CVE Vulnerability Database
Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11641 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced ... |
| CVE-2026-11640 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re... |
| CVE-2026-11639 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbit... |
| CVE-2026-11638 | CRITICAL | 9.6 | 0.3% | Jun 9, 2026 | Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a s... |
| CVE-2026-11637 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary c... |
| CVE-2026-11636 | HIGH | 7.5 | 0.2% | Jun 9, 2026 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a... |
| CVE-2026-11635 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromise... |
| CVE-2026-11634 | CRITICAL | 9.6 | 0.3% | Jun 9, 2026 | Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially p... |
| CVE-2026-11633 | HIGH | 8.8 | 0.2% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitra... |
| CVE-2026-11632 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to en... |
| CVE-2026-11631 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised... |
| CVE-2026-11630 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit h... |
| CVE-2026-11629 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap c... |
| CVE-2026-11628 | MEDIUM | 6.8 | 0.2% | Jun 9, 2026 | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap co... |
| CVE-2026-9669 | HIGH | 8.2 | 0.4% | Jun 8, 2026 | bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError ... |
| CVE-2026-44541 | HIGH | 7 | 0.3% | Jun 8, 2026 | Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based... |
| CVE-2026-40215 | HIGH | 7.4 | 0.3% | Jun 8, 2026 | A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cau... |
| CVE-2026-11585 | MEDIUM | 6.3 | 0.2% | Jun 8, 2026 | A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of... |
| CVE-2026-49141 | HIGH | 7.1 | 0.2% | Jun 8, 2026 | WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authent... |
| CVE-2026-47345 | MEDIUM | 5.1 | 0.4% | Jun 8, 2026 | Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting... |
| CVE-2026-47344 | LOW | 2.1 | 0.3% | Jun 8, 2026 | When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sa... |
| CVE-2026-46484 | HIGH | 8.1 | 0.4% | Jun 8, 2026 | Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable... |
| CVE-2026-40519 | HIGH | 7.7 | 0.9% | Jun 8, 2026 | Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execut... |
| CVE-2026-35058 | MEDIUM | 6.5 | 0.3% | Jun 8, 2026 | Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 t... |
| CVE-2026-11584 | MEDIUM | 6.3 | 0.2% | Jun 8, 2026 | A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the... |
