CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-101152
8.0 HIGH

Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, …

Oct 6, 2026
CVE-2026-101027
7.7 HIGH

When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who …

Oct 6, 2026
CVE-2026-86362
8.2 HIGH

Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, …

Oct 6, 2026
CVE-2026-86361
8.2 HIGH

Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially …

Oct 6, 2026
CVE-2026-83550
7.1 HIGH

A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker …

Oct 6, 2026
CVE-2026-82162
7.4 HIGH

Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially …

Oct 6, 2026
CVE-2026-71168
7.3 HIGH

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker …

Oct 6, 2026
CVE-2026-63697
7.6 HIGH

Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, …

Oct 6, 2026
CVE-2026-56906
7.0 HIGH

In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional …

Oct 6, 2026
CVE-2026-106443
8.8 HIGH

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS …

Oct 6, 2026
CVE-2026-106442
7.8 HIGH

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the …

Oct 6, 2026
CVE-2026-106441
7.8 HIGH

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target …

Oct 6, 2026
CVE-2026-106440
7.8 HIGH

Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, …

Oct 6, 2026
CVE-2026-106426
8.3 HIGH

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106423
8.8 HIGH

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106421
8.8 HIGH

Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106412
8.3 HIGH

Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged …

Oct 6, 2026
CVE-2026-106411
8.8 HIGH

Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106409
8.3 HIGH

Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to …

Oct 6, 2026
CVE-2026-106403
8.1 HIGH

Incorrect authorization in Accessibility in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Oct 6, 2026
CVE-2026-106393
8.3 HIGH

Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code …

Oct 6, 2026
CVE-2026-106387
8.8 HIGH

Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via …

Oct 6, 2026
CVE-2026-106383
8.8 HIGH

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106378
8.3 HIGH

Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute …

Oct 6, 2026
CVE-2026-106377
8.3 HIGH

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside …

Oct 6, 2026
CVE-2026-106374
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Oct 6, 2026
CVE-2026-106373
8.8 HIGH

Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox …

Oct 6, 2026
CVE-2026-106371
8.8 HIGH

Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted …

Oct 6, 2026
CVE-2026-106367
8.4 HIGH

Missing authorization in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to potentially execute arbitrary code …

Oct 6, 2026
CVE-2026-106357
8.8 HIGH

Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106352
8.8 HIGH

Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML …

Oct 6, 2026
CVE-2026-106350
8.8 HIGH

Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106349
8.8 HIGH

Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106347
8.8 HIGH

Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106346
8.8 HIGH

Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a …

Oct 6, 2026
CVE-2026-106342
8.8 HIGH

Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106341
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106335
8.8 HIGH

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106334
8.8 HIGH

Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML …

Oct 6, 2026
CVE-2026-106318
8.8 HIGH

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106315
8.8 HIGH

Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106314
8.8 HIGH

Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106309
8.8 HIGH

Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML …

Oct 6, 2026
CVE-2026-106308
8.8 HIGH

Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information …

Oct 6, 2026
CVE-2026-106301
8.1 HIGH

Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access …

Oct 6, 2026
CVE-2026-106293
8.3 HIGH

Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Oct 6, 2026
CVE-2026-106292
8.3 HIGH

Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Oct 6, 2026
CVE-2026-106291
8.8 HIGH

Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106283
8.8 HIGH

Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the …

Oct 6, 2026
CVE-2026-106279
7.4 HIGH

Incorrect reference resolution in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker who had compromised the renderer process to …

Oct 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.