026-17671Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.48%30 July 2026
CVE-2026-17670Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.48%30 July 2026
CVE-2026-17669Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.49%30 July 2026
CVE-2026-17666Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic.CRITICAL 9.1EPSS 0.24%30 July 2026
CVE-2026-17656Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.53%30 July 2026
CVE-2026-17655Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.53%30 July 2026
CVE-2026-17652Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.51%30 July 2026
CVE-2026-17651Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.CRITICAL 9.6EPSS 0.53%30 July 2026
CVE-2026-67595VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the…CRITICAL 9.2EPSS 0.53%29 July 2026
CVE-2025-69943kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.CRITICAL 9.8EPSS 0.28%29 July 2026
CVE-2025-69942kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.CRITICAL 9.8EPSS 0.26%29 July 2026
CVE-2025-67404Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.CRITICAL 9.8EPSS 0.26%29 July 2026
CVE-2025-67403Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.CRITICAL 9.8EPSS 0.26%29 July 2026
CVE-2025-65340kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.CRITICAL 9.8EPSS 0.26%29 July 2026
CVE-2026-67429Flyto2 Core is an execution kernel for automation and AI-agent workflows.CRITICAL 10.0EPSS 0.49%29 July 2026
CVE-2026-67426Flyto2 Core is an execution kernel for automation and AI-agent workflows.CRITICAL 9.3EPSS 0.31%29 July 2026
CVE-2026-16326In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients.CRITICAL 10.0EPSS 0.30%29 July 2026
CVE-2026-14529IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.CRITICAL 9.8EPSS 0.40%29 July 2026
CVE-2026-41939Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical…CRITICAL 9.3EPSS 0.80%29 July 2026
CVE-2026-18236A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations.CRITICAL 9.3EPSS 0.38%29 July 2026
CVE-2026-8338A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0.CRITICAL 9.2EPSS 0.30%29 July 2026
CVE-2026-54680Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow…CRITICAL 9.9EPSS 0.53%29 July 2026
CVE-2026-13697In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with…CRITICAL 9.1EPSS 0.46%29 July 2026
CVE-2026-67192Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated.CRITICAL 9.2EPSS 0.66%29 July 2026
CVE-2026-67191Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string.CRITICAL 9.3EPSS 0.62%29 July 2026
CVE-2026-60113AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected…CRITICAL 9.3EPSS 0.53%29 July 2026
CVE-2026-60112AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any…CRITICAL 9.3EPSS 0.53%29 July 2026
CVE-2026-54735Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests…CRITICAL 10.0EPSS 0.34%29 July 2026
CVE-2026-65888Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.CRITICAL 10.0EPSS 0.29%29 July 2026
CVE-2026-65887Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.CRITICAL 10.0EPSS 0.30%29 July 2026
CVE-2026-65886Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.CRITICAL 9.2EPSS 0.36%29 July 2026
CVE-2026-9177A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326.CRITICAL 9.4EPSS 0.29%29 July 2026
CVE-2026-65890Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.CRITICAL 9.2EPSS 0.28%29 July 2026
CVE-2026-65889Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.CRITICAL 9.2EPSS 0.29%29 July 2026
CVE-2026-65885Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files.CRITICAL 9.4EPSS 0.29%29 July 2026
CVE-2026-65884Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.CRITICAL 10.0EPSS 0.28%29 July 2026
CVE-2026-0667CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.CRITICAL 9.3EPSS 0.37%29 July 2026
CVE-2026-65883Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.CRITICAL 10.0EPSS 0.71%29 July 2026
CVE-2026-14900The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function.CRITICAL 9.8EPSS 0.69%29 July 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.