CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-17683
6.5 MEDIUM

Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 30, 2026
CVE-2026-17682
9.6 CRITICAL

Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jul 30, 2026
CVE-2026-17681
9.6 CRITICAL

Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer …

Jul 30, 2026
CVE-2026-17680
9.6 CRITICAL

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17679
6.5 MEDIUM

Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to …

Jul 30, 2026
CVE-2026-17678
8.8 HIGH

Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17677
8.8 HIGH

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Jul 30, 2026
CVE-2026-17676
9.6 CRITICAL

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17675
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17674
6.5 MEDIUM

Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium …

Jul 30, 2026
CVE-2026-17673
9.6 CRITICAL

Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jul 30, 2026
CVE-2026-17672
9.6 CRITICAL

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17671
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17670
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17669
9.6 CRITICAL

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via …

Jul 30, 2026
CVE-2026-17668
6.5 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Jul 30, 2026
CVE-2026-17667
6.5 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Jul 30, 2026
CVE-2026-17666
9.1 CRITICAL

Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious …

Jul 30, 2026
CVE-2026-17665
8.8 HIGH

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 30, 2026
CVE-2026-17664
6.5 MEDIUM

Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak …

Jul 30, 2026
CVE-2026-17663
8.3 HIGH

Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process …

Jul 30, 2026
CVE-2026-17662
4.3 MEDIUM

Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

Jul 30, 2026
CVE-2026-17661
8.8 HIGH

Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 30, 2026
CVE-2026-17660
8.3 HIGH

Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17659
4.2 MEDIUM

Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Jul 30, 2026
CVE-2026-17658
8.8 HIGH

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 30, 2026
CVE-2026-17657
8.3 HIGH

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17656
9.6 CRITICAL

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jul 30, 2026
CVE-2026-17655
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 30, 2026
CVE-2026-17654
7.8 HIGH

Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium …

Jul 30, 2026
CVE-2026-17653
8.3 HIGH

Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17652
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17651
9.6 CRITICAL

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape …

Jul 30, 2026
CVE-2026-17650
8.3 HIGH

Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-64685
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for …

Jul 30, 2026
CVE-2026-62946
5.1 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large …

Jul 30, 2026
CVE-2026-62363
5.0 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in …

Jul 30, 2026
CVE-2026-62343
4.7 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, …

Jul 30, 2026
CVE-2026-16339

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2026
CVE-2026-67595
8.1 HIGH

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers …

Jul 29, 2026
CVE-2026-15157
4.2 MEDIUM

undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In …

Jul 29, 2026
CVE-2026-14643
5.9 MEDIUM

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to …

Jul 29, 2026
CVE-2025-69949
7.3 HIGH

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.

Jul 29, 2026
CVE-2025-69945
7.3 HIGH

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.

Jul 29, 2026
CVE-2025-69944
7.3 HIGH

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.

Jul 29, 2026
CVE-2025-69943
9.8 CRITICAL

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.

Jul 29, 2026
CVE-2025-69942
9.8 CRITICAL

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

Jul 29, 2026
CVE-2025-67408
7.3 HIGH

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.

Jul 29, 2026
CVE-2025-67407
7.3 HIGH

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.

Jul 29, 2026
CVE-2025-67406
7.3 HIGH

https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector …

Jul 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.