CVE Database

130945+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-91731
8.8 HIGH

Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 15, 2026
CVE-2026-91730
3.1 LOW

Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Sep 15, 2026
CVE-2026-91729
9.6 CRITICAL

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Sep 15, 2026
CVE-2026-91728
9.6 CRITICAL

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 15, 2026
CVE-2026-91727
8.1 HIGH

Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to …

Sep 15, 2026
CVE-2026-91726
4.7 MEDIUM

Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox …

Sep 15, 2026
CVE-2026-91725
5.3 MEDIUM

Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Sep 15, 2026
CVE-2026-91724
8.3 HIGH

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 15, 2026
CVE-2026-91723

Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Sep 15, 2026
CVE-2026-91722
8.8 HIGH

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 15, 2026
CVE-2026-91721
8.8 HIGH

Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 15, 2026
CVE-2026-91720
4.7 MEDIUM

Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. …

Sep 15, 2026
CVE-2026-91719

Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Sep 15, 2026
CVE-2026-91718
9.6 CRITICAL

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Sep 15, 2026
CVE-2026-91717
5.1 MEDIUM

Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. …

Sep 15, 2026
CVE-2026-91716
9.6 CRITICAL

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Sep 15, 2026
CVE-2026-91715
8.8 HIGH

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 15, 2026
CVE-2026-91714
5.3 MEDIUM

Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML …

Sep 15, 2026
CVE-2026-91713
4.2 MEDIUM

Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via …

Sep 15, 2026
CVE-2026-91712
8.3 HIGH

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially …

Sep 15, 2026
CVE-2026-91711
8.8 HIGH

Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a …

Sep 15, 2026
CVE-2026-91710
9.6 CRITICAL

Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Sep 15, 2026
CVE-2026-91709
8.8 HIGH

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 15, 2026
CVE-2026-91708
3.1 LOW

Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via …

Sep 15, 2026
CVE-2026-88065
7.5 HIGH

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken …

Sep 15, 2026
CVE-2026-81927

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing …

Sep 15, 2026
CVE-2026-81926

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint …

Sep 15, 2026
CVE-2026-79994

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A …

Sep 15, 2026
CVE-2026-68953
6.5 MEDIUM

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by …

Sep 15, 2026
CVE-2026-68950
8.8 HIGH

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP …

Sep 15, 2026
CVE-2026-68491

An insufficient check allowed for the overwrite of arbitrary files via a symlink.

Sep 15, 2026
CVE-2026-68070
8.8 HIGH

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to …

Sep 15, 2026
CVE-2026-66890
9.6 CRITICAL

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

Sep 15, 2026
CVE-2026-66887
9.6 CRITICAL

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

Sep 15, 2026
CVE-2026-66372
6.8 MEDIUM

The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.

Sep 15, 2026
CVE-2026-61568
9.6 CRITICAL

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin …

Sep 15, 2026
CVE-2026-61559
9.6 CRITICAL

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, …

Sep 15, 2026
CVE-2026-61554
7.5 HIGH

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before …

Sep 15, 2026
CVE-2026-54544
7.2 HIGH

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An …

Sep 15, 2026
CVE-2026-54337
9.8 CRITICAL

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system …

Sep 15, 2026
CVE-2026-19655
6.5 MEDIUM

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server …

Sep 15, 2026
CVE-2026-18426

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token …

Sep 15, 2026
CVE-2026-92240

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. …

Sep 15, 2026
CVE-2026-92239

A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Sep 15, 2026
CVE-2026-92238

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird …

Sep 15, 2026
CVE-2026-89040
9.8 CRITICAL

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on …

Sep 15, 2026
CVE-2026-89027
6.5 MEDIUM

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured …

Sep 15, 2026
CVE-2026-88975
7.5 HIGH

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits …

Sep 15, 2026
CVE-2026-88922
6.7 MEDIUM

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a …

Sep 15, 2026
CVE-2026-88743

Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.