CVE Vulnerability Database

Search and browse 398,150 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-7905HIGH8.3Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote ...
CVE-2026-7904MEDIUM4.3Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bound...
CVE-2026-7903HIGH8.8Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentiall...
CVE-2026-7902HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary...
CVE-2026-7901HIGH8.8Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary co...
CVE-2026-7900HIGH8.3Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the ...
CVE-2026-7899HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrar...
CVE-2026-7898HIGH8.8Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbit...
CVE-2026-7897HIGH7.5Use after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user t...
CVE-2026-7896HIGH8.8Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap ...
CVE-2026-41938HIGH8.8Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows ...
CVE-2026-41936HIGH8.6Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import fea...
CVE-2026-41934HIGH8.8Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that...
CVE-2026-41931MEDIUM6.9Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to o...
CVE-2026-41930CRITICAL9.8Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configura...
CVE-2026-34474HIGH7.5Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to ...
CVE-2026-34473HIGH7.5Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H...
CVE-2026-0300CRITICAL9.8A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks...
CVE-2025-31974HIGH7.2HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configur...
CVE-2025-31960MEDIUM5.3HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its repor...
CVE-2024-30151HIGH8.3HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation...
CVE-2026-33079HIGH7.5In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `...
CVE-2026-29090HIGH8.8### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and ...
CVE-2026-7875CRITICAL9.3NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment hand...
CVE-2026-42503HIGH8.8gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen...