CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-87656
5.4 MEDIUM

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. …

Sep 9, 2026
CVE-2026-87655
5.4 MEDIUM

Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. …

Sep 9, 2026
CVE-2026-87654
9.6 CRITICAL

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via …

Sep 9, 2026
CVE-2026-87653
5.4 MEDIUM

UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML …

Sep 9, 2026
CVE-2026-87652
3.1 LOW

Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Sep 9, 2026
CVE-2026-87651
4.3 MEDIUM

Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87650
9.6 CRITICAL

Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via …

Sep 9, 2026
CVE-2026-87649
5.4 MEDIUM

UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 9, 2026
CVE-2026-87648
8.3 HIGH

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to …

Sep 9, 2026
CVE-2026-87647
3.4 LOW

Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the …

Sep 9, 2026
CVE-2026-87646
9.6 CRITICAL

Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a …

Sep 9, 2026
CVE-2026-87645
5.4 MEDIUM

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. …

Sep 9, 2026
CVE-2026-87644
8.3 HIGH

Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged …

Sep 9, 2026
CVE-2026-87643
9.6 CRITICAL

Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87642
4.3 MEDIUM

Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87641
4.2 MEDIUM

Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium …

Sep 9, 2026
CVE-2026-87640
6.1 MEDIUM

Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process …

Sep 9, 2026
CVE-2026-87639
8.3 HIGH

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 9, 2026
CVE-2026-87638
9.6 CRITICAL

Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via …

Sep 9, 2026
CVE-2026-87637
9.6 CRITICAL

Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87636
8.8 HIGH

Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87635
5.4 MEDIUM

UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87634
9.6 CRITICAL

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 9, 2026
CVE-2026-87633
8.6 HIGH

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. …

Sep 9, 2026
CVE-2026-87632
4.3 MEDIUM

Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Sep 9, 2026
CVE-2026-87631
6.5 MEDIUM

Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium …

Sep 9, 2026
CVE-2026-87630
4.3 MEDIUM

Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. …

Sep 9, 2026
CVE-2026-87629
6.5 MEDIUM

Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML …

Sep 9, 2026
CVE-2026-87628
8.3 HIGH

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted …

Sep 9, 2026
CVE-2026-87627
6.5 MEDIUM

Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions …

Sep 9, 2026
CVE-2026-87626
6.5 MEDIUM

Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security …

Sep 9, 2026
CVE-2026-87625
8.8 HIGH

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox …

Sep 9, 2026
CVE-2026-87624
4.2 MEDIUM

UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof …

Sep 9, 2026
CVE-2026-87623
6.5 MEDIUM

Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML …

Sep 9, 2026
CVE-2026-87622
4.3 MEDIUM

Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Sep 9, 2026
CVE-2026-87621
9.6 CRITICAL

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside …

Sep 9, 2026
CVE-2026-87620
6.5 MEDIUM

Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87619
4.3 MEDIUM

Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87618
8.3 HIGH

Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to …

Sep 9, 2026
CVE-2026-87617
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox …

Sep 9, 2026
CVE-2026-87616
8.3 HIGH

Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged …

Sep 9, 2026
CVE-2026-87615
5.4 MEDIUM

Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 9, 2026
CVE-2026-87614
3.1 LOW

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Sep 9, 2026
CVE-2026-87613
9.0 CRITICAL

Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted …

Sep 9, 2026
CVE-2026-87612
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 9, 2026
CVE-2026-87611
3.1 LOW

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via …

Sep 9, 2026
CVE-2026-87610
6.5 MEDIUM

Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a …

Sep 9, 2026
CVE-2026-87609
9.6 CRITICAL

Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87608
7.5 HIGH

Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted …

Sep 9, 2026
CVE-2026-87607
9.6 CRITICAL

Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the …

Sep 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.