CVE Vulnerability Database

Search and browse 381,546 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-17655CRITICAL9.6Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to...
CVE-2026-17654HIGH7.8Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege es...
CVE-2026-17653HIGH8.3Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendere...
CVE-2026-17652CRITICAL9.6Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the render...
CVE-2026-17651CRITICAL9.6Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote a...
CVE-2026-17650HIGH8.3Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the ...
CVE-2026-64685MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1....
CVE-2026-62946MEDIUM4.7ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both...
CVE-2026-62363MEDIUM5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1....
CVE-2026-62343MEDIUM4.7ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9....
CVE-2026-16339Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-67595CRITICAL9.2VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template re...
CVE-2026-18060Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-15157MEDIUM5.4undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type he...
CVE-2026-14643HIGH7.5undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or priva...
CVE-2025-69949HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em...
CVE-2025-69945HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
CVE-2025-69944HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie...
CVE-2025-69943CRITICAL9.8kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and ...
CVE-2025-69942CRITICAL9.8kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
CVE-2025-67408HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter ...
CVE-2025-67407HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters...
CVE-2025-67406HIGH7.3https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu...
CVE-2025-67405HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param...
CVE-2025-67404CRITICAL9.8Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters ...