Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,699 CVEs1,716 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
39,247 results · page 63 of 785
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-64751 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.50% | 27 July 2026 |
| CVE-2026-64746 | An authorization issue was addressed with improved validation. | CRITICAL 9.8EPSS 0.55% | 27 July 2026 |
| CVE-2026-64740 | A malicious app may be able to break out of its sandbox. | CRITICAL 9.3EPSS 0.22% | 27 July 2026 |
| CVE-2026-64738 | A malicious app may be able to break out of its sandbox. | CRITICAL 9.8EPSS 0.57% | 27 July 2026 |
| CVE-2026-64733 | This issue was addressed with improved data protection. | CRITICAL 9.8EPSS 0.64% | 27 July 2026 |
| CVE-2026-64731 | A malicious app may be able to break out of its sandbox. | CRITICAL 9.8EPSS 0.61% | 27 July 2026 |
| CVE-2026-64729 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.58% | 27 July 2026 |
| CVE-2026-64727 | A type confusion issue was addressed with improved memory handling. | CRITICAL 9.8EPSS 0.49% | 27 July 2026 |
| CVE-2026-64726 | An attacker in physical proximity may be able to corrupt process memory. | CRITICAL 9.8EPSS 0.64% | 27 July 2026 |
| CVE-2026-64720 | A race condition was addressed with improved state handling. | CRITICAL 9.8EPSS 0.46% | 27 July 2026 |
| CVE-2026-64704 | A type confusion issue was addressed with improved memory handling. | CRITICAL 9.8EPSS 0.85% | 27 July 2026 |
| CVE-2026-64703 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.78% | 27 July 2026 |
| CVE-2026-64702 | An access issue was addressed with additional sandbox restrictions. | CRITICAL 9.8EPSS 0.56% | 27 July 2026 |
| CVE-2026-64700 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.65% | 27 July 2026 |
| CVE-2026-64698 | The issue was addressed with improved memory handling. | CRITICAL 9.8EPSS 0.60% | 27 July 2026 |
| CVE-2026-64697 | An app may be able to cause unexpected system termination or corrupt kernel memory. | CRITICAL 9.8EPSS 0.60% | 27 July 2026 |
| CVE-2026-64696 | A remote user may be able to cause unexpected system termination or corrupt kernel memory. | CRITICAL 9.8EPSS 0.72% | 27 July 2026 |
| CVE-2026-64695 | A remote user may be able to cause unexpected system termination or corrupt kernel memory. | CRITICAL 9.8EPSS 0.73% | 27 July 2026 |
| CVE-2026-64694 | An integer overflow was addressed with improved input validation. | CRITICAL 9.8EPSS 0.60% | 27 July 2026 |
| CVE-2026-64691 | A buffer overflow was addressed with improved size validation. | CRITICAL 9.8EPSS 0.45% | 27 July 2026 |
| CVE-2026-64551 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length before reading staleness When an ERROR chunk with a STALE_COOKIE cause is received in the COOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads… | CRITICAL 9.1EPSS 0.51% | 27 July 2026 |
| CVE-2026-64541 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handler() looks up the connection by token under the link group's conns_lock, drops the lock, and then… | CRITICAL 9.8EPSS 0.56% | 27 July 2026 |
| CVE-2026-43822 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.65% | 27 July 2026 |
| CVE-2026-43814 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.58% | 27 July 2026 |
| CVE-2026-43812 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.62% | 27 July 2026 |
| CVE-2026-43810 | A remote user may be able to cause unexpected system termination or corrupt kernel memory. | CRITICAL 9.8EPSS 0.78% | 27 July 2026 |
| CVE-2026-43809 | An out-of-bounds read was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.62% | 27 July 2026 |
| CVE-2026-43807 | A buffer overflow was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.77% | 27 July 2026 |
| CVE-2026-43805 | A race condition was addressed with improved state handling. | CRITICAL 9.8EPSS 0.41% | 27 July 2026 |
| CVE-2026-43803 | An out-of-bounds write issue was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.78% | 27 July 2026 |
| CVE-2026-43802 | An out-of-bounds write issue was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.62% | 27 July 2026 |
| CVE-2026-43799 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.65% | 27 July 2026 |
| CVE-2026-43793 | An issue existed in the handling of environment variables. | CRITICAL 9.8EPSS 0.60% | 27 July 2026 |
| CVE-2026-43779 | A logic issue was addressed with improved restrictions. | CRITICAL 9.8EPSS 0.63% | 27 July 2026 |
| CVE-2026-43778 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.65% | 27 July 2026 |
| CVE-2026-43773 | An out-of-bounds read was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.60% | 27 July 2026 |
| CVE-2026-43769 | An integer overflow was addressed with improved input validation. | CRITICAL 9.8EPSS 0.67% | 27 July 2026 |
| CVE-2026-43764 | An integer overflow was addressed with improved input validation. | CRITICAL 9.8EPSS 0.60% | 27 July 2026 |
| CVE-2026-43757 | An out-of-bounds read was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.53% | 27 July 2026 |
| CVE-2026-43750 | A buffer overflow was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.69% | 27 July 2026 |
| CVE-2026-43748 | An out-of-bounds write issue was addressed with improved bounds checking. | CRITICAL 9.8EPSS 0.60% | 27 July 2026 |
| CVE-2026-43730 | A permissions issue was addressed with additional restrictions. | CRITICAL 9.8EPSS 0.51% | 27 July 2026 |
| CVE-2026-43710 | An attacker may be able to cause unexpected system termination or corrupt kernel memory. | CRITICAL 9.8EPSS 0.52% | 27 July 2026 |
| CVE-2026-43694 | The issue was addressed with improved memory handling. | CRITICAL 9.8EPSS 0.60% | 27 July 2026 |
| CVE-2026-43682 | A remote user may be able to cause unexpected system termination or corrupt kernel memory. | CRITICAL 9.8EPSS 0.72% | 27 July 2026 |
| CVE-2026-39873 | Connecting to a malicious SMB server may lead to unexpected system termination. | CRITICAL 9.8EPSS 0.52% | 27 July 2026 |
| CVE-2026-28982 | A race condition was addressed with improved locking. | CRITICAL 9.8EPSS 0.49% | 27 July 2026 |
| CVE-2026-28928 | A use after free issue was addressed with improved memory management. | CRITICAL 9.8EPSS 0.58% | 27 July 2026 |
| CVE-2026-28911 | A malicious app may be able to corrupt memory of a system process. | CRITICAL 9.8EPSS 0.42% | 27 July 2026 |
| CVE-2026-55579 | From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). | CRITICAL 9.8EPSS 0.60% | 27 July 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.