Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.6
CVE-2026-17688

Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17687

Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17684

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had comprom…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17682

Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially p…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17681

Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17680

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process …

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17676

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer p…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17675

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17673

Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially pe…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17672

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the re…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17671

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendere…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17670

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17669

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sand…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.1
CVE-2026-17666

Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17652

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17656

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17655

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbo…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17651

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perfor…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69943

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.

Mitigation only
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-69942

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-67404

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_cla…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-67403

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-65340

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 10.0
CVE-2026-67429

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller…

Patch available
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-67426

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri…

Patch available
Fix from $2,300 2026-07-29
Unclassified CRITICAL 10.0
CVE-2026-16326

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authen…

No fix yet
Fix from $2,300 2026-07-29
Websphere Application Server CRITICAL 9.8
CVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-41939

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows u…

Mitigation only
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-18236

A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or in…

Patch available
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.2
CVE-2026-8338

A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malic…

No fix yet
Fix from $2,300 2026-07-29