CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-102876
8.1 HIGH

SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS …

Sep 29, 2026
CVE-2026-102875
7.8 HIGH

VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers …

Sep 29, 2026
CVE-2026-102328
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102327
7.5 HIGH

Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially …

Sep 29, 2026
CVE-2026-102326
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102324
8.3 HIGH

Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-102323
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102321
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102317
8.6 HIGH

Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the …

Sep 29, 2026
CVE-2026-102302
8.8 HIGH

Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-102301
8.3 HIGH

Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute …

Sep 29, 2026
CVE-2026-102299
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-100298
8.8 HIGH

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation.

Sep 29, 2026
CVE-2026-100296
8.1 HIGH

In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the …

Sep 29, 2026
CVE-2026-100294
7.5 HIGH

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can …

Sep 29, 2026
CVE-2026-100293
8.8 HIGH

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. …

Sep 29, 2026
CVE-2026-100292
8.8 HIGH

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a …

Sep 29, 2026
CVE-2026-102831
8.1 HIGH

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook …

Sep 29, 2026
CVE-2026-102827
8.1 HIGH

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin …

Sep 29, 2026
CVE-2026-102826
8.1 HIGH

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin …

Sep 29, 2026
CVE-2026-102823
7.5 HIGH

Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and CHANNEL_REQUEST …

Sep 29, 2026
CVE-2026-102616
7.3 HIGH

A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. …

Sep 29, 2026
CVE-2026-95381
8.3 HIGH

Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95380
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox …

Sep 29, 2026
CVE-2026-95376
8.0 HIGH

Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted …

Sep 29, 2026
CVE-2026-95373
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox …

Sep 29, 2026
CVE-2026-95372
8.3 HIGH

Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95369
8.8 HIGH

Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95365
8.8 HIGH

Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95362
8.8 HIGH

Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a …

Sep 29, 2026
CVE-2026-95355
8.3 HIGH

Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially …

Sep 29, 2026
CVE-2026-95354
8.3 HIGH

Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95353
8.8 HIGH

Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95351
8.3 HIGH

Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code …

Sep 29, 2026
CVE-2026-95348
8.3 HIGH

Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95345
8.8 HIGH

Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95344
8.0 HIGH

Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome …

Sep 29, 2026
CVE-2026-95343
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95341
8.3 HIGH

Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95338
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95335
8.3 HIGH

Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95334
8.3 HIGH

Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95333
8.1 HIGH

Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network …

Sep 29, 2026
CVE-2026-95326
8.4 HIGH

Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 29, 2026
CVE-2026-95322
8.3 HIGH

Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process …

Sep 29, 2026
CVE-2026-95319
8.3 HIGH

Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95315
7.8 HIGH

Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI …

Sep 29, 2026
CVE-2026-95314
8.1 HIGH

Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions …

Sep 29, 2026
CVE-2026-95306
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-95304
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a …

Sep 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.