CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78897
6.5 MEDIUM

Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome …

Aug 25, 2026
CVE-2026-78896
4.3 MEDIUM

Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78895
4.3 MEDIUM

Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78894
3.1 LOW

Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

Aug 25, 2026
CVE-2026-78893
6.5 MEDIUM

Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78892
7.1 HIGH

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local …

Aug 25, 2026
CVE-2026-78891
8.8 HIGH

Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-77680
5.3 MEDIUM

An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated …

Aug 25, 2026
CVE-2026-77357

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, applications running in debug mode expose a GET /hot-reload …

Aug 25, 2026
CVE-2026-75465
7.5 HIGH

The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. …

Aug 25, 2026
CVE-2026-75421
4.0 MEDIUM

aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.

Aug 25, 2026
CVE-2026-72924

GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created by gh codespace ports forward to all …

Aug 25, 2026
CVE-2026-65105
8.1 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful …

Aug 25, 2026
CVE-2026-65099
7.8 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability …

Aug 25, 2026
CVE-2026-65098
8.1 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability …

Aug 25, 2026
CVE-2026-65097
7.5 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful …

Aug 25, 2026
CVE-2026-65096
7.8 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of …

Aug 25, 2026
CVE-2026-65093
9.9 CRITICAL

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code …

Aug 25, 2026
CVE-2026-65092
8.5 HIGH

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit …

Aug 25, 2026
CVE-2026-65091
8.8 HIGH

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead …

Aug 25, 2026
CVE-2026-65090
7.8 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this …

Aug 25, 2026
CVE-2026-65089
7.8 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit …

Aug 25, 2026
CVE-2026-65088
5.5 MEDIUM

NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead …

Aug 25, 2026
CVE-2026-65087
5.6 MEDIUM

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure …

Aug 25, 2026
CVE-2026-65086
6.8 MEDIUM

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of …

Aug 25, 2026
CVE-2026-65085
5.2 MEDIUM

NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful …

Aug 25, 2026
CVE-2026-65084
8.1 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability …

Aug 25, 2026
CVE-2026-65083
9.9 CRITICAL

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful …

Aug 25, 2026
CVE-2026-65082
7.0 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability …

Aug 25, 2026
CVE-2026-65081
8.1 HIGH

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this …

Aug 25, 2026
CVE-2026-55588
6.5 MEDIUM

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, …

Aug 25, 2026
CVE-2026-53965

The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport …

Aug 25, 2026
CVE-2026-52491
8.4 HIGH

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

Aug 25, 2026
CVE-2026-52489
7.8 HIGH

Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function

Aug 25, 2026
CVE-2026-51368
9.8 CRITICAL

An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted …

Aug 25, 2026
CVE-2026-39113
4.0 MEDIUM

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause …

Aug 25, 2026
CVE-2026-77585
5.3 MEDIUM

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may …

Aug 25, 2026
CVE-2026-74932
7.5 HIGH

The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files …

Aug 25, 2026
CVE-2026-68515
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through …

Aug 25, 2026
CVE-2026-68514
5.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 …

Aug 25, 2026
CVE-2026-68513
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 …

Aug 25, 2026
CVE-2026-66153
7.0 HIGH

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

Aug 25, 2026
CVE-2026-66152
8.8 HIGH

A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root.

Aug 25, 2026
CVE-2026-65367
5.5 MEDIUM

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. …

Aug 25, 2026
CVE-2026-64705
5.5 MEDIUM

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7. An app may be able …

Aug 25, 2026
CVE-2026-59981
7.1 HIGH

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 …

Aug 25, 2026
CVE-2026-55099
7.5 HIGH

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares …

Aug 25, 2026
CVE-2026-45019
7.2 HIGH

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose …

Aug 25, 2026
CVE-2026-45018
9.8 CRITICAL

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose …

Aug 25, 2026
CVE-2026-43670
8.8 HIGH

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.