CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-79911
10.0 CRITICAL

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI …

Aug 25, 2026
CVE-2026-16645
9.1 CRITICAL

Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery …

Aug 25, 2026
CVE-2026-16644
9.1 CRITICAL

Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.

Aug 25, 2026
CVE-2026-16641
9.8 CRITICAL

Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

Aug 25, 2026
CVE-2026-16639
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from …

Aug 25, 2026
CVE-2026-78655
9.1 CRITICAL

Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts …

Aug 25, 2026
CVE-2026-78619
9.8 CRITICAL

Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the …

Aug 25, 2026
CVE-2026-68525
9.1 CRITICAL

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST …

Aug 25, 2026
CVE-2026-65905
9.8 CRITICAL

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with …

Aug 25, 2026
CVE-2026-65637
9.8 CRITICAL

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through …

Aug 25, 2026
CVE-2026-65182
9.1 CRITICAL

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a …

Aug 25, 2026
CVE-2026-80104
9.8 CRITICAL

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename …

Aug 25, 2026
CVE-2026-79290
9.6 CRITICAL

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79282
9.6 CRITICAL

Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-79275
9.6 CRITICAL

Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79257
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79235
9.6 CRITICAL

Use after free in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79232
9.6 CRITICAL

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Aug 25, 2026
CVE-2026-79200
9.6 CRITICAL

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79189
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via …

Aug 25, 2026
CVE-2026-79188
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via …

Aug 25, 2026
CVE-2026-79152
9.8 CRITICAL

Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed …

Aug 25, 2026
CVE-2026-79150
9.6 CRITICAL

Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-79149
9.6 CRITICAL

Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79148
9.1 CRITICAL

Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially read memory inside the sandbox via …

Aug 25, 2026
CVE-2026-79140
9.6 CRITICAL

Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-79138
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside …

Aug 25, 2026
CVE-2026-79131
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a …

Aug 25, 2026
CVE-2026-79130
9.6 CRITICAL

Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-79129
9.6 CRITICAL

Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code …

Aug 25, 2026
CVE-2026-79128
9.6 CRITICAL

Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-79111
9.6 CRITICAL

Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Aug 25, 2026
CVE-2026-79091
9.6 CRITICAL

Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code …

Aug 25, 2026
CVE-2026-79090
9.8 CRITICAL

Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a …

Aug 25, 2026
CVE-2026-79078
9.6 CRITICAL

Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-79064
9.6 CRITICAL

Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code …

Aug 25, 2026
CVE-2026-79058
9.1 CRITICAL

Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via …

Aug 25, 2026
CVE-2026-79056
9.6 CRITICAL

Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Aug 25, 2026
CVE-2026-79052
9.6 CRITICAL

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-79047
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-79043
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via …

Aug 25, 2026
CVE-2026-79026
9.6 CRITICAL

Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the …

Aug 25, 2026
CVE-2026-79019
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside …

Aug 25, 2026
CVE-2026-79012
9.6 CRITICAL

Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code …

Aug 25, 2026
CVE-2026-78989
9.6 CRITICAL

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside …

Aug 25, 2026
CVE-2026-78985
9.6 CRITICAL

Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the …

Aug 25, 2026
CVE-2026-78964
9.6 CRITICAL

Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the …

Aug 25, 2026
CVE-2026-78951
9.6 CRITICAL

Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-78948
9.6 CRITICAL

Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-78945
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.