CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10999
6.5 MEDIUM

Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially …

Jun 4, 2026
CVE-2026-10998
4.0 MEDIUM

Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of …

Jun 4, 2026
CVE-2026-10997
6.5 MEDIUM

Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass …

Jun 4, 2026
CVE-2026-10996
6.5 MEDIUM

Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium …

Jun 4, 2026
CVE-2026-10994
6.5 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jun 4, 2026
CVE-2026-10993
6.5 MEDIUM

Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a …

Jun 4, 2026
CVE-2026-10992
6.5 MEDIUM

Insufficient data validation in Animation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a …

Jun 4, 2026
CVE-2026-10985
6.5 MEDIUM

Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

Jun 4, 2026
CVE-2026-10984
5.4 MEDIUM

Inappropriate implementation in Accessibility in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Jun 4, 2026
CVE-2026-10981
6.5 MEDIUM

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak …

Jun 4, 2026
CVE-2026-10980
6.5 MEDIUM

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 4, 2026
CVE-2026-10979
6.5 MEDIUM

Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via …

Jun 4, 2026
CVE-2026-10977
6.5 MEDIUM

Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

Jun 4, 2026
CVE-2026-10950
6.5 MEDIUM

Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Jun 4, 2026
CVE-2026-10944
6.5 MEDIUM

Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Jun 4, 2026
CVE-2026-10938
6.5 MEDIUM

Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Jun 4, 2026
CVE-2026-10937
6.5 MEDIUM

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium …

Jun 4, 2026
CVE-2026-10916
6.1 MEDIUM

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to inject …

Jun 4, 2026
CVE-2026-10912
6.5 MEDIUM

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 4, 2026
CVE-2026-10875
6.3 MEDIUM

A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unknown function of the file /admin/adminHome.ph. …

Jun 4, 2026
CVE-2026-10874
6.3 MEDIUM

A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin/adminHome.php. The manipulation …

Jun 4, 2026
CVE-2024-27891
5.3 MEDIUM

On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets …

Jun 4, 2026
CVE-2023-5502
5.9 MEDIUM

On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a …

Jun 4, 2026
CVE-2026-42547
5.4 MEDIUM

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users can create alerts for …

Jun 4, 2026
CVE-2026-42543
4.3 MEDIUM

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vulnerable to a cross-site request …

Jun 4, 2026
CVE-2026-42540
4.3 MEDIUM

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 allow a user to alter values …

Jun 4, 2026
CVE-2026-42539
6.5 MEDIUM

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return sensitive data to the user …

Jun 4, 2026
CVE-2026-11322
6.5 MEDIUM

Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks that resolve to files …

Jun 4, 2026
CVE-2024-6858
6.5 MEDIUM

In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device …

Jun 4, 2026
CVE-2026-5066
6.3 MEDIUM

A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/lib/sockets/sockets_tls.c). When the TLS session cache is enabled, tls_session_store() …

Jun 4, 2026
CVE-2026-42538
6.3 MEDIUM

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files. …

Jun 4, 2026
CVE-2026-42329
4.7 MEDIUM

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 contain a weakness where an attacker …

Jun 4, 2026
CVE-2026-5589
6.3 MEDIUM

An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-bounds write. When CONFIG_BT_MESH_OD_PRIV_PROXY_SRV is enabled, the function parses solicitation …

Jun 4, 2026
CVE-2026-21404
6.3 MEDIUM

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can …

Jun 4, 2026
CVE-2026-40898
5.3 MEDIUM

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client …

Jun 4, 2026
CVE-2026-36499
6.5 MEDIUM

A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of …

Jun 4, 2026
CVE-2025-65640
6.3 MEDIUM

Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user …

Jun 4, 2026
CVE-2026-41207
5.3 MEDIUM

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The byte[] is filled with …

Jun 4, 2026
CVE-2026-49940
6.5 MEDIUM

Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly …

Jun 4, 2026
CVE-2026-46739
5.3 MEDIUM

Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources …

Jun 4, 2026
CVE-2026-41178
5.3 MEDIUM

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and …

Jun 4, 2026
CVE-2026-40930
5.4 MEDIUM

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard …

Jun 4, 2026
CVE-2026-10815
6.3 MEDIUM

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard …

Jun 4, 2026
CVE-2026-10814
4.5 MEDIUM

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID …

Jun 4, 2026
CVE-2026-47707
5.3 MEDIUM

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect …

Jun 4, 2026
CVE-2026-47706
5.3 MEDIUM

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to …

Jun 4, 2026
CVE-2026-36180
4.6 MEDIUM

A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for …

Jun 4, 2026
CVE-2026-36178
4.6 MEDIUM

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and …

Jun 4, 2026
CVE-2026-36175
6.8 MEDIUM

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence …

Jun 4, 2026
CVE-2026-36174
4.6 MEDIUM

GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximate attackers …

Jun 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.