Free Security Tools & CVE Database

Track CVE vulnerabilities, run security tools, and stay informed with expert cybersecurity guides.

🛡️ CVE Vulnerability Database (11,425+ CVEs tracked) Browse all →

🔴 Critical (1,151) 🟠 High (3,823) 🟡 Medium 🟢 Low 📅 2026
CVE-2026-10986 8.8
Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)
Google › Chrome
CVE-2026-10982 8.8
Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Google › Chrome
CVE-2026-10978 8.8
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
Google › Chrome
CVE-2026-10975 8.8
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Google › Chrome
CVE-2026-10973 7.4
Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Google › Chrome
CVE-2026-10972 9.6
Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Google › Chrome
🏢 Browse CVEs by Vendor:
Google (241) Linux (236) Microsoft (150) Apache (124) Openclaw (116) Mozilla (81) Axiomthemes (58) Schneider-Electric (55)

🛠️ Security Tools View all →

🔐
Password Checker
Test your password strength
🔑
Password Generator
Generate secure passwords
🛡️
Privacy Score Quiz
Rate your digital privacy habits
🎣
Phishing Detector
Analyze suspicious emails
🔓
Data Breach Info
What to do after a breach
🌐
VPN Comparison
Compare top VPN services
🔒
Encryption Strength
Evaluate algorithm security
📶
WiFi Security
Audit your WiFi settings
📱
2FA Guide
2FA support by service
👁️
Social Privacy Audit
Lock down your social accounts

📝 Latest Articles

Passkeys vs Passwords in 2026: A Small Business Migration Guide
Password Managers

Passkeys vs Passwords in 2026: A Small Business Migration Guide

Passkeys cut account-takeover risk by 99.9% over passwords, but most small teams still run on shared spreadsheets. Here is a practical, phased migration plan based on shipping WebAuthn in real production apps.

May 30, 2026 8 min read
Mini Shai-Hulud npm and PyPI Worm: How TeamPCP Hijacked TanStack, AntV, and OIDC Trusted Publishing in May 2026 (Developer Defense Guide)
Threat Analysis

Mini Shai-Hulud npm and PyPI Worm: How TeamPCP Hijacked TanStack, AntV, and OIDC Trusted Publishing in May 2026 (Developer Defense Guide)

In May 2026 the Mini Shai-Hulud worm compromised 84 @tanstack packages in 6 minutes and 300+ @antv-adjacent versions in 22 minutes by exploiting npm OIDC trusted publishing. Even maintainers with 2FA, short-lived tokens, and signed provenance got hit. Here is what actually broke, what I changed in my CI pipelines across seven aggregator sites, and a 9-step lockdown plan for your npm and PyPI workflow.

May 29, 2026 9 min read