CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-91744
5.3 MEDIUM

Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged …

Sep 15, 2026
CVE-2026-91742
4.8 MEDIUM

Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions …

Sep 15, 2026
CVE-2026-91740
4.3 MEDIUM

Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Sep 15, 2026
CVE-2026-91739
4.2 MEDIUM

Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements …

Sep 15, 2026
CVE-2026-91726
4.7 MEDIUM

Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox …

Sep 15, 2026
CVE-2026-91725
5.3 MEDIUM

Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Sep 15, 2026
CVE-2026-91720
4.7 MEDIUM

Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. …

Sep 15, 2026
CVE-2026-91717
5.1 MEDIUM

Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. …

Sep 15, 2026
CVE-2026-91714
5.3 MEDIUM

Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML …

Sep 15, 2026
CVE-2026-91713
4.2 MEDIUM

Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via …

Sep 15, 2026
CVE-2026-81927
5.4 MEDIUM

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing …

Sep 15, 2026
CVE-2026-81926
6.1 MEDIUM

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint …

Sep 15, 2026
CVE-2026-68953
6.5 MEDIUM

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by …

Sep 15, 2026
CVE-2026-66372
6.8 MEDIUM

The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.

Sep 15, 2026
CVE-2026-19655
6.5 MEDIUM

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server …

Sep 15, 2026
CVE-2026-18426
6.5 MEDIUM

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token …

Sep 15, 2026
CVE-2026-89027
6.5 MEDIUM

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured …

Sep 15, 2026
CVE-2026-88922
6.7 MEDIUM

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a …

Sep 15, 2026
CVE-2026-88743
6.1 MEDIUM

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

Sep 15, 2026
CVE-2026-88742
5.4 MEDIUM

Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.

Sep 15, 2026
CVE-2026-87285
6.0 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high …

Sep 15, 2026
CVE-2026-87283
6.0 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high …

Sep 15, 2026
CVE-2026-87282
6.0 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high …

Sep 15, 2026
CVE-2026-87280
4.2 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high …

Sep 15, 2026
CVE-2026-87279
6.1 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low …

Sep 15, 2026
CVE-2026-87278
6.1 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated …

Sep 15, 2026
CVE-2026-87275
4.6 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high …

Sep 15, 2026
CVE-2026-87274
4.4 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows …

Sep 15, 2026
CVE-2026-87267
5.3 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows …

Sep 15, 2026
CVE-2026-87253
6.1 MEDIUM

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Web Client). The supported version that is affected is 9.3.6. Easily exploitable vulnerability …

Sep 15, 2026
CVE-2026-87252
6.8 MEDIUM

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Difficult to exploit …

Sep 15, 2026
CVE-2026-87248
6.7 MEDIUM

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87169
6.1 MEDIUM

Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Wage Determination Online). Supported versions that are affected are …

Sep 15, 2026
CVE-2026-83491
6.8 MEDIUM

Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows …

Sep 15, 2026
CVE-2026-83488
5.4 MEDIUM

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker …

Sep 15, 2026
CVE-2026-83480
5.3 MEDIUM

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with …

Sep 15, 2026
CVE-2026-83460
6.5 MEDIUM

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with …

Sep 15, 2026
CVE-2026-83459
5.3 MEDIUM

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Supported versions that are affected are 3.0.0-3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with …

Sep 15, 2026
CVE-2026-83458
5.3 MEDIUM

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with …

Sep 15, 2026
CVE-2026-83443
6.5 MEDIUM

Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low …

Sep 15, 2026
CVE-2026-83441
6.8 MEDIUM

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability …

Sep 15, 2026
CVE-2026-83433
6.5 MEDIUM

Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability …

Sep 15, 2026
CVE-2026-83431
5.4 MEDIUM

Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low …

Sep 15, 2026
CVE-2026-83419
5.4 MEDIUM

Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 …

Sep 15, 2026
CVE-2026-83416
4.3 MEDIUM

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable …

Sep 15, 2026
CVE-2026-83354
6.3 MEDIUM

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows …

Sep 15, 2026
CVE-2026-83347
6.5 MEDIUM

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with …

Sep 15, 2026
CVE-2026-83346
5.4 MEDIUM

Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable …

Sep 15, 2026
CVE-2026-83279
5.5 MEDIUM

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily …

Sep 15, 2026
CVE-2026-83278
6.8 MEDIUM

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows …

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.