CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-54784
7.4 HIGH

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose …

Jul 8, 2026
CVE-2026-54783
7.4 HIGH

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and …

Jul 8, 2026
CVE-2026-54782
10.0 CRITICAL

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and …

Jul 8, 2026
CVE-2026-54781
7.4 HIGH

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation …

Jul 8, 2026
CVE-2026-54780
3.7 LOW

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 …

Jul 8, 2026
CVE-2026-54779
5.9 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay …

Jul 8, 2026
CVE-2026-54778
6.2 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer …

Jul 8, 2026
CVE-2026-54776
4.4 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted …

Jul 8, 2026
CVE-2026-54775
6.5 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening …

Jul 8, 2026
CVE-2026-54774
7.4 HIGH

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue …

Jul 8, 2026
CVE-2026-54773
5.9 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification …

Jul 8, 2026
CVE-2026-54772
7.5 HIGH

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote attacker …

Jul 8, 2026
CVE-2026-54499
7.5 HIGH

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such …

Jul 8, 2026
CVE-2026-15133
8.8 HIGH

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 8, 2026
CVE-2026-15132
8.8 HIGH

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Jul 8, 2026
CVE-2026-15131
4.3 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security …

Jul 8, 2026
CVE-2026-15130
4.3 MEDIUM

Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium …

Jul 8, 2026
CVE-2026-15129
8.8 HIGH

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jul 8, 2026
CVE-2026-15128
6.1 MEDIUM

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …

Jul 8, 2026
CVE-2026-15127
6.1 MEDIUM

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …

Jul 8, 2026
CVE-2026-15126
8.8 HIGH

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 8, 2026
CVE-2026-15125
8.8 HIGH

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Jul 8, 2026
CVE-2026-15124
4.3 MEDIUM

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. …

Jul 8, 2026
CVE-2026-15123
8.8 HIGH

Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Jul 8, 2026
CVE-2026-15122
8.3 HIGH

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process …

Jul 8, 2026
CVE-2026-15121
8.8 HIGH

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 8, 2026
CVE-2026-15120
8.3 HIGH

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 8, 2026
CVE-2026-15119
8.3 HIGH

Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape …

Jul 8, 2026
CVE-2026-15118
8.8 HIGH

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 8, 2026
CVE-2026-15117
7.5 HIGH

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Jul 8, 2026
CVE-2026-15116
8.8 HIGH

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 8, 2026
CVE-2026-15115
3.3 LOW

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via …

Jul 8, 2026
CVE-2026-15114
8.8 HIGH

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a …

Jul 8, 2026
CVE-2026-15113
9.6 CRITICAL

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 8, 2026
CVE-2026-15112
8.8 HIGH

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jul 8, 2026
CVE-2026-15111
7.5 HIGH

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Jul 8, 2026
CVE-2026-15110
8.8 HIGH

Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially …

Jul 8, 2026
CVE-2026-15109
6.5 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 8, 2026
CVE-2026-15108
4.3 MEDIUM

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform …

Jul 8, 2026
CVE-2026-15107
8.8 HIGH

Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 8, 2026
CVE-2026-15105
6.3 MEDIUM

A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request …

Jul 8, 2026
CVE-2026-5923

Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.

Jul 8, 2026
CVE-2026-5922

The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage.

Jul 8, 2026
CVE-2026-55878
7.8 HIGH

Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs files from a …

Jul 8, 2026
CVE-2026-55877
6.1 MEDIUM

Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and …

Jul 8, 2026
CVE-2026-55849

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper …

Jul 8, 2026
CVE-2026-55830
8.3 HIGH

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. …

Jul 8, 2026
CVE-2026-55471

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare …

Jul 8, 2026
CVE-2026-55470
7.5 HIGH

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched …

Jul 8, 2026
CVE-2026-54777
6.5 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts …

Jul 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.