Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-95367 | MEDIUM | 5.3 | Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to … | Sep 29, 2026 |
| CVE-2026-95366 | UNKNOWN | — | Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web … | Sep 29, 2026 |
| CVE-2026-95365 | HIGH | 8.8 | Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-95364 | MEDIUM | 5.4 | Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium … | Sep 29, 2026 |
| CVE-2026-95363 | MEDIUM | 5.4 | UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95362 | UNKNOWN | — | Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a … | Sep 29, 2026 |
| CVE-2026-95361 | UNKNOWN | — | Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted … | Sep 29, 2026 |
| CVE-2026-95360 | MEDIUM | 5.3 | Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95359 | LOW | 3.4 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read … | Sep 29, 2026 |
| CVE-2026-95358 | UNKNOWN | — | Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged … | Sep 29, 2026 |
| CVE-2026-95357 | CRITICAL | 9.6 | Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside … | Sep 29, 2026 |
| CVE-2026-95356 | CRITICAL | 9.6 | Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the … | Sep 29, 2026 |
| CVE-2026-95355 | HIGH | 8.3 | Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially … | Sep 29, 2026 |
| CVE-2026-95354 | HIGH | 8.3 | Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-95353 | HIGH | 8.8 | Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-95352 | MEDIUM | 5.4 | Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted … | Sep 29, 2026 |
| CVE-2026-95351 | HIGH | 8.3 | Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code … | Sep 29, 2026 |
| CVE-2026-95350 | CRITICAL | 9.6 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via … | Sep 29, 2026 |
| CVE-2026-95349 | CRITICAL | 9.6 | Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox … | Sep 29, 2026 |
| CVE-2026-95348 | HIGH | 8.3 | Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-95347 | CRITICAL | 9.6 | Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox … | Sep 29, 2026 |
| CVE-2026-95346 | MEDIUM | 4.8 | UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: … | Sep 29, 2026 |
| CVE-2026-95345 | HIGH | 8.8 | Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-95344 | UNKNOWN | — | Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome … | Sep 29, 2026 |
| CVE-2026-95343 | HIGH | 8.8 | Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Sep 29, 2026 |