CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-106278
8.8 HIGH

Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox …

Oct 6, 2026
CVE-2026-106274
8.8 HIGH

Incorrect reference resolution in Browser in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information …

Oct 6, 2026
CVE-2026-106271
8.1 HIGH

Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Oct 6, 2026
CVE-2026-106269
8.8 HIGH

Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106268
8.8 HIGH

Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106257
8.8 HIGH

Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106256
8.8 HIGH

Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via …

Oct 6, 2026
CVE-2026-106255
8.8 HIGH

Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106252
8.8 HIGH

Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106249
8.8 HIGH

Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML …

Oct 6, 2026
CVE-2026-106248
8.8 HIGH

Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106247
8.3 HIGH

Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Oct 6, 2026
CVE-2026-106240
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Oct 6, 2026
CVE-2026-106238
8.3 HIGH

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Oct 6, 2026
CVE-2026-106235
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106233
8.3 HIGH

Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code …

Oct 6, 2026
CVE-2026-106228
8.3 HIGH

Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Oct 6, 2026
CVE-2026-106225
8.8 HIGH

Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML …

Oct 6, 2026
CVE-2026-106221
8.3 HIGH

Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy …

Oct 6, 2026
CVE-2026-106220
8.8 HIGH

Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106212
8.8 HIGH

Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML …

Oct 6, 2026
CVE-2026-106207
8.8 HIGH

Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Oct 6, 2026
CVE-2026-106205
8.1 HIGH

Missing authorization in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass …

Oct 6, 2026
CVE-2026-106204
8.8 HIGH

Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106203
8.8 HIGH

Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via …

Oct 6, 2026
CVE-2026-106201
8.8 HIGH

Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Oct 6, 2026
CVE-2026-106200
8.8 HIGH

Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106194
8.3 HIGH

Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Oct 6, 2026
CVE-2026-106193
8.8 HIGH

Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106191
8.3 HIGH

Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Oct 6, 2026
CVE-2026-106190
8.8 HIGH

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 6, 2026
CVE-2026-106186
8.6 HIGH

Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentially execute arbitrary code outside …

Oct 6, 2026
CVE-2026-106118
7.5 HIGH

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, tiled TIFF decoding allocates a destination buffer using TileWidth but TiffDecompressorsFactory.Create constructs T4, T6, and …

Oct 6, 2026
CVE-2026-105488
7.1 HIGH

Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and earlier allows an authenticated user with only the global vault view permission to modify …

Oct 6, 2026
CVE-2026-104073
7.6 HIGH

NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal …

Oct 6, 2026
CVE-2026-106117
7.5 HIGH

ImageSharp is a 2D graphics library. From 3.0.0 until 4.1.1, decoding a strip TIFF using CCITT Group 3 or Modified Huffman compression can pass attacker-expanded …

Oct 6, 2026
CVE-2026-106115
7.5 HIGH

ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can …

Oct 6, 2026
CVE-2026-106113
7.5 HIGH

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite …

Oct 6, 2026
CVE-2026-106112
7.5 HIGH

ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store …

Oct 6, 2026
CVE-2026-106110
7.5 HIGH

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. …

Oct 6, 2026
CVE-2026-106103
7.1 HIGH

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values …

Oct 6, 2026
CVE-2026-101207
8.8 HIGH

Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS …

Oct 6, 2026
CVE-2025-45871
8.1 HIGH

LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via …

Oct 6, 2026
CVE-2026-95140
7.5 HIGH

kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability in FileController.java. The fileUpload, createFolder and existsFile endpoints accept a "path" parameter that is concatenated into …

Oct 6, 2026
CVE-2026-106218
8.8 HIGH

In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

Oct 6, 2026
CVE-2026-106100
7.1 HIGH

Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who …

Oct 6, 2026
CVE-2026-105865
8.1 HIGH

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can …

Oct 6, 2026
CVE-2026-105862
8.7 HIGH

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable …

Oct 6, 2026
CVE-2026-105858
8.1 HIGH

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the …

Oct 6, 2026
CVE-2026-104850
7.5 HIGH

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and …

Oct 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.