CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-95328
6.5 MEDIUM

Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via …

Sep 29, 2026
CVE-2026-95327
6.5 MEDIUM

Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Sep 29, 2026
CVE-2026-95323
5.4 MEDIUM

UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via …

Sep 29, 2026
CVE-2026-95321
5.4 MEDIUM

UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML …

Sep 29, 2026
CVE-2026-95320
5.4 MEDIUM

Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via …

Sep 29, 2026
CVE-2026-95309
5.4 MEDIUM

UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML …

Sep 29, 2026
CVE-2026-95307
5.4 MEDIUM

UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 29, 2026
CVE-2026-95305
4.8 MEDIUM

UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. …

Sep 29, 2026
CVE-2026-95303
6.5 MEDIUM

Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 29, 2026
CVE-2026-95300
4.8 MEDIUM

Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network …

Sep 29, 2026
CVE-2026-95297
6.5 MEDIUM

Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. …

Sep 29, 2026
CVE-2026-95296
4.3 MEDIUM

Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via …

Sep 29, 2026
CVE-2026-95295
4.6 MEDIUM

Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium …

Sep 29, 2026
CVE-2026-95294
5.4 MEDIUM

UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 29, 2026
CVE-2026-95293
4.7 MEDIUM

Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. …

Sep 29, 2026
CVE-2026-95292
4.8 MEDIUM

Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security …

Sep 29, 2026
CVE-2026-95291
5.4 MEDIUM

UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML …

Sep 29, 2026
CVE-2026-95290
5.4 MEDIUM

Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions …

Sep 29, 2026
CVE-2026-95289
4.3 MEDIUM

Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML …

Sep 29, 2026
CVE-2026-95288
5.4 MEDIUM

UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML …

Sep 29, 2026
CVE-2026-95287
5.4 MEDIUM

Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Sep 29, 2026
CVE-2026-95279
5.4 MEDIUM

UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML …

Sep 29, 2026
CVE-2026-95275
6.5 MEDIUM

Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via …

Sep 29, 2026
CVE-2026-102809
6.5 MEDIUM

PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers …

Sep 29, 2026
CVE-2026-102808
6.5 MEDIUM

PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before …

Sep 29, 2026
CVE-2026-102807
5.3 MEDIUM

OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers …

Sep 29, 2026
CVE-2026-102806
6.3 MEDIUM

OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or …

Sep 29, 2026
CVE-2026-102639
6.5 MEDIUM

MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to …

Sep 29, 2026
CVE-2026-102633
5.9 MEDIUM

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to …

Sep 29, 2026
CVE-2026-102623
6.5 MEDIUM

A flaw was found in KubeVirt. An authenticated user with permission to create Virtual Machine Instances (VMIs) can cause a Denial of Service (DoS) by …

Sep 29, 2026
CVE-2026-100245
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue …

Sep 29, 2026
CVE-2026-100243
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiSEO Extension allows Stored XSS. This issue …

Sep 29, 2026
CVE-2026-100238
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue …

Sep 29, 2026
CVE-2026-93332
5.4 MEDIUM

Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete …

Sep 29, 2026
CVE-2026-93330
4.3 MEDIUM

Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway …

Sep 29, 2026
CVE-2026-75806
5.3 MEDIUM

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter …

Sep 29, 2026
CVE-2026-75805
5.3 MEDIUM

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when …

Sep 29, 2026
CVE-2026-75804
5.3 MEDIUM

Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit …

Sep 29, 2026
CVE-2026-42772
5.3 MEDIUM

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional …

Sep 29, 2026
CVE-2026-35189
5.3 MEDIUM

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate …

Sep 29, 2026
CVE-2026-102630
4.7 MEDIUM

UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary …

Sep 29, 2026
CVE-2026-100289
5.0 MEDIUM

Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generate a network scan …

Sep 29, 2026
CVE-2026-100287
5.4 MEDIUM

Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments …

Sep 29, 2026
CVE-2026-100286
6.5 MEDIUM

Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a …

Sep 29, 2026
CVE-2026-102570
5.5 MEDIUM

ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the …

Sep 29, 2026
CVE-2026-102569
5.5 MEDIUM

ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an …

Sep 29, 2026
CVE-2026-102568
5.5 MEDIUM

Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. …

Sep 29, 2026
CVE-2026-102567
6.1 MEDIUM

CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious …

Sep 29, 2026
CVE-2025-33207
6.8 MEDIUM

NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register …

Sep 29, 2026
CVE-2026-81569
4.3 MEDIUM

An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can …

Sep 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.