CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76731
6.5 MEDIUM

An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful …

Sep 29, 2026
CVE-2026-76730
6.5 MEDIUM

An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing …

Sep 29, 2026
CVE-2026-76729
6.6 MEDIUM

A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause …

Sep 29, 2026
CVE-2026-53989
4.7 MEDIUM

Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenticated users to attacker-controlled sites …

Sep 29, 2026
CVE-2026-102879
5.0 MEDIUM

ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transition …

Sep 29, 2026
CVE-2026-102877
4.4 MEDIUM

Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. …

Sep 29, 2026
CVE-2026-102330
6.5 MEDIUM

Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Sep 29, 2026
CVE-2026-102329
6.1 MEDIUM

Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a …

Sep 29, 2026
CVE-2026-102325
4.3 MEDIUM

Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Sep 29, 2026
CVE-2026-102320
6.5 MEDIUM

Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Sep 29, 2026
CVE-2026-102318
4.7 MEDIUM

Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted …

Sep 29, 2026
CVE-2026-102314
5.4 MEDIUM

UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Sep 29, 2026
CVE-2026-102313
4.7 MEDIUM

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a …

Sep 29, 2026
CVE-2026-102312
4.3 MEDIUM

UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML …

Sep 29, 2026
CVE-2026-102310
6.5 MEDIUM

Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Sep 29, 2026
CVE-2026-102307
4.7 MEDIUM

Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a …

Sep 29, 2026
CVE-2026-102305
5.4 MEDIUM

UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML …

Sep 29, 2026
CVE-2026-102303
4.3 MEDIUM

Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML …

Sep 29, 2026
CVE-2026-102300
4.3 MEDIUM

Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Sep 29, 2026
CVE-2026-100299
6.8 MEDIUM

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption.

Sep 29, 2026
CVE-2026-100297
5.3 MEDIUM

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may …

Sep 29, 2026
CVE-2026-100295
6.3 MEDIUM

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When …

Sep 29, 2026
CVE-2024-31027
5.4 MEDIUM

Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, …

Sep 29, 2026
CVE-2026-102830
6.8 MEDIUM

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in …

Sep 29, 2026
CVE-2026-102824
4.3 MEDIUM

Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte …

Sep 29, 2026
CVE-2026-102821
6.5 MEDIUM

Russh is a Rust SSH client and server library. Prior to 0.63.2, an authenticated remote peer can send SSH_MSG_KEXINIT without the required SSH_MSG_KEX_ECDH_INIT and then …

Sep 29, 2026
CVE-2026-102820
6.2 MEDIUM

pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant …

Sep 29, 2026
CVE-2026-95385
6.5 MEDIUM

Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions …

Sep 29, 2026
CVE-2026-95384
5.3 MEDIUM

Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. …

Sep 29, 2026
CVE-2026-95382
6.5 MEDIUM

Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering …

Sep 29, 2026
CVE-2026-95375
6.3 MEDIUM

Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Sep 29, 2026
CVE-2026-95374
6.5 MEDIUM

Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Sep 29, 2026
CVE-2026-95371
5.4 MEDIUM

Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged …

Sep 29, 2026
CVE-2026-95370
5.4 MEDIUM

Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium …

Sep 29, 2026
CVE-2026-95368
4.3 MEDIUM

Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted …

Sep 29, 2026
CVE-2026-95367
5.3 MEDIUM

Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Sep 29, 2026
CVE-2026-95366
6.5 MEDIUM

Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web …

Sep 29, 2026
CVE-2026-95364
5.4 MEDIUM

Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium …

Sep 29, 2026
CVE-2026-95363
5.4 MEDIUM

UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 29, 2026
CVE-2026-95361
4.3 MEDIUM

Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted …

Sep 29, 2026
CVE-2026-95360
5.3 MEDIUM

Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML …

Sep 29, 2026
CVE-2026-95358
4.4 MEDIUM

Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged …

Sep 29, 2026
CVE-2026-95352
5.4 MEDIUM

Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted …

Sep 29, 2026
CVE-2026-95346
4.8 MEDIUM

UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: …

Sep 29, 2026
CVE-2026-95342
4.3 MEDIUM

Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Sep 29, 2026
CVE-2026-95340
4.3 MEDIUM

Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted …

Sep 29, 2026
CVE-2026-95337
5.4 MEDIUM

UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements …

Sep 29, 2026
CVE-2026-95336
6.5 MEDIUM

Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted …

Sep 29, 2026
CVE-2026-95332
4.7 MEDIUM

Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox …

Sep 29, 2026
CVE-2026-95330
6.5 MEDIUM

Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. …

Sep 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.