CVE Database

5195+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13480
3.1 LOW

The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes without validating that enough payload bytes remain before each access. …

Aug 26, 2026
CVE-2026-13479
3.1 LOW

The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only guarantees that the one-byte command id is in bounds; for the …

Aug 26, 2026
CVE-2026-7487
3.5 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain …

Aug 26, 2026
CVE-2026-19220
3.7 LOW

The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated …

Aug 26, 2026
CVE-2026-9805
2.7 LOW

SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.

Aug 26, 2026
CVE-2026-80201
2.0 LOW

Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with …

Aug 26, 2026
CVE-2026-80199
3.7 LOW

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response …

Aug 26, 2026
CVE-2026-79289
3.1 LOW

Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer …

Aug 25, 2026
CVE-2026-79272
3.1 LOW

Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data …

Aug 25, 2026
CVE-2026-79255
3.1 LOW

Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin …

Aug 25, 2026
CVE-2026-79228
3.1 LOW

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation into …

Aug 25, 2026
CVE-2026-79203
3.1 LOW

Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation …

Aug 25, 2026
CVE-2026-79191
3.1 LOW

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Aug 25, 2026
CVE-2026-79186
3.1 LOW

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Aug 25, 2026
CVE-2026-79103
3.1 LOW

Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation …

Aug 25, 2026
CVE-2026-79066
3.1 LOW

Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation …

Aug 25, 2026
CVE-2026-79059
3.1 LOW

Information leak in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via …

Aug 25, 2026
CVE-2026-79053
3.1 LOW

Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Aug 25, 2026
CVE-2026-79034
3.1 LOW

Information leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

Aug 25, 2026
CVE-2026-79031
3.1 LOW

Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-79007
3.1 LOW

Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside …

Aug 25, 2026
CVE-2026-79004
3.4 LOW

Out of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory …

Aug 25, 2026
CVE-2026-79002
3.1 LOW

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Aug 25, 2026
CVE-2026-78986
3.1 LOW

Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data …

Aug 25, 2026
CVE-2026-78984
3.4 LOW

Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside …

Aug 25, 2026
CVE-2026-78958
3.1 LOW

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data …

Aug 25, 2026
CVE-2026-78953
3.1 LOW

Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Aug 25, 2026
CVE-2026-78949
2.9 LOW

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. …

Aug 25, 2026
CVE-2026-78943
3.1 LOW

Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering …

Aug 25, 2026
CVE-2026-78941
3.1 LOW

Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Aug 25, 2026
CVE-2026-78936
2.9 LOW

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. …

Aug 25, 2026
CVE-2026-78903
3.1 LOW

Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Aug 25, 2026
CVE-2026-78894
3.1 LOW

Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

Aug 25, 2026
CVE-2026-43657
3.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to …

Aug 25, 2026
CVE-2026-79783
3.6 LOW

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on …

Aug 25, 2026
CVE-2026-79782
3.1 LOW

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can …

Aug 25, 2026
CVE-2026-79777
2.7 LOW

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, …

Aug 25, 2026
CVE-2026-70548
3.5 LOW

Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.

Aug 25, 2026
CVE-2025-71346
2.9 LOW

Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-read (CVE-2025-32415) in the xmlSchemaIDCFillNodeTables function in xmlschemas.c. The …

Aug 25, 2026
CVE-2026-78887
3.7 LOW

A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation …

Aug 25, 2026
CVE-2026-78886
3.7 LOW

A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public …

Aug 25, 2026
CVE-2026-21758
3.7 LOW

HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment.

Aug 25, 2026
CVE-2026-78638
3.3 LOW

A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component …

Aug 25, 2026
CVE-2026-72701
3.7 LOW

Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce …

Aug 25, 2026
CVE-2026-78435
3.8 LOW

A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. …

Aug 24, 2026
CVE-2026-76816
3.5 LOW

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH …

Aug 24, 2026
CVE-2026-78187
3.1 LOW

A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang …

Aug 24, 2026
CVE-2026-19565
3.7 LOW

Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessionAuthKey runs five rounds of SHA-256, …

Aug 23, 2026
CVE-2026-77003
2.7 LOW

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role …

Aug 23, 2026
CVE-2026-78049
3.7 LOW

A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes of the file src/ClientServer/address_space/internal/sopc_node_mgt_helper_internal.c of the component AddNodes Service. …

Aug 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.