CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13802
7.5 HIGH

Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Jun 30, 2026
CVE-2026-13801
8.3 HIGH

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jun 30, 2026
CVE-2026-13800
7.8 HIGH

Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. …

Jun 30, 2026
CVE-2026-13799
8.1 HIGH

Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium …

Jun 30, 2026
CVE-2026-13798
9.6 CRITICAL

Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jun 30, 2026
CVE-2026-13797
9.6 CRITICAL

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially …

Jun 30, 2026
CVE-2026-13796
9.6 CRITICAL

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jun 30, 2026
CVE-2026-13795
6.5 MEDIUM

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a …

Jun 30, 2026
CVE-2026-13794
7.5 HIGH

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage …

Jun 30, 2026
CVE-2026-13793
6.5 MEDIUM

Insufficient policy enforcement in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

Jun 30, 2026
CVE-2026-13792
9.6 CRITICAL

Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 30, 2026
CVE-2026-13791
8.1 HIGH

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension …

Jun 30, 2026
CVE-2026-13790
6.5 MEDIUM

Side-channel information leakage in Scroll in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

Jun 30, 2026
CVE-2026-13789
9.6 CRITICAL

Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jun 30, 2026
CVE-2026-13788
8.8 HIGH

Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML …

Jun 30, 2026
CVE-2026-13787
8.1 HIGH

Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. …

Jun 30, 2026
CVE-2026-13786
8.8 HIGH

Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium …

Jun 30, 2026
CVE-2026-13785
9.6 CRITICAL

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific …

Jun 30, 2026
CVE-2026-13784
8.8 HIGH

Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Jun 30, 2026
CVE-2026-13783
8.8 HIGH

Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Jun 30, 2026
CVE-2026-13782
10.0 CRITICAL

Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jun 30, 2026
CVE-2026-13781
9.6 CRITICAL

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially …

Jun 30, 2026
CVE-2026-13780
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially …

Jun 30, 2026
CVE-2026-13779
8.1 HIGH

Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. …

Jun 30, 2026
CVE-2026-13778
7.8 HIGH

Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious peripheral. …

Jun 30, 2026
CVE-2026-13777
8.8 HIGH

Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via …

Jun 30, 2026
CVE-2026-13776
9.8 CRITICAL

Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jun 30, 2026
CVE-2026-13775
9.8 CRITICAL

Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jun 30, 2026
CVE-2026-13774
8.1 HIGH

Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute …

Jun 30, 2026
CVE-2025-71381
6.5 MEDIUM

Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the …

Jun 30, 2026
CVE-2025-71374
8.1 HIGH

picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers …

Jun 30, 2026
CVE-2025-71371
8.1 HIGH

picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pickle payloads that bypass picklescan detection and execute …

Jun 30, 2026
CVE-2025-71368
8.1 HIGH

picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle …

Jun 30, 2026
CVE-2025-71363
8.1 HIGH

picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle …

Jun 30, 2026
CVE-2025-71355

Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and execute arbitrary code during deserialization. …

Jun 30, 2026
CVE-2025-71352
8.1 HIGH

picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce methods, allowing attackers to execute arbitrary code. Remote …

Jun 30, 2026
CVE-2025-71350
8.1 HIGH

picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed undetected code in pickle files that executes …

Jun 30, 2026
CVE-2025-71349
8.1 HIGH

picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft …

Jun 30, 2026
CVE-2026-58450
4.3 MEDIUM

Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external …

Jun 30, 2026
CVE-2026-58449
9.8 CRITICAL

txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr …

Jun 30, 2026
CVE-2026-58448
6.5 MEDIUM

yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by …

Jun 30, 2026
CVE-2026-58447
6.5 MEDIUM

Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists …

Jun 30, 2026
CVE-2026-58446
6.5 MEDIUM

Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSWORD), is reachable unauthenticated at /mcp because the nginx front-end …

Jun 30, 2026
CVE-2026-57585
7.5 HIGH

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading …

Jun 30, 2026
CVE-2026-57204
6.5 MEDIUM

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability …

Jun 30, 2026
CVE-2026-52868
8.2 HIGH

An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental …

Jun 30, 2026
CVE-2026-52196
7.5 HIGH

Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_416f28 component

Jun 30, 2026
CVE-2026-50254
7.5 HIGH

An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly …

Jun 30, 2026
CVE-2026-50003
9.8 CRITICAL

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative …

Jun 30, 2026
CVE-2026-37106
9.8 CRITICAL

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed …

Jun 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.