Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-95317 | LOW | 3.1 | Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome … | Sep 29, 2026 |
| CVE-2026-95316 | LOW | 2.9 | Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program. (Chromium security … | Sep 29, 2026 |
| CVE-2026-95315 | HIGH | 7.8 | Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI … | Sep 29, 2026 |
| CVE-2026-95314 | UNKNOWN | — | Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions … | Sep 29, 2026 |
| CVE-2026-95313 | CRITICAL | 9.6 | Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a … | Sep 29, 2026 |
| CVE-2026-95312 | LOW | 3.1 | Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via … | Sep 29, 2026 |
| CVE-2026-95311 | CRITICAL | 9.6 | Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside … | Sep 29, 2026 |
| CVE-2026-95310 | CRITICAL | 9.6 | Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-95309 | MEDIUM | 5.4 | UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95308 | LOW | 3.4 | Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially read memory outside … | Sep 29, 2026 |
| CVE-2026-95307 | MEDIUM | 5.4 | UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95306 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95305 | MEDIUM | 4.8 | UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. … | Sep 29, 2026 |
| CVE-2026-95304 | HIGH | 8.8 | Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a … | Sep 29, 2026 |
| CVE-2026-95303 | UNKNOWN | — | Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted … | Sep 29, 2026 |
| CVE-2026-95302 | LOW | 2.9 | Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. … | Sep 29, 2026 |
| CVE-2026-95301 | UNKNOWN | — | Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via … | Sep 29, 2026 |
| CVE-2026-95300 | UNKNOWN | — | Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network … | Sep 29, 2026 |
| CVE-2026-95299 | CRITICAL | 9.6 | Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-95298 | HIGH | 7.8 | Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI … | Sep 29, 2026 |
| CVE-2026-95297 | UNKNOWN | — | Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. … | Sep 29, 2026 |
| CVE-2026-95296 | MEDIUM | 4.3 | Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via … | Sep 29, 2026 |
| CVE-2026-95295 | MEDIUM | 4.6 | Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium … | Sep 29, 2026 |
| CVE-2026-95294 | MEDIUM | 5.4 | UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95293 | MEDIUM | 4.7 | Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. … | Sep 29, 2026 |