CVE Database

10419+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-17688
9.6 CRITICAL

Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17687
9.6 CRITICAL

Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jul 30, 2026
CVE-2026-17684
9.6 CRITICAL

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the …

Jul 30, 2026
CVE-2026-17682
9.6 CRITICAL

Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jul 30, 2026
CVE-2026-17681
9.6 CRITICAL

Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer …

Jul 30, 2026
CVE-2026-17680
9.6 CRITICAL

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17676
9.6 CRITICAL

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17675
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17673
9.6 CRITICAL

Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jul 30, 2026
CVE-2026-17672
9.6 CRITICAL

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17671
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17670
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17669
9.6 CRITICAL

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via …

Jul 30, 2026
CVE-2026-17666
9.1 CRITICAL

Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious …

Jul 30, 2026
CVE-2026-17656
9.6 CRITICAL

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jul 30, 2026
CVE-2026-17655
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 30, 2026
CVE-2026-17652
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17651
9.6 CRITICAL

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape …

Jul 30, 2026
CVE-2025-69943
9.8 CRITICAL

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.

Jul 29, 2026
CVE-2025-69942
9.8 CRITICAL

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

Jul 29, 2026
CVE-2025-67404
9.8 CRITICAL

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.

Jul 29, 2026
CVE-2025-67403
9.8 CRITICAL

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.

Jul 29, 2026
CVE-2025-65340
9.8 CRITICAL

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.

Jul 29, 2026
CVE-2026-67429
10.0 CRITICAL

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config …

Jul 29, 2026
CVE-2026-67426
9.3 CRITICAL

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on …

Jul 29, 2026
CVE-2026-16326
10.0 CRITICAL

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to …

Jul 29, 2026
CVE-2026-14529
9.4 CRITICAL

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) …

Jul 29, 2026
CVE-2026-41939
9.8 CRITICAL

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access …

Jul 29, 2026
CVE-2026-54680
9.9 CRITICAL

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such …

Jul 29, 2026
CVE-2026-51992
9.1 CRITICAL

SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.

Jul 29, 2026
CVE-2026-67191
9.8 CRITICAL

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap …

Jul 29, 2026
CVE-2026-60113
9.8 CRITICAL

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that …

Jul 29, 2026
CVE-2026-60112
9.8 CRITICAL

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue …

Jul 29, 2026
CVE-2026-54735
10.0 CRITICAL

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate …

Jul 29, 2026
CVE-2026-14900
9.8 CRITICAL

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php …

Jul 29, 2026
CVE-2026-14488
9.1 CRITICAL

The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up …

Jul 29, 2026
CVE-2026-59243
9.8 CRITICAL

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned …

Jul 29, 2026
CVE-2026-58162
10.0 CRITICAL

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 …

Jul 29, 2026
CVE-2025-10656
9.8 CRITICAL

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and …

Jul 29, 2026
CVE-2026-58155
9.3 CRITICAL

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, …

Jul 29, 2026
CVE-2026-58150
10.0 CRITICAL

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from …

Jul 29, 2026
CVE-2026-57834
10.0 CRITICAL

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, …

Jul 29, 2026
CVE-2026-41920
9.3 CRITICAL

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended …

Jul 29, 2026
CVE-2026-33267
10.0 CRITICAL

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended …

Jul 29, 2026
CVE-2026-18191
9.8 CRITICAL

VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of …

Jul 29, 2026
CVE-2026-63234
9.9 CRITICAL

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed …

Jul 29, 2026
CVE-2026-63233
9.9 CRITICAL

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed …

Jul 29, 2026
CVE-2026-63232
9.9 CRITICAL

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to …

Jul 29, 2026
CVE-2026-63230
9.1 CRITICAL

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid …

Jul 29, 2026
CVE-2026-63229
9.1 CRITICAL

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to …

Jul 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.