CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,867 CVEs tracked 53,243 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,925 Nuclei templates 37,802 vendors 42,500 researchers
6,619 results Clear all
CVE-2026-2799 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
CWE-416 Feb 24, 2026
CVE-2026-2798 8.8 HIGH EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
CWE-416 Feb 24, 2026
CVE-2026-2797 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
CWE-416 Feb 24, 2026
CVE-2026-2795 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
CWE-416 Feb 24, 2026
CVE-2026-2789 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2787 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the DOM: Window and Location component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2786 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2772 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the Audio/Video: Playback component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2770 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2769 8.8 HIGH EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the Storage: IndexedDB component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2767 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2766 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2765 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2764 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2763 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-2758 9.8 CRITICAL EPSS 0.00
Firefox <148 - Use After Free
Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CWE-416 Feb 24, 2026
CVE-2026-26983 5.3 MEDIUM EPSS 0.00
ImageMagick <7.1.2-15/6.9.13-40 - Use After Free
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
CWE-476 Feb 24, 2026
CVE-2026-25983 5.3 MEDIUM EPSS 0.00
ImageMagick <7.1.2-15/6.9.13-40 - Use After Free
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The operation element handler replaces and frees the image while the parser continues reading from it, leading to a UAF in ReadBlobString during further parsing. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
CWE-416 Feb 24, 2026
CVE-2026-2889 3.3 LOW 1 Writeup EPSS 0.00
CCExtractor <=0.96.5 - Use After Free
A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address this issue. The patch is named fd7271bae238ccb3ae8a71304ea64f0886324925. You should upgrade the affected component.
CWE-119 Feb 21, 2026
CVE-2026-2408 4.7 MEDIUM EPSS 0.00
Tanium Cloud Workloads Enforce - Use After Free
Tanium addressed a use-after-free vulnerability in the Cloud Workloads Enforce client extension.
CWE-416 Feb 20, 2026