Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-95342 | UNKNOWN | — | Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium … | Sep 29, 2026 |
| CVE-2026-95341 | HIGH | 8.3 | Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-95340 | UNKNOWN | — | Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted … | Sep 29, 2026 |
| CVE-2026-95339 | CRITICAL | 9.6 | Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-95338 | HIGH | 8.8 | Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-95337 | MEDIUM | 5.4 | UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements … | Sep 29, 2026 |
| CVE-2026-95336 | MEDIUM | 6.5 | Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted … | Sep 29, 2026 |
| CVE-2026-95335 | HIGH | 8.3 | Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-95334 | HIGH | 8.3 | Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-95333 | HIGH | 8.1 | Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network … | Sep 29, 2026 |
| CVE-2026-95332 | MEDIUM | 4.7 | Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox … | Sep 29, 2026 |
| CVE-2026-95331 | CRITICAL | 9.6 | Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via … | Sep 29, 2026 |
| CVE-2026-95330 | UNKNOWN | — | Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. … | Sep 29, 2026 |
| CVE-2026-95329 | CRITICAL | 9.6 | Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside … | Sep 29, 2026 |
| CVE-2026-95328 | MEDIUM | 6.5 | Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via … | Sep 29, 2026 |
| CVE-2026-95327 | MEDIUM | 6.5 | Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security … | Sep 29, 2026 |
| CVE-2026-95326 | UNKNOWN | — | Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted … | Sep 29, 2026 |
| CVE-2026-95325 | CRITICAL | 9.6 | Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a … | Sep 29, 2026 |
| CVE-2026-95324 | LOW | 3.4 | Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the … | Sep 29, 2026 |
| CVE-2026-95323 | MEDIUM | 5.4 | UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via … | Sep 29, 2026 |
| CVE-2026-95322 | HIGH | 8.3 | Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process … | Sep 29, 2026 |
| CVE-2026-95321 | MEDIUM | 5.4 | UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95320 | MEDIUM | 5.4 | Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via … | Sep 29, 2026 |
| CVE-2026-95319 | HIGH | 8.3 | Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-95318 | CRITICAL | 9.6 | Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted … | Sep 29, 2026 |