CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-95301
8.1 HIGH

Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Sep 29, 2026
CVE-2026-95298
7.8 HIGH

Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI …

Sep 29, 2026
CVE-2026-95286
8.8 HIGH

Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-95285
8.4 HIGH

Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass …

Sep 29, 2026
CVE-2026-95282
8.8 HIGH

Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-95280
7.5 HIGH

Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 29, 2026
CVE-2026-95278
8.4 HIGH

Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions …

Sep 29, 2026
CVE-2026-95276
8.3 HIGH

Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-95274
8.3 HIGH

Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 29, 2026
CVE-2026-94954
8.8 HIGH

A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control …

Sep 29, 2026
CVE-2026-84842
8.1 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit …

Sep 29, 2026
CVE-2026-84440
7.5 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text …

Sep 29, 2026
CVE-2026-84422
7.2 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to …

Sep 29, 2026
CVE-2026-84421
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during …

Sep 29, 2026
CVE-2026-84414
7.8 HIGH

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of …

Sep 29, 2026
CVE-2026-102811
7.5 HIGH

Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content …

Sep 29, 2026
CVE-2026-102810
7.5 HIGH

Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request …

Sep 29, 2026
CVE-2026-102758
7.5 HIGH

The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and …

Sep 29, 2026
CVE-2026-102728
7.5 HIGH

Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. …

Sep 29, 2026
CVE-2026-102677
7.8 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code …

Sep 29, 2026
CVE-2026-102560
8.6 HIGH

A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could …

Sep 29, 2026
CVE-2026-102559
8.6 HIGH

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation …

Sep 29, 2026
CVE-2026-102558
8.6 HIGH

A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the …

Sep 29, 2026
CVE-2026-102555
8.2 HIGH

A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained …

Sep 29, 2026
CVE-2026-102796
7.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue …

Sep 29, 2026
CVE-2026-102697
7.8 HIGH

Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell …

Sep 29, 2026
CVE-2026-102676
8.3 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest …

Sep 29, 2026
CVE-2026-102675
7.4 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol …

Sep 29, 2026
CVE-2026-102674
8.2 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a …

Sep 29, 2026
CVE-2026-102673
8.2 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed …

Sep 29, 2026
CVE-2026-102634
7.5 HIGH

SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send …

Sep 29, 2026
CVE-2026-102557
8.6 HIGH

A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits …

Sep 29, 2026
CVE-2026-102556
8.6 HIGH

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the …

Sep 29, 2026
CVE-2026-100244
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows Excavation. This issue affects Mediawiki - CentralAuth Extension: …

Sep 29, 2026
CVE-2026-100242
7.5 HIGH

Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - …

Sep 29, 2026
CVE-2026-100241
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: …

Sep 29, 2026
CVE-2022-51019
8.8 HIGH

Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell …

Sep 29, 2026
CVE-2026-92371
7.0 HIGH

TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting …

Sep 29, 2026
CVE-2026-92370
8.8 HIGH

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to …

Sep 29, 2026
CVE-2026-92369
7.3 HIGH

TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker …

Sep 29, 2026
CVE-2026-92368
7.8 HIGH

TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording …

Sep 29, 2026
CVE-2026-84784
7.5 HIGH

Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs …

Sep 29, 2026
CVE-2026-84783
7.5 HIGH

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another …

Sep 29, 2026
CVE-2026-84782
8.2 HIGH

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read …

Sep 29, 2026
CVE-2026-72897
7.5 HIGH

Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond …

Sep 29, 2026
CVE-2026-54873
7.5 HIGH

Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability …

Sep 29, 2026
CVE-2026-19743
7.8 HIGH

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a …

Sep 29, 2026
CVE-2026-102600
7.5 HIGH

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered …

Sep 29, 2026
CVE-2026-100308
7.8 HIGH

Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with …

Sep 29, 2026
CVE-2026-100288
7.2 HIGH

Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain …

Sep 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.