CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-94204
7.5 HIGH

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket …

Sep 29, 2026
CVE-2026-102925
7.8 HIGH

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already …

Sep 29, 2026
CVE-2026-102253
7.5 HIGH

iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an …

Sep 29, 2026
CVE-2026-96274
7.4 HIGH

In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. …

Sep 29, 2026
CVE-2026-94953
8.8 HIGH

A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using …

Sep 29, 2026
CVE-2026-79403
8.4 HIGH

An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint

Sep 29, 2026
CVE-2026-76728
7.2 HIGH

A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side …

Sep 29, 2026
CVE-2026-76727
7.2 HIGH

Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform …

Sep 29, 2026
CVE-2026-76726
8.1 HIGH

An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if …

Sep 29, 2026
CVE-2026-67993
8.8 HIGH

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.

Sep 29, 2026
CVE-2026-67987
7.5 HIGH

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many …

Sep 29, 2026
CVE-2026-61519
8.8 HIGH

Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts …

Sep 29, 2026
CVE-2026-102878
8.1 HIGH

mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web …

Sep 29, 2026
CVE-2026-102876
8.1 HIGH

SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS …

Sep 29, 2026
CVE-2026-102875
7.8 HIGH

VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers …

Sep 29, 2026
CVE-2026-102328
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102327
7.5 HIGH

Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially …

Sep 29, 2026
CVE-2026-102326
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102324
8.3 HIGH

Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-102323
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102321
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102317
8.6 HIGH

Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the …

Sep 29, 2026
CVE-2026-102302
8.8 HIGH

Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102301
8.3 HIGH

Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute …

Sep 29, 2026
CVE-2026-102299
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-100298
8.8 HIGH

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation.

Sep 29, 2026
CVE-2026-100296
8.1 HIGH

In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the …

Sep 29, 2026
CVE-2026-100294
7.5 HIGH

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can …

Sep 29, 2026
CVE-2026-100293
8.8 HIGH

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. …

Sep 29, 2026
CVE-2026-100292
8.8 HIGH

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a …

Sep 29, 2026
CVE-2026-102831
8.1 HIGH

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook …

Sep 29, 2026
CVE-2026-102827
8.1 HIGH

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin …

Sep 29, 2026
CVE-2026-102826
8.1 HIGH

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin …

Sep 29, 2026
CVE-2026-102823
7.5 HIGH

Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and CHANNEL_REQUEST …

Sep 29, 2026
CVE-2026-102616
7.3 HIGH

A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. …

Sep 29, 2026
CVE-2026-95381
8.3 HIGH

Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95380
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox …

Sep 29, 2026
CVE-2026-95376
8.0 HIGH

Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted …

Sep 29, 2026
CVE-2026-95373
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox …

Sep 29, 2026
CVE-2026-95372
8.3 HIGH

Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95369
8.8 HIGH

Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95365
8.8 HIGH

Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95362
8.8 HIGH

Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a …

Sep 29, 2026
CVE-2026-95355
8.3 HIGH

Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially …

Sep 29, 2026
CVE-2026-95354
8.3 HIGH

Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95353
8.8 HIGH

Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95351
8.3 HIGH

Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code …

Sep 29, 2026
CVE-2026-95348
8.3 HIGH

Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95345
8.8 HIGH

Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95344
8.0 HIGH

Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome …

Sep 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.