CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-106262
4.2 MEDIUM

Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Oct 6, 2026
CVE-2026-106260
4.3 MEDIUM

Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML …

Oct 6, 2026
CVE-2026-106259
5.4 MEDIUM

Incorrect authorization in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium …

Oct 6, 2026
CVE-2026-106258
4.7 MEDIUM

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a …

Oct 6, 2026
CVE-2026-106254
5.1 MEDIUM

Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. …

Oct 6, 2026
CVE-2026-106253
4.3 MEDIUM

Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security …

Oct 6, 2026
CVE-2026-106251
5.4 MEDIUM

UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via …

Oct 6, 2026
CVE-2026-106250
5.4 MEDIUM

Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Oct 6, 2026
CVE-2026-106246
5.4 MEDIUM

Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106245
4.3 MEDIUM

Uninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106244
6.5 MEDIUM

Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security …

Oct 6, 2026
CVE-2026-106243
5.3 MEDIUM

Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security …

Oct 6, 2026
CVE-2026-106242
6.5 MEDIUM

Information leak in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via …

Oct 6, 2026
CVE-2026-106236
5.4 MEDIUM

UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via …

Oct 6, 2026
CVE-2026-106232
5.4 MEDIUM

UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Oct 6, 2026
CVE-2026-106231
4.7 MEDIUM

Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a …

Oct 6, 2026
CVE-2026-106230
5.3 MEDIUM

Incorrect reference resolution in Offline in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to …

Oct 6, 2026
CVE-2026-106229
5.4 MEDIUM

UI misrepresentation in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Oct 6, 2026
CVE-2026-106226
4.2 MEDIUM

Improper input validation in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof address bar …

Oct 6, 2026
CVE-2026-106223
4.7 MEDIUM

Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a …

Oct 6, 2026
CVE-2026-106222
5.9 MEDIUM

Incorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: …

Oct 6, 2026
CVE-2026-106217
4.3 MEDIUM

Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to leak cross-origin data …

Oct 6, 2026
CVE-2026-106215
4.7 MEDIUM

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a …

Oct 6, 2026
CVE-2026-106214
5.3 MEDIUM

Information leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. …

Oct 6, 2026
CVE-2026-106213
4.3 MEDIUM

Race condition in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium …

Oct 6, 2026
CVE-2026-106209
5.4 MEDIUM

UI misrepresentation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof address bar via …

Oct 6, 2026
CVE-2026-106206
5.9 MEDIUM

Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network …

Oct 6, 2026
CVE-2026-106202
4.7 MEDIUM

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a …

Oct 6, 2026
CVE-2026-106192
4.6 MEDIUM

Information leak in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via physical access. (Chromium …

Oct 6, 2026
CVE-2026-106187
4.2 MEDIUM

Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via …

Oct 6, 2026
CVE-2026-106184
4.3 MEDIUM

Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106183
5.9 MEDIUM

Missing authorization in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. …

Oct 6, 2026
CVE-2026-106182
5.4 MEDIUM

UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106181
5.3 MEDIUM

Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information …

Oct 6, 2026
CVE-2026-106179
5.4 MEDIUM

UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Oct 6, 2026
CVE-2026-106121
4.9 MEDIUM

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate …

Oct 6, 2026
CVE-2026-106033
5.4 MEDIUM

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application …

Oct 6, 2026
CVE-2026-105485
6.8 MEDIUM

Authentication bypass OAuth device authorization flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of …

Oct 6, 2026
CVE-2026-103778
6.2 MEDIUM

Dell Command | Configure (DCC), versions prior to 5.2.3.35 contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially …

Oct 6, 2026
CVE-2026-0198
4.4 MEDIUM

In is_pd_allowed of gem_msg.c, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with System …

Oct 6, 2026
CVE-2026-88252
4.7 MEDIUM

A flaw was found in sssd. A local user can cause a Denial of Service (DoS) by exhausting the responder service's available file descriptors (system …

Oct 6, 2026
CVE-2026-106116
5.3 MEDIUM

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, ExifReader.ReadValues64 trusts the 64-bit BigTIFF IFD entry count and iterates once per declared entry. When …

Oct 6, 2026
CVE-2026-106114
5.3 MEDIUM

ImageSharp is a 2D graphics library. From 1.0.0-beta0001 until 4.1.2, ICC CLUT parsing calculates allocation sizes from attacker-declared channel and grid dimensions before confirming that …

Oct 6, 2026
CVE-2026-106111
5.9 MEDIUM

ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ExrBaseDecompressor.UndoZipCompression accepts a nonempty ZIP or ZIPS inflate result that is shorter than the EXR …

Oct 6, 2026
CVE-2026-95153
4.9 MEDIUM

An issue in Bludit CMS 3.22.0 allows a remote attacker to obtain sensitive information via the /admin/ajax/clippy and /admin/ajax/save-as-draft endpoints

Oct 6, 2026
CVE-2026-106219
6.5 MEDIUM

In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server

Oct 6, 2026
CVE-2026-105957
6.3 MEDIUM

A vulnerability was detected in SourceCodester Performance Indicator System 1.0. The affected element is an unknown function of the file /opils/admin/view_product.php. Performing a manipulation of …

Oct 6, 2026
CVE-2026-105846
6.1 MEDIUM

Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can …

Oct 6, 2026
CVE-2025-71384
6.7 MEDIUM

Dbit WIFI4 N300 1.0.0 devices allows administrators (from the local Wi-Fi network) to execute OS commands by leveraging a stack-based buffer overflow via the /api/addStaticDHCP …

Oct 6, 2026
CVE-2026-63691
6.1 MEDIUM

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated …

Oct 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.