CVE Vulnerability Database

Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-11641HIGH7.5Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced ...
CVE-2026-11640HIGH8.3Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re...
CVE-2026-11639HIGH7.5Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbit...
CVE-2026-11638CRITICAL9.6Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a s...
CVE-2026-11637HIGH8.8Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary c...
CVE-2026-11636HIGH7.5Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a...
CVE-2026-11635HIGH8.3Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromise...
CVE-2026-11634CRITICAL9.6Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially p...
CVE-2026-11633HIGH8.8Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitra...
CVE-2026-11632HIGH7.5Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to en...
CVE-2026-11631HIGH8.3Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised...
CVE-2026-11630HIGH8.8Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit h...
CVE-2026-11629HIGH8.8Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap c...
CVE-2026-11628MEDIUM6.8Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap co...
CVE-2026-9669HIGH8.2bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError ...
CVE-2026-44541HIGH7Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based...
CVE-2026-40215HIGH7.4A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cau...
CVE-2026-11585MEDIUM6.3A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of...
CVE-2026-49141HIGH7.1WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authent...
CVE-2026-47345MEDIUM5.1Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting...
CVE-2026-47344LOW2.1When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sa...
CVE-2026-46484HIGH8.1Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable...
CVE-2026-40519HIGH7.7Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execut...
CVE-2026-35058MEDIUM6.5Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 t...
CVE-2026-11584MEDIUM6.3A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the...