CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-22590
9.1 CRITICAL

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, …

Sep 9, 2026
CVE-2026-85103
9.8 CRITICAL

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management …

Sep 9, 2026
CVE-2026-85102
9.8 CRITICAL

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the …

Sep 9, 2026
CVE-2026-80172
9.8 CRITICAL

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. …

Sep 9, 2026
CVE-2026-85978
9.8 CRITICAL

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and …

Sep 9, 2026
CVE-2026-56207
9.8 CRITICAL

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another …

Sep 9, 2026
CVE-2026-41871
9.8 CRITICAL

Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache …

Sep 9, 2026
CVE-2026-41869
9.1 CRITICAL

Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. …

Sep 9, 2026
CVE-2026-16272
9.1 CRITICAL

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of …

Sep 9, 2026
CVE-2026-21096
9.8 CRITICAL

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Sep 9, 2026
CVE-2026-21095
9.8 CRITICAL

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Sep 9, 2026
CVE-2026-87654
9.6 CRITICAL

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via …

Sep 9, 2026
CVE-2026-87650
9.6 CRITICAL

Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via …

Sep 9, 2026
CVE-2026-87646
9.6 CRITICAL

Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a …

Sep 9, 2026
CVE-2026-87643
9.6 CRITICAL

Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87638
9.6 CRITICAL

Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via …

Sep 9, 2026
CVE-2026-87637
9.6 CRITICAL

Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87634
9.6 CRITICAL

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 9, 2026
CVE-2026-87621
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside …

Sep 9, 2026
CVE-2026-87613
9.0 CRITICAL

Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted …

Sep 9, 2026
CVE-2026-87609
9.6 CRITICAL

Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87607
9.6 CRITICAL

Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-87595
9.8 CRITICAL

Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a …

Sep 9, 2026
CVE-2026-87581
9.6 CRITICAL

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-87558
9.6 CRITICAL

Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87547
9.6 CRITICAL

Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-87544
9.8 CRITICAL

Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a …

Sep 9, 2026
CVE-2026-87534
9.8 CRITICAL

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions …

Sep 9, 2026
CVE-2026-87529
9.6 CRITICAL

Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 9, 2026
CVE-2026-87528
9.6 CRITICAL

Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87527
9.6 CRITICAL

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML …

Sep 9, 2026
CVE-2026-87526
9.6 CRITICAL

Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-87520
9.6 CRITICAL

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87512
9.6 CRITICAL

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87504
9.6 CRITICAL

Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87500
9.6 CRITICAL

Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87494
9.6 CRITICAL

Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code …

Sep 9, 2026
CVE-2026-87492
9.6 CRITICAL

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87488
9.6 CRITICAL

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87474
9.6 CRITICAL

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 9, 2026
CVE-2026-87470
9.6 CRITICAL

Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-87464
9.6 CRITICAL

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87455
9.6 CRITICAL

Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 9, 2026
CVE-2026-87448
9.6 CRITICAL

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87438
9.6 CRITICAL

Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-53939
9.1 CRITICAL

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an …

Sep 9, 2026
CVE-2026-53581
9.0 CRITICAL

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in …

Sep 8, 2026
CVE-2026-85982
9.0 CRITICAL

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log …

Sep 8, 2026
CVE-2026-84869
9.9 CRITICAL KEV

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in …

Sep 8, 2026
CVE-2026-75746
9.1 CRITICAL

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.