CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
157 results Clear all
CVE-2026-2919 4.3 MEDIUM
Focus for iOS <148.2 - Open Redirect
Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _self navigation to an invalid port and triggering an iframe redirect, causing the UI to display a trusted domain without user interaction. This vulnerability affects Focus for iOS < 148.2.
CWE-451 Mar 09, 2026
CVE-2025-68277 5.0 MEDIUM 1 Writeup EPSS 0.00
OpenEMR <7.0.4 - Open Redirect
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. This behavior could be exploited for phishing. Version 7.0.4 patches the issue.
CWE-451 Feb 25, 2026
CVE-2026-2634 9.8 CRITICAL EPSS 0.00
Firefox iOS <147.4 - Spoofing
Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability affects Firefox for iOS < 147.4.
CWE-451 Feb 24, 2026
CVE-2026-26320 6.5 MEDIUM 1 Writeup EPSS 0.00
OpenClaw macOS 2026.2.6-2026.2.13 - Command Injection
OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without an unattended `key`, the app shows a confirmation dialog that previously displayed only the first 240 characters of the message, but executed the full message after the user clicked "Run." At the time of writing, the OpenClaw macOS desktop client is still in beta. In versions 2026.2.6 through 2026.2.13, an attacker could pad the message with whitespace to push a malicious payload outside the visible preview, increasing the chance a user approves a different message than the one that is actually executed. If a user runs the deep link, the agent may perform actions that can lead to arbitrary command execution depending on the user's configured tool approvals/allowlists. This is a social-engineering mediated vulnerability: the confirmation prompt could be made to misrepresent the executed message. The issue is fixed in 2026.2.14. Other mitigations include not approve unexpected "Run OpenClaw agent?" prompts triggered while browsing untrusted sites and usingunattended deep links only with a valid `key` for trusted personal automations.
CWE-451 Feb 19, 2026
CVE-2026-1658 5.3 MEDIUM EPSS 0.00
OpenText Directory Services 20.4.1-25.2 - Cache Poisoning
User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning.  The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText application, potentially misleading users. This issue affects Directory Services: from 20.4.1 through 25.2.
CWE-451 Feb 19, 2026
CVE-2026-2032 4.3 MEDIUM EPSS 0.00
Firefox for iOS < 147.2.1 - SSRF
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1.
CWE-451 Feb 16, 2026
CVE-2026-2323 4.3 MEDIUM EPSS 0.00
Google Chrome <145.0.7632.45 - XSS
Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CWE-451 Feb 11, 2026
CVE-2026-2322 5.4 MEDIUM EPSS 0.00
Google Chrome <145.0.7632.45 - XSS
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CWE-451 Feb 11, 2026
CVE-2026-2320 6.5 MEDIUM EPSS 0.00
Google Chrome <145.0.7632.45 - XSS
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CWE-451 Feb 11, 2026
CVE-2026-2318 6.5 MEDIUM EPSS 0.00
Google Chrome <145.0.7632.45 - XSS
Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CWE-451 Feb 11, 2026
CVE-2026-2316 6.5 MEDIUM EPSS 0.00
Google Chrome <145.0.7632.45 - XSS
Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CWE-451 Feb 11, 2026
CVE-2026-21527 6.5 MEDIUM EPSS 0.00
Microsoft Exchange Server - Info Disclosure
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CWE-451 Feb 10, 2026
CVE-2026-0391 6.5 MEDIUM EPSS 0.00
Microsoft Edge for Android - Info Disclosure
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
CWE-451 Feb 05, 2026
CVE-2026-20732 3.1 LOW EPSS 0.00
BIG-IP - Info Disclosure
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE-451 Feb 04, 2026
CVE-2026-0907 9.8 CRITICAL EPSS 0.00
Google Chrome <144.0.7559.59 - XSS
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CWE-451 Jan 20, 2026
CVE-2026-0906 9.8 CRITICAL EPSS 0.00
Google Chrome <144.0.7559.59 - XSS
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
CWE-451 Jan 20, 2026
CVE-2026-0904 5.4 MEDIUM EPSS 0.00
Google Chrome <144.0.7559.59 - CSRF
Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
CWE-451 Jan 20, 2026
CVE-2026-0901 5.4 MEDIUM EPSS 0.00
Google Chrome <144.0.7559.59 - XSS
Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
CWE-451 Jan 20, 2026
CVE-2025-62224 5.5 MEDIUM EPSS 0.00
Microsoft Edge for Android - Spoofing
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network.
CWE-451 Jan 07, 2026
CVE-2025-65046 3.1 LOW EPSS 0.00
Microsoft Edge Chromium - Authentication Bypass by Spoofing
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CWE-451 Dec 18, 2025