CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-87454
6.5 MEDIUM

Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML …

Sep 9, 2026
CVE-2026-87453
5.3 MEDIUM

Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via …

Sep 9, 2026
CVE-2026-87449
4.3 MEDIUM

Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. …

Sep 9, 2026
CVE-2026-87447
6.5 MEDIUM

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted …

Sep 9, 2026
CVE-2026-87446
6.5 MEDIUM

Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 9, 2026
CVE-2026-87445
5.4 MEDIUM

UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87443
6.5 MEDIUM

Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87441
6.5 MEDIUM

Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium …

Sep 9, 2026
CVE-2026-87439
5.3 MEDIUM

Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via …

Sep 9, 2026
CVE-2026-87437
6.5 MEDIUM

Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87436
6.5 MEDIUM

Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted …

Sep 9, 2026
CVE-2026-87435
5.3 MEDIUM

Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via …

Sep 9, 2026
CVE-2026-87432
4.2 MEDIUM

Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via …

Sep 9, 2026
CVE-2026-87429
6.5 MEDIUM

Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions …

Sep 9, 2026
CVE-2026-53937
6.2 MEDIUM

MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in `kotlin-sdk-core/src/commonMain/kotlin/io/modelcontextprotocol/kotlin/sdk/shared/ReadBuffer.kt` writes every …

Sep 9, 2026
CVE-2026-53638
4.3 MEDIUM

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability …

Sep 8, 2026
CVE-2026-53637
6.5 MEDIUM

Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement …

Sep 8, 2026
CVE-2026-18090
6.1 MEDIUM

A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon …

Sep 8, 2026
CVE-2026-86996
5.4 MEDIUM

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced …

Sep 8, 2026
CVE-2026-86995
4.3 MEDIUM

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, …

Sep 8, 2026
CVE-2026-86994
4.3 MEDIUM

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance …

Sep 8, 2026
CVE-2026-86993
4.9 MEDIUM

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential …

Sep 8, 2026
CVE-2026-86085
4.9 MEDIUM

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage …

Sep 8, 2026
CVE-2026-86084
5.5 MEDIUM

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when …

Sep 8, 2026
CVE-2026-86082
6.5 MEDIUM

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal …

Sep 8, 2026
CVE-2026-86080
5.3 MEDIUM

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when …

Sep 8, 2026
CVE-2026-86079
6.5 MEDIUM

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers …

Sep 8, 2026
CVE-2026-86078
6.5 MEDIUM

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from …

Sep 8, 2026
CVE-2026-86077
6.5 MEDIUM

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution …

Sep 8, 2026
CVE-2026-85981
6.7 MEDIUM

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, …

Sep 8, 2026
CVE-2026-84685
6.5 MEDIUM

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment …

Sep 8, 2026
CVE-2026-82001
5.5 MEDIUM

Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system …

Sep 8, 2026
CVE-2026-81997
6.3 MEDIUM

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Sep 8, 2026
CVE-2026-81993
5.5 MEDIUM

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to …

Sep 8, 2026
CVE-2026-81991
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-81984
5.5 MEDIUM

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to …

Sep 8, 2026
CVE-2026-81982
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-81978
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-81977
5.5 MEDIUM

Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Sep 8, 2026
CVE-2026-80162
5.5 MEDIUM

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to …

Sep 8, 2026
CVE-2026-80160
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-80159
4.0 MEDIUM

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability …

Sep 8, 2026
CVE-2026-79910
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-79588
4.3 MEDIUM

U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

Sep 8, 2026
CVE-2026-78971
4.6 MEDIUM

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

Sep 8, 2026
CVE-2026-78742
6.1 MEDIUM

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

Sep 8, 2026
CVE-2026-78741
6.1 MEDIUM

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

Sep 8, 2026
CVE-2026-78738
6.1 MEDIUM

Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

Sep 8, 2026
CVE-2026-78635
5.0 MEDIUM

The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// …

Sep 8, 2026
CVE-2026-78631
5.3 MEDIUM

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.