CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-58092
8.1 HIGH

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the …

Aug 26, 2026
CVE-2026-58091
7.8 HIGH

The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the …

Aug 26, 2026
CVE-2026-58090
7.8 HIGH

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths …

Aug 26, 2026
CVE-2026-58089
7.8 HIGH

When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check …

Aug 26, 2026
CVE-2026-57171
7.7 HIGH

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, …

Aug 26, 2026
CVE-2026-57170
7.8 HIGH

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom …

Aug 26, 2026
CVE-2026-54467
7.0 HIGH

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

Aug 26, 2026
CVE-2026-29988
7.6 HIGH

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker …

Aug 26, 2026
CVE-2026-79912
8.3 HIGH

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument …

Aug 25, 2026
CVE-2026-54757
7.8 HIGH

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is …

Aug 25, 2026
CVE-2026-41707
7.4 HIGH

Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID …

Aug 25, 2026
CVE-2026-18985
8.1 HIGH

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.

Aug 25, 2026
CVE-2026-18259
7.5 HIGH

Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.

Aug 25, 2026
CVE-2026-80186
7.6 HIGH

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted …

Aug 25, 2026
CVE-2026-79845
7.3 HIGH

A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID …

Aug 25, 2026
CVE-2026-79804
7.3 HIGH

A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing …

Aug 25, 2026
CVE-2026-68763
7.5 HIGH

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache …

Aug 25, 2026
CVE-2026-68569
8.1 HIGH

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did …

Aug 25, 2026
CVE-2026-66422
8.1 HIGH

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage …

Aug 25, 2026
CVE-2026-65927
7.5 HIGH

Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than …

Aug 25, 2026
CVE-2026-65183
8.1 HIGH

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. …

Aug 25, 2026
CVE-2026-79292
8.3 HIGH

Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Aug 25, 2026
CVE-2026-79286
7.4 HIGH

Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-79266
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox …

Aug 25, 2026
CVE-2026-79263
8.1 HIGH

Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via crafted network traffic. …

Aug 25, 2026
CVE-2026-79256
8.3 HIGH

Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to …

Aug 25, 2026
CVE-2026-79247
8.3 HIGH

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to …

Aug 25, 2026
CVE-2026-79245
7.7 HIGH

Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer process to execute arbitrary code …

Aug 25, 2026
CVE-2026-79244
8.8 HIGH

Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79240
8.8 HIGH

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside …

Aug 25, 2026
CVE-2026-79236
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-79231
8.8 HIGH

Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-79230
8.8 HIGH

Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the …

Aug 25, 2026
CVE-2026-79227
8.8 HIGH

Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via …

Aug 25, 2026
CVE-2026-79226
8.8 HIGH

Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via …

Aug 25, 2026
CVE-2026-79224
8.3 HIGH

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code …

Aug 25, 2026
CVE-2026-79223
8.8 HIGH

Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted file. (Chromium …

Aug 25, 2026
CVE-2026-79219
8.8 HIGH

Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-79218
8.3 HIGH

Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Aug 25, 2026
CVE-2026-79216
7.5 HIGH

Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside …

Aug 25, 2026
CVE-2026-79215
8.8 HIGH

Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79210
8.3 HIGH

Use after free in Audio in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to …

Aug 25, 2026
CVE-2026-79209
8.8 HIGH

Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79202
8.8 HIGH

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79198
8.8 HIGH

Use after free in Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79197
8.8 HIGH

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79195
8.8 HIGH

Use after free in Script in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79194
8.1 HIGH

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-79187
8.8 HIGH

Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79183
8.8 HIGH

Use after free in Accessibility in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.