Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54274
Total
4303
Critical
16132
High
15830
Medium
CVE ID Severity Score Description Published
CVE-2026-95367 MEDIUM 5.3 Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to … Sep 29, 2026
CVE-2026-95366 UNKNOWN — Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web … Sep 29, 2026
CVE-2026-95365 HIGH 8.8 Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted … Sep 29, 2026
CVE-2026-95364 MEDIUM 5.4 Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium … Sep 29, 2026
CVE-2026-95363 MEDIUM 5.4 UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML … Sep 29, 2026
CVE-2026-95362 UNKNOWN — Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a … Sep 29, 2026
CVE-2026-95361 UNKNOWN — Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted … Sep 29, 2026
CVE-2026-95360 MEDIUM 5.3 Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML … Sep 29, 2026
CVE-2026-95359 LOW 3.4 Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read … Sep 29, 2026
CVE-2026-95358 UNKNOWN — Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged … Sep 29, 2026
CVE-2026-95357 CRITICAL 9.6 Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside … Sep 29, 2026
CVE-2026-95356 CRITICAL 9.6 Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the … Sep 29, 2026
CVE-2026-95355 HIGH 8.3 Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially … Sep 29, 2026
CVE-2026-95354 HIGH 8.3 Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … Sep 29, 2026
CVE-2026-95353 HIGH 8.8 Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … Sep 29, 2026
CVE-2026-95352 MEDIUM 5.4 Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted … Sep 29, 2026
CVE-2026-95351 HIGH 8.3 Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code … Sep 29, 2026
CVE-2026-95350 CRITICAL 9.6 Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via … Sep 29, 2026
CVE-2026-95349 CRITICAL 9.6 Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox … Sep 29, 2026
CVE-2026-95348 HIGH 8.3 Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … Sep 29, 2026
CVE-2026-95347 CRITICAL 9.6 Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox … Sep 29, 2026
CVE-2026-95346 MEDIUM 4.8 UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: … Sep 29, 2026
CVE-2026-95345 HIGH 8.8 Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … Sep 29, 2026
CVE-2026-95344 UNKNOWN — Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome … Sep 29, 2026
CVE-2026-95343 HIGH 8.8 Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … Sep 29, 2026