CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-103005
6.5 MEDIUM

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management …

Oct 6, 2026
CVE-2026-102413
6.2 MEDIUM

Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes …

Oct 6, 2026
CVE-2026-102412
6.5 MEDIUM

Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with …

Oct 6, 2026
CVE-2026-102411
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit …

Oct 6, 2026
CVE-2026-102410
4.3 MEDIUM

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal API surface within the …

Oct 6, 2026
CVE-2026-102409
6.5 MEDIUM

Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive …

Oct 6, 2026
CVE-2026-102408
4.3 MEDIUM

Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking …

Oct 6, 2026
CVE-2026-102407
5.4 MEDIUM

Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with …

Oct 6, 2026
CVE-2026-102404
6.5 MEDIUM

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted …

Oct 6, 2026
CVE-2026-102169
6.5 MEDIUM

On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with …

Oct 6, 2026
CVE-2026-102168
6.5 MEDIUM

On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with …

Oct 6, 2026
CVE-2026-102158
6.5 MEDIUM

Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend …

Oct 6, 2026
CVE-2026-102157
5.9 MEDIUM

An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access …

Oct 6, 2026
CVE-2026-102156
6.8 MEDIUM

Improper neutralization of Lightweight Directory Access Protocol (LDAP) authentication input may allow an unauthenticated network attacker, under high-complexity conditions, to inject queries against the configured …

Oct 6, 2026
CVE-2026-101151
4.3 MEDIUM

Insufficient validation of request in login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the …

Oct 6, 2026
CVE-2026-101150
4.1 MEDIUM

Insufficient validation of OIDC bearer token configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.

Oct 6, 2026
CVE-2026-101149
4.1 MEDIUM

Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.

Oct 6, 2026
CVE-2026-101029
4.3 MEDIUM

Gitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address that was validated …

Oct 6, 2026
CVE-2026-9226
6.8 MEDIUM

Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account …

Oct 6, 2026
CVE-2026-70414
5.5 MEDIUM

Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially …

Oct 6, 2026
CVE-2026-56952
6.7 MEDIUM

In platform_msg_handler_init of default_msg_handlers.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with …

Oct 6, 2026
CVE-2026-56936
6.8 MEDIUM

In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with …

Oct 6, 2026
CVE-2026-55307
4.4 MEDIUM

In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure …

Oct 6, 2026
CVE-2026-106427
5.4 MEDIUM

Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged …

Oct 6, 2026
CVE-2026-106424
4.0 MEDIUM

Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the …

Oct 6, 2026
CVE-2026-106420
5.4 MEDIUM

Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via …

Oct 6, 2026
CVE-2026-106416
5.4 MEDIUM

Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome …

Oct 6, 2026
CVE-2026-106415
4.3 MEDIUM

Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106413
4.2 MEDIUM

Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via …

Oct 6, 2026
CVE-2026-106410
4.2 MEDIUM

Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via …

Oct 6, 2026
CVE-2026-106406
5.4 MEDIUM

Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via …

Oct 6, 2026
CVE-2026-106404
6.5 MEDIUM

Incorrect authorization in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions …

Oct 6, 2026
CVE-2026-106402
4.8 MEDIUM

Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome …

Oct 6, 2026
CVE-2026-106400
5.4 MEDIUM

Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a …

Oct 6, 2026
CVE-2026-106398
4.3 MEDIUM

Incorrect authorization in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106395
4.7 MEDIUM

Uninitialized resource in Dawn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a …

Oct 6, 2026
CVE-2026-106394
4.3 MEDIUM

Incomplete cleanup in Glic in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML …

Oct 6, 2026
CVE-2026-106392
4.3 MEDIUM

Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium …

Oct 6, 2026
CVE-2026-106391
4.2 MEDIUM

Incorrect authorization in WebShare in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof …

Oct 6, 2026
CVE-2026-106390
4.3 MEDIUM

Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML …

Oct 6, 2026
CVE-2026-106388
5.3 MEDIUM

Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via …

Oct 6, 2026
CVE-2026-106386
6.5 MEDIUM

Uninitialized resource in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. …

Oct 6, 2026
CVE-2026-106380
5.4 MEDIUM

UI misrepresentation in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Oct 6, 2026
CVE-2026-106379
4.3 MEDIUM

Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106376
4.7 MEDIUM

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a …

Oct 6, 2026
CVE-2026-106370
4.7 MEDIUM

Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read …

Oct 6, 2026
CVE-2026-106368
5.4 MEDIUM

UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML …

Oct 6, 2026
CVE-2026-106364
5.3 MEDIUM

Incorrect authorization in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via …

Oct 6, 2026
CVE-2026-106360
4.3 MEDIUM

Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106356
5.4 MEDIUM

Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. …

Oct 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.