Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.6
CVE-2026-17669

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sand…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17664

Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the render…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17668

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chro…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17667

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chro…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome CRITICAL 9.1
CVE-2026-17666

Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome HIGH 8.8
CVE-2026-17665

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.3
CVE-2026-17663

Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised th…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17661

Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17652

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome HIGH 8.3
CVE-2026-17660

Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rende…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17658

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.3
CVE-2026-17657

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17656

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17655

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbo…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome HIGH 7.8
CVE-2026-17654

Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.3
CVE-2026-17653

Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perf…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17651

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perfor…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome HIGH 8.3
CVE-2026-17650

Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Imagemagick MEDIUM 5.3
CVE-2026-64685

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does no…

Fix: 7.1.2-27+
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.1
CVE-2026-62946

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, proc…

No fix yet
Fix from $1,600 2026-07-30
Imagemagick MEDIUM 5.0
CVE-2026-62363

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-writ…

Fix: 7.1.2-27+
Fix from $1,600 2026-07-30
Undici MEDIUM 5.4
CVE-2026-15157

undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatch…

Fix: 6.28.0 / 7.29.0+
Fix from $1,600 2026-07-29
Unclassified HIGH 7.3
CVE-2025-69949

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.3
CVE-2025-69945

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.1
CVE-2026-67595

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering secur…

Patch available
Fix from $1,950 2026-07-29
Undici HIGH 7.5
CVE-2026-14643

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. I…

Fix: 7.29.0 / 8.9.0+
Fix from $1,950 2026-07-29
Unclassified HIGH 7.3
CVE-2025-69944

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-69943

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.

Mitigation only
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-69942

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 7.3
CVE-2025-67408

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.

No fix yet
Fix from $1,950 2026-07-29