CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78966
4.3 MEDIUM

Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. …

Aug 25, 2026
CVE-2026-78965
4.3 MEDIUM

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78964
9.6 CRITICAL

Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the …

Aug 25, 2026
CVE-2026-78963
8.8 HIGH

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Aug 25, 2026
CVE-2026-78962
4.3 MEDIUM

Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted …

Aug 25, 2026
CVE-2026-78961
4.3 MEDIUM

Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Aug 25, 2026
CVE-2026-78960
6.5 MEDIUM

Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome …

Aug 25, 2026
CVE-2026-78959
6.5 MEDIUM

Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions …

Aug 25, 2026
CVE-2026-78958
3.1 LOW

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data …

Aug 25, 2026
CVE-2026-78957
5.5 MEDIUM

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. …

Aug 25, 2026
CVE-2026-78956
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via …

Aug 25, 2026
CVE-2026-78955
6.5 MEDIUM

Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78954
4.3 MEDIUM

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Aug 25, 2026
CVE-2026-78953
3.1 LOW

Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Aug 25, 2026
CVE-2026-78952
8.3 HIGH

Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process …

Aug 25, 2026
CVE-2026-78951
9.6 CRITICAL

Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-78950
8.8 HIGH

Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-78949
2.9 LOW

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. …

Aug 25, 2026
CVE-2026-78948
9.6 CRITICAL

Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-78947
6.5 MEDIUM

Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted …

Aug 25, 2026
CVE-2026-78946
4.3 MEDIUM

Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78945
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the …

Aug 25, 2026
CVE-2026-78944
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox …

Aug 25, 2026
CVE-2026-78943
3.1 LOW

Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering …

Aug 25, 2026
CVE-2026-78942
4.3 MEDIUM

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium …

Aug 25, 2026
CVE-2026-78941
3.1 LOW

Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Aug 25, 2026
CVE-2026-78940
4.3 MEDIUM

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78939
9.6 CRITICAL

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code …

Aug 25, 2026
CVE-2026-78938
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-78937
9.6 CRITICAL

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary …

Aug 25, 2026
CVE-2026-78936
2.9 LOW

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. …

Aug 25, 2026
CVE-2026-78935
9.6 CRITICAL

Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside …

Aug 25, 2026
CVE-2026-78934
8.3 HIGH

Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via …

Aug 25, 2026
CVE-2026-78915
7.5 HIGH

Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-78914
6.5 MEDIUM

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-78913
8.1 HIGH

Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted …

Aug 25, 2026
CVE-2026-78912
5.4 MEDIUM

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78911
8.3 HIGH

Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Aug 25, 2026
CVE-2026-78910
8.8 HIGH

Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-78909
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-78908
4.3 MEDIUM

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78907
6.5 MEDIUM

Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78906
7.5 HIGH

Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-78905
8.8 HIGH

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-78904
9.6 CRITICAL

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-78903
3.1 LOW

Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Aug 25, 2026
CVE-2026-78901
7.5 HIGH

Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-78900
9.6 CRITICAL

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Aug 25, 2026
CVE-2026-78899
8.8 HIGH

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-78898
5.4 MEDIUM

Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.