CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-11264
4.3 MEDIUM

Policy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML …

Jun 5, 2026
CVE-2026-11263
6.5 MEDIUM

Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak …

Jun 5, 2026
CVE-2026-11261
4.3 MEDIUM

Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via …

Jun 5, 2026
CVE-2026-11260
4.3 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium …

Jun 5, 2026
CVE-2026-11259
4.3 MEDIUM

Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted …

Jun 5, 2026
CVE-2026-11258
6.5 MEDIUM

Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI …

Jun 5, 2026
CVE-2026-11257
4.3 MEDIUM

Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security …

Jun 5, 2026
CVE-2026-11254
4.3 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Jun 5, 2026
CVE-2026-11253
4.3 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Jun 5, 2026
CVE-2026-11252
4.3 MEDIUM

Insufficient policy enforcement in Content Settings in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML …

Jun 5, 2026
CVE-2026-11249
4.7 MEDIUM

Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive …

Jun 5, 2026
CVE-2026-11246
5.3 MEDIUM

Insufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 5, 2026
CVE-2026-11245
4.3 MEDIUM

Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Jun 5, 2026
CVE-2026-11243
5.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security …

Jun 5, 2026
CVE-2026-11238
5.9 MEDIUM

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially …

Jun 5, 2026
CVE-2026-10878
6.3 MEDIUM

A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results …

Jun 5, 2026
CVE-2026-10876
6.3 MEDIUM

A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of …

Jun 5, 2026
CVE-2026-47655
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

Jun 4, 2026
CVE-2026-47644
6.5 MEDIUM

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information …

Jun 4, 2026
CVE-2026-42824
6.5 MEDIUM

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Jun 4, 2026
CVE-2026-11234
4.3 MEDIUM

Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Jun 4, 2026
CVE-2026-11233
4.7 MEDIUM

Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin …

Jun 4, 2026
CVE-2026-11232
5.4 MEDIUM

Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: …

Jun 4, 2026
CVE-2026-11229
6.1 MEDIUM

Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium …

Jun 4, 2026
CVE-2026-11228
4.3 MEDIUM

Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Jun 4, 2026
CVE-2026-11227
6.5 MEDIUM

Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain …

Jun 4, 2026
CVE-2026-11226
6.5 MEDIUM

Insufficient policy enforcement in PreviewTab in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific …

Jun 4, 2026
CVE-2026-11225
6.5 MEDIUM

Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security …

Jun 4, 2026
CVE-2026-11223
6.5 MEDIUM

Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 4, 2026
CVE-2026-11222
6.5 MEDIUM

Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted HTML page. …

Jun 4, 2026
CVE-2026-11221
4.3 MEDIUM

Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform …

Jun 4, 2026
CVE-2026-11220
6.5 MEDIUM

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 4, 2026
CVE-2026-11219
4.3 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security …

Jun 4, 2026
CVE-2026-11218
6.8 MEDIUM

Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI …

Jun 4, 2026
CVE-2026-11217
6.5 MEDIUM

Inappropriate implementation in Fenced Frames in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation …

Jun 4, 2026
CVE-2026-11216
4.3 MEDIUM

Incorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI …

Jun 4, 2026
CVE-2026-11215
6.5 MEDIUM

Inappropriate implementation in Cronet in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. …

Jun 4, 2026
CVE-2026-11214
6.5 MEDIUM

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted …

Jun 4, 2026
CVE-2026-11212
4.3 MEDIUM

Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak …

Jun 4, 2026
CVE-2026-11210
6.5 MEDIUM

Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted RAR file. …

Jun 4, 2026
CVE-2026-11209
6.5 MEDIUM

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information …

Jun 4, 2026
CVE-2026-11208
6.5 MEDIUM

Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a …

Jun 4, 2026
CVE-2026-11206
6.5 MEDIUM

Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

Jun 4, 2026
CVE-2026-11205
6.1 MEDIUM

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user …

Jun 4, 2026
CVE-2026-11204
6.5 MEDIUM

Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. …

Jun 4, 2026
CVE-2026-11203
6.5 MEDIUM

Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

Jun 4, 2026
CVE-2026-11200
6.5 MEDIUM

Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Jun 4, 2026
CVE-2026-11199
5.9 MEDIUM

Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to leak cross-origin data via malicious network …

Jun 4, 2026
CVE-2026-11197
6.5 MEDIUM

Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin …

Jun 4, 2026
CVE-2026-11196
6.5 MEDIUM

Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jun 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.