CVE Vulnerability Database

Search and browse 390,033 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15121HIGH8.8Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code in...
CVE-2026-15120HIGH8.3Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised...
CVE-2026-15119HIGH8.3Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer...
CVE-2026-15118HIGH8.8Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-15117HIGH7.5Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to en...
CVE-2026-15116HIGH8.8Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-15115LOW3.3Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed...
CVE-2026-15114HIGH8.8Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially...
CVE-2026-15113CRITICAL9.6Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially ...
CVE-2026-15112HIGH8.8Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap c...
CVE-2026-15111HIGH7.5Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engag...
CVE-2026-15110HIGH8.8Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to instal...
CVE-2026-15109MEDIUM6.5Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sens...
CVE-2026-15108MEDIUM4.3Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to ...
CVE-2026-15107HIGH8.8Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code...
CVE-2026-15105MEDIUM6.3A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the...
CVE-2026-5923MEDIUM6Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.
CVE-2026-5922MEDIUM5.9The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpa...
CVE-2026-55878HIGH7.8Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install ...
CVE-2026-55877MEDIUM6.1Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() T...
CVE-2026-55849HIGH8.5@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CL...
CVE-2026-55830HIGH8.3RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input ...
CVE-2026-55471CRITICAL9.1HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10...
CVE-2026-55470HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10...
CVE-2026-54777MEDIUM6.5CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...