CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-17832
9.6 CRITICAL

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17804
9.6 CRITICAL

Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17803
9.6 CRITICAL

Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process …

Jul 30, 2026
CVE-2026-17801
9.6 CRITICAL

Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via …

Jul 30, 2026
CVE-2026-17768
9.6 CRITICAL

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17758
9.6 CRITICAL

Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jul 30, 2026
CVE-2026-17749
9.6 CRITICAL

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension …

Jul 30, 2026
CVE-2026-17738
9.6 CRITICAL

Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17727
9.6 CRITICAL

Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via …

Jul 30, 2026
CVE-2026-17726
9.6 CRITICAL

Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Jul 30, 2026
CVE-2026-17721
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Jul 30, 2026
CVE-2026-17718
9.6 CRITICAL

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jul 30, 2026
CVE-2026-17717
9.6 CRITICAL

Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Jul 30, 2026
CVE-2026-17713
9.6 CRITICAL

Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process …

Jul 30, 2026
CVE-2026-17711
9.6 CRITICAL

Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17710
9.6 CRITICAL

Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17709
9.6 CRITICAL

Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17708
9.6 CRITICAL

Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17704
9.6 CRITICAL

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17701
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process …

Jul 30, 2026
CVE-2026-17697
9.6 CRITICAL

Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Jul 30, 2026
CVE-2026-17695
9.6 CRITICAL

Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Jul 30, 2026
CVE-2026-17692
9.6 CRITICAL

Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17691
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via …

Jul 30, 2026
CVE-2026-17688
9.6 CRITICAL

Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17687
9.6 CRITICAL

Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jul 30, 2026
CVE-2026-17684
9.6 CRITICAL

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the …

Jul 30, 2026
CVE-2026-17682
9.6 CRITICAL

Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jul 30, 2026
CVE-2026-17681
9.6 CRITICAL

Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer …

Jul 30, 2026
CVE-2026-17680
9.6 CRITICAL

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17676
9.6 CRITICAL

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17675
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jul 30, 2026
CVE-2026-17673
9.6 CRITICAL

Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jul 30, 2026
CVE-2026-17672
9.6 CRITICAL

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17671
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 30, 2026
CVE-2026-17670
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17669
9.6 CRITICAL

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via …

Jul 30, 2026
CVE-2026-17666
9.1 CRITICAL

Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious …

Jul 30, 2026
CVE-2026-17656
9.6 CRITICAL

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jul 30, 2026
CVE-2026-17655
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 30, 2026
CVE-2026-17652
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jul 30, 2026
CVE-2026-17651
9.6 CRITICAL

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape …

Jul 30, 2026
CVE-2025-69943
9.8 CRITICAL

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.

Jul 29, 2026
CVE-2025-69942
9.8 CRITICAL

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

Jul 29, 2026
CVE-2025-67404
9.8 CRITICAL

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.

Jul 29, 2026
CVE-2025-67403
9.8 CRITICAL

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.

Jul 29, 2026
CVE-2025-65340
9.8 CRITICAL

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.

Jul 29, 2026
CVE-2026-67429
10.0 CRITICAL

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config …

Jul 29, 2026
CVE-2026-67426
9.3 CRITICAL

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on …

Jul 29, 2026
CVE-2026-16326
10.0 CRITICAL

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to …

Jul 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.