CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-95343
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95341
8.3 HIGH

Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95338
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95335
8.3 HIGH

Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95334
8.3 HIGH

Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95333
8.1 HIGH

Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network …

Sep 29, 2026
CVE-2026-95326
8.4 HIGH

Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 29, 2026
CVE-2026-95322
8.3 HIGH

Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process …

Sep 29, 2026
CVE-2026-95319
8.3 HIGH

Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95315
7.8 HIGH

Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI …

Sep 29, 2026
CVE-2026-95314
8.1 HIGH

Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions …

Sep 29, 2026
CVE-2026-95306
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-95304
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a …

Sep 29, 2026
CVE-2026-95301
8.1 HIGH

Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Sep 29, 2026
CVE-2026-95298
7.8 HIGH

Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI …

Sep 29, 2026
CVE-2026-95286
8.8 HIGH

Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-95285
8.4 HIGH

Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass …

Sep 29, 2026
CVE-2026-95282
8.8 HIGH

Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95280
7.5 HIGH

Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-95278
8.4 HIGH

Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions …

Sep 29, 2026
CVE-2026-95276
8.3 HIGH

Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95274
8.3 HIGH

Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-94954
8.8 HIGH

A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control …

Sep 29, 2026
CVE-2026-84842
8.1 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit …

Sep 29, 2026
CVE-2026-84440
7.5 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text …

Sep 29, 2026
CVE-2026-84422
7.2 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to …

Sep 29, 2026
CVE-2026-84421
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during …

Sep 29, 2026
CVE-2026-84414
7.8 HIGH

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of …

Sep 29, 2026
CVE-2026-102811
7.5 HIGH

Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content …

Sep 29, 2026
CVE-2026-102810
7.5 HIGH

Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request …

Sep 29, 2026
CVE-2026-102758
7.5 HIGH

The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and …

Sep 29, 2026
CVE-2026-102728
7.5 HIGH

Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. …

Sep 29, 2026
CVE-2026-102677
7.8 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code …

Sep 29, 2026
CVE-2026-102560
8.6 HIGH

A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could …

Sep 29, 2026
CVE-2026-102559
8.6 HIGH

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation …

Sep 29, 2026
CVE-2026-102558
8.6 HIGH

A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the …

Sep 29, 2026
CVE-2026-102555
8.2 HIGH

A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained …

Sep 29, 2026
CVE-2026-102796
7.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue …

Sep 29, 2026
CVE-2026-102697
7.8 HIGH

Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell …

Sep 29, 2026
CVE-2026-102676
8.3 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest …

Sep 29, 2026
CVE-2026-102675
7.4 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol …

Sep 29, 2026
CVE-2026-102674
8.2 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a …

Sep 29, 2026
CVE-2026-102673
8.2 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed …

Sep 29, 2026
CVE-2026-102634
7.5 HIGH

SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send …

Sep 29, 2026
CVE-2026-102557
8.6 HIGH

A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits …

Sep 29, 2026
CVE-2026-102556
8.6 HIGH

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the …

Sep 29, 2026
CVE-2026-100244
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows Excavation. This issue affects Mediawiki - CentralAuth Extension: …

Sep 29, 2026
CVE-2026-100242
7.5 HIGH

Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - …

Sep 29, 2026
CVE-2026-100241
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: …

Sep 29, 2026
CVE-2022-51019
8.8 HIGH

Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell …

Sep 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.