CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-12023
8.3 HIGH

Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially …

Jun 11, 2026
CVE-2026-12022
8.3 HIGH

Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform …

Jun 11, 2026
CVE-2026-12020
8.8 HIGH

Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Jun 11, 2026
CVE-2026-12019
8.3 HIGH

Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process …

Jun 11, 2026
CVE-2026-12018
8.8 HIGH

Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. …

Jun 11, 2026
CVE-2026-12016
8.3 HIGH

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jun 11, 2026
CVE-2026-12014
8.3 HIGH

Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape …

Jun 11, 2026
CVE-2026-12012
8.1 HIGH

Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via …

Jun 11, 2026
CVE-2026-12011
8.3 HIGH

Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially …

Jun 11, 2026
CVE-2026-12010
8.3 HIGH

Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially …

Jun 11, 2026
CVE-2026-12009
8.3 HIGH

Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process …

Jun 11, 2026
CVE-2026-12008
8.3 HIGH

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jun 11, 2026
CVE-2026-12007
8.8 HIGH

Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML …

Jun 11, 2026
CVE-2026-53819
8.8 HIGH

OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with …

Jun 11, 2026
CVE-2026-53817
8.8 HIGH

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable …

Jun 11, 2026
CVE-2026-53816
7.2 HIGH

OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. …

Jun 11, 2026
CVE-2026-53814
8.3 HIGH

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a …

Jun 11, 2026
CVE-2026-53813
7.8 HIGH

OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected …

Jun 11, 2026
CVE-2026-53812
7.7 HIGH

OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. …

Jun 11, 2026
CVE-2026-53811
8.8 HIGH

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name …

Jun 11, 2026
CVE-2026-53810
8.8 HIGH

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access …

Jun 11, 2026
CVE-2026-53807
8.8 HIGH

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks …

Jun 11, 2026
CVE-2026-53806
8.8 HIGH

OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by …

Jun 11, 2026
CVE-2026-50245
7.7 HIGH

Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera …

Jun 11, 2026
CVE-2026-50005
7.7 HIGH

Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.

Jun 11, 2026
CVE-2026-53782
7.4 HIGH

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript …

Jun 11, 2026
CVE-2026-46622
8.1 HIGH

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in …

Jun 11, 2026
CVE-2026-46489
8.1 HIGH

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can …

Jun 11, 2026
CVE-2026-52860
7.8 HIGH

Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current …

Jun 11, 2026
CVE-2026-52859
8.2 HIGH

Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the …

Jun 11, 2026
CVE-2026-52858
7.8 HIGH

Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter …

Jun 11, 2026
CVE-2026-48547
7.3 HIGH

KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the …

Jun 11, 2026
CVE-2026-47170
7.7 HIGH

Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the …

Jun 11, 2026
CVE-2026-47162
8.8 HIGH

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin …

Jun 11, 2026
CVE-2026-46519
8.8 HIGH

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as …

Jun 11, 2026
CVE-2026-11774
7.6 HIGH

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet …

Jun 11, 2026
CVE-2025-46315
7.5 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user …

Jun 11, 2026
CVE-2025-31272
7.8 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections …

Jun 11, 2026
CVE-2025-24284
8.8 HIGH

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to …

Jun 11, 2026
CVE-2026-48546
7.3 HIGH

KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require …

Jun 11, 2026
CVE-2026-46697
7.5 HIGH

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true …

Jun 11, 2026
CVE-2026-49982
8.2 HIGH

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain …

Jun 11, 2026
CVE-2026-44705
8.2 HIGH

tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping …

Jun 11, 2026
CVE-2026-44496
7.5 HIGH

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the …

Jun 11, 2026
CVE-2026-44495
7.0 HIGH

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request …

Jun 11, 2026
CVE-2026-44494
8.7 HIGH

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype …

Jun 11, 2026
CVE-2026-44492
8.6 HIGH

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When …

Jun 11, 2026
CVE-2026-44488
7.5 HIGH

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size …

Jun 11, 2026
CVE-2026-44487
7.5 HIGH

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization …

Jun 11, 2026
CVE-2026-44486
7.5 HIGH

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials …

Jun 11, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.