CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-87556
4.3 MEDIUM

Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium …

Sep 9, 2026
CVE-2026-87555
4.7 MEDIUM

Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a …

Sep 9, 2026
CVE-2026-87554
8.1 HIGH

Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via …

Sep 9, 2026
CVE-2026-87553
8.3 HIGH

Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 9, 2026
CVE-2026-87552
5.5 MEDIUM

Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. …

Sep 9, 2026
CVE-2026-87551
4.3 MEDIUM

Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted …

Sep 9, 2026
CVE-2026-87550
4.3 MEDIUM

Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via …

Sep 9, 2026
CVE-2026-87549
6.5 MEDIUM

Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 9, 2026
CVE-2026-87548
4.3 MEDIUM

Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. …

Sep 9, 2026
CVE-2026-87547
9.6 CRITICAL

Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-87546
4.3 MEDIUM

Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions …

Sep 9, 2026
CVE-2026-87545
6.5 MEDIUM

Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via …

Sep 9, 2026
CVE-2026-87544
9.8 CRITICAL

Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a …

Sep 9, 2026
CVE-2026-87543
4.3 MEDIUM

Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Sep 9, 2026
CVE-2026-87542
8.8 HIGH

Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87541
6.5 MEDIUM

Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Sep 9, 2026
CVE-2026-87540
5.4 MEDIUM

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87539
3.1 LOW

Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87538
4.2 MEDIUM

Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof …

Sep 9, 2026
CVE-2026-87537
8.1 HIGH

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Sep 9, 2026
CVE-2026-87536
8.8 HIGH

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87535
6.5 MEDIUM

Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via …

Sep 9, 2026
CVE-2026-87534
9.8 CRITICAL

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions …

Sep 9, 2026
CVE-2026-87533
8.1 HIGH

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local …

Sep 9, 2026
CVE-2026-87532
6.5 MEDIUM

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. …

Sep 9, 2026
CVE-2026-87531
3.1 LOW

Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via …

Sep 9, 2026
CVE-2026-87530
8.1 HIGH

Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-87529
9.6 CRITICAL

Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 9, 2026
CVE-2026-87528
9.6 CRITICAL

Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87527
9.6 CRITICAL

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML …

Sep 9, 2026
CVE-2026-87526
9.6 CRITICAL

Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the …

Sep 9, 2026
CVE-2026-87525
2.7 LOW

Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox …

Sep 9, 2026
CVE-2026-87524
8.3 HIGH

Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to …

Sep 9, 2026
CVE-2026-87523
5.3 MEDIUM

Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML …

Sep 9, 2026
CVE-2026-87522
6.5 MEDIUM

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access …

Sep 9, 2026
CVE-2026-87521
3.1 LOW

Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via …

Sep 9, 2026
CVE-2026-87520
9.6 CRITICAL

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87519
6.5 MEDIUM

Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 9, 2026
CVE-2026-87518
5.3 MEDIUM

Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially …

Sep 9, 2026
CVE-2026-87517
3.1 LOW

Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy …

Sep 9, 2026
CVE-2026-87516
4.3 MEDIUM

Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Sep 9, 2026
CVE-2026-87515
6.5 MEDIUM

Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 9, 2026
CVE-2026-87514
8.1 HIGH

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local …

Sep 9, 2026
CVE-2026-87513
6.5 MEDIUM

Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Sep 9, 2026
CVE-2026-87512
9.6 CRITICAL

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 9, 2026
CVE-2026-87511
4.3 MEDIUM

Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security …

Sep 9, 2026
CVE-2026-87510
8.3 HIGH

Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 9, 2026
CVE-2026-87509
8.1 HIGH

Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via …

Sep 9, 2026
CVE-2026-87508
4.3 MEDIUM

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Sep 9, 2026
CVE-2026-87507
5.4 MEDIUM

UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.