CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-11066
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 4, 2026
CVE-2026-11065
9.6 CRITICAL

Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jun 4, 2026
CVE-2026-11063
9.6 CRITICAL

Insufficient validation of untrusted input in WebNN in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process …

Jun 4, 2026
CVE-2026-11061
9.6 CRITICAL

Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Jun 4, 2026
CVE-2026-11056
9.6 CRITICAL

Insufficient validation of untrusted input in SiteIsolation in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process …

Jun 4, 2026
CVE-2026-11052
9.6 CRITICAL

Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jun 4, 2026
CVE-2026-11047
9.6 CRITICAL

Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jun 4, 2026
CVE-2026-11043
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to …

Jun 4, 2026
CVE-2026-11037
9.6 CRITICAL

Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Jun 4, 2026
CVE-2026-11029
9.6 CRITICAL

Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the …

Jun 4, 2026
CVE-2026-11021
9.6 CRITICAL

Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process …

Jun 4, 2026
CVE-2026-11009
9.6 CRITICAL

Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 4, 2026
CVE-2026-11002
9.6 CRITICAL

Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jun 4, 2026
CVE-2026-10990
9.6 CRITICAL

Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jun 4, 2026
CVE-2026-10983
9.6 CRITICAL

Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 4, 2026
CVE-2026-10974
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 4, 2026
CVE-2026-10972
9.6 CRITICAL

Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 4, 2026
CVE-2026-10971
9.6 CRITICAL

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process …

Jun 4, 2026
CVE-2026-10966
9.6 CRITICAL

Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. …

Jun 4, 2026
CVE-2026-10931
9.6 CRITICAL

Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jun 4, 2026
CVE-2026-10892
9.6 CRITICAL

Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via …

Jun 4, 2026
CVE-2026-10886
9.6 CRITICAL

Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jun 4, 2026
CVE-2026-10881
9.6 CRITICAL

Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via …

Jun 4, 2026
CVE-2024-27892
9.6 CRITICAL

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in …

Jun 4, 2026
CVE-2024-27890
9.6 CRITICAL

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in …

Jun 4, 2026
CVE-2025-71316
9.8 CRITICAL

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' …

Jun 4, 2026
CVE-2026-48040
9.1 CRITICAL

The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. …

Jun 4, 2026
CVE-2026-25550
9.8 CRITICAL

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via …

Jun 4, 2026
CVE-2026-10880
9.8 CRITICAL

OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a …

Jun 4, 2026
CVE-2025-67447
9.8 CRITICAL

The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does not properly sanitize user …

Jun 4, 2026
CVE-2026-50076
9.1 CRITICAL

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to …

Jun 4, 2026
CVE-2025-67446
9.8 CRITICAL

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie …

Jun 4, 2026
CVE-2026-43986
9.9 CRITICAL

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that resolves attacker-controlled …

Jun 4, 2026
CVE-2026-36182
9.8 CRITICAL

GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges …

Jun 4, 2026
CVE-2026-35906
9.6 CRITICAL

An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via …

Jun 4, 2026
CVE-2026-35905
9.8 CRITICAL

T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.

Jun 4, 2026
CVE-2026-35904
9.8 CRITICAL

Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable …

Jun 4, 2026
CVE-2026-8037
9.6 CRITICAL KEV

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance …

Jun 4, 2026
CVE-2019-25741
9.8 CRITICAL

Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to …

Jun 4, 2026
CVE-2019-25738
9.8 CRITICAL

WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can …

Jun 4, 2026
CVE-2019-25729
9.8 CRITICAL

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie …

Jun 4, 2026
CVE-2019-25727
9.8 CRITICAL

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. …

Jun 4, 2026
CVE-2026-4104
9.8 CRITICAL

Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: …

Jun 4, 2026
CVE-2026-50225
9.1 CRITICAL

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Jun 4, 2026
CVE-2026-50214
9.8 CRITICAL

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

Jun 4, 2026
CVE-2026-50211
9.8 CRITICAL

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.

Jun 4, 2026
CVE-2026-50208
9.4 CRITICAL

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.

Jun 4, 2026
CVE-2026-49191
9.8 CRITICAL

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Jun 4, 2026
CVE-2026-49188
9.8 CRITICAL

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root …

Jun 4, 2026
CVE-2026-49186
9.8 CRITICAL

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to …

Jun 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.