CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-79014
4.3 MEDIUM

Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Aug 25, 2026
CVE-2026-79013
5.9 MEDIUM

Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security …

Aug 25, 2026
CVE-2026-79010
4.3 MEDIUM

Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer …

Aug 25, 2026
CVE-2026-79009
4.3 MEDIUM

UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Aug 25, 2026
CVE-2026-79006
4.3 MEDIUM

Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium …

Aug 25, 2026
CVE-2026-79005
6.5 MEDIUM

Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Aug 25, 2026
CVE-2026-79003
4.3 MEDIUM

Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Aug 25, 2026
CVE-2026-79001
5.3 MEDIUM

Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged …

Aug 25, 2026
CVE-2026-79000
4.3 MEDIUM

Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted …

Aug 25, 2026
CVE-2026-78991
5.3 MEDIUM

Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via …

Aug 25, 2026
CVE-2026-78987
4.3 MEDIUM

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78981
6.5 MEDIUM

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local …

Aug 25, 2026
CVE-2026-78980
4.3 MEDIUM

Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a …

Aug 25, 2026
CVE-2026-78979
4.3 MEDIUM

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy …

Aug 25, 2026
CVE-2026-78977
6.5 MEDIUM

Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via …

Aug 25, 2026
CVE-2026-78976
4.3 MEDIUM

Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin …

Aug 25, 2026
CVE-2026-78975
6.5 MEDIUM

Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78974
5.4 MEDIUM

UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via …

Aug 25, 2026
CVE-2026-78969
6.5 MEDIUM

Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. …

Aug 25, 2026
CVE-2026-78968
6.5 MEDIUM

Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially spoof address bar …

Aug 25, 2026
CVE-2026-78967
6.5 MEDIUM

Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions …

Aug 25, 2026
CVE-2026-78966
4.3 MEDIUM

Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. …

Aug 25, 2026
CVE-2026-78965
4.3 MEDIUM

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78962
4.3 MEDIUM

Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted …

Aug 25, 2026
CVE-2026-78961
4.3 MEDIUM

Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Aug 25, 2026
CVE-2026-78960
6.5 MEDIUM

Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome …

Aug 25, 2026
CVE-2026-78959
6.5 MEDIUM

Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions …

Aug 25, 2026
CVE-2026-78957
5.5 MEDIUM

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. …

Aug 25, 2026
CVE-2026-78955
6.5 MEDIUM

Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78954
4.3 MEDIUM

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Aug 25, 2026
CVE-2026-78947
6.5 MEDIUM

Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted …

Aug 25, 2026
CVE-2026-78946
4.3 MEDIUM

Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78942
4.3 MEDIUM

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium …

Aug 25, 2026
CVE-2026-78940
4.3 MEDIUM

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78914
6.5 MEDIUM

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML …

Aug 25, 2026
CVE-2026-78912
5.4 MEDIUM

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78908
4.3 MEDIUM

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78907
6.5 MEDIUM

Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78898
5.4 MEDIUM

Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted …

Aug 25, 2026
CVE-2026-78897
6.5 MEDIUM

Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome …

Aug 25, 2026
CVE-2026-78896
4.3 MEDIUM

Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-78895
4.3 MEDIUM

Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium …

Aug 25, 2026
CVE-2026-78893
6.5 MEDIUM

Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security …

Aug 25, 2026
CVE-2026-77680
5.3 MEDIUM

An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated …

Aug 25, 2026
CVE-2026-75421
4.0 MEDIUM

aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.

Aug 25, 2026
CVE-2026-65088
5.5 MEDIUM

NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead …

Aug 25, 2026
CVE-2026-65087
5.6 MEDIUM

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure …

Aug 25, 2026
CVE-2026-65086
6.8 MEDIUM

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of …

Aug 25, 2026
CVE-2026-65085
5.2 MEDIUM

NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful …

Aug 25, 2026
CVE-2026-55588
6.5 MEDIUM

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.