91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,651–1,700 of 91,785 · page 34 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-95375 | CVE-2026-95375 CVSS 6.3google | Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web … |
| CVE-2026-95374 | CVE-2026-95374 CVSS 6.5google | Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chro… |
| CVE-2026-95373 | CVE-2026-95373 CVSS 8.8google | Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the… |
| CVE-2026-95372 | CVE-2026-95372 CVSS 8.3google | Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute … |
| CVE-2026-95371 | CVE-2026-95371 CVSS 5.4google | Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leverag… |
| CVE-2026-95370 | CVE-2026-95370 CVSS 5.4google | Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML p… |
| CVE-2026-9537 | CVE-2026-9537 CVSS 5.3 | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature… |
| CVE-2026-95369 | CVE-2026-95369 CVSS 8.8google | Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox … |
| CVE-2026-95368 | CVE-2026-95368 CVSS 4.3google | Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross… |
| CVE-2026-95367 | CVE-2026-95367 CVSS 5.3google | Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged socia… |
| CVE-2026-95366 | CVE-2026-95366 CVSS 6.5google | Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origi… |
| CVE-2026-95365 | CVE-2026-95365 CVSS 8.8google | Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a cr… |
| CVE-2026-95364 | CVE-2026-95364 CVSS 5.4google | Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromiu… |
| CVE-2026-95363 | CVE-2026-95363 CVSS 5.4google | UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a c… |
| CVE-2026-95362 | CVE-2026-95362 CVSS 8.8google | Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin pol… |
| CVE-2026-95361 | CVE-2026-95361 CVSS 4.3google | Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a c… |
| CVE-2026-95360 | CVE-2026-95360 CVSS 5.3google | Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a… |
| CVE-2026-95359 | CVE-2026-95359 CVSS 3.4google | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read … |
| CVE-2026-95358 | CVE-2026-95358 CVSS 4.4google | Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a pr… |
| CVE-2026-95357 | CVE-2026-95357 CVSS 9.6google | Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sa… |
| CVE-2026-95356 | CVE-2026-95356 CVSS 9.6google | Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary… |
| CVE-2026-95355 | CVE-2026-95355 CVSS 8.3google | Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to p… |
| CVE-2026-95354 | CVE-2026-95354 CVSS 8.3google | Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute ar… |
| CVE-2026-95353 | CVE-2026-95353 CVSS 8.8google | Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pa… |
| CVE-2026-95352 | CVE-2026-95352 CVSS 5.4google | Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy… |
| CVE-2026-95351 | CVE-2026-95351 CVSS 8.3google | Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code ou… |
| CVE-2026-95350 | CVE-2026-95350 CVSS 9.6google | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a cr… |
| CVE-2026-95349 | CVE-2026-95349 CVSS 9.6google | Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sand… |
| CVE-2026-95348 | CVE-2026-95348 CVSS 8.3google | Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute a… |
| CVE-2026-95347 | CVE-2026-95347 CVSS 9.6google | Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted… |
| CVE-2026-95346 | CVE-2026-95346 CVSS 4.8google | UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromiu… |
| CVE-2026-95345 | CVE-2026-95345 CVSS 8.8google | Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.… |
| CVE-2026-95344 | CVE-2026-95344 CVSS 8.0google | Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a craft… |
| CVE-2026-95343 | CVE-2026-95343 CVSS 8.8google | Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pa… |
| CVE-2026-95342 | CVE-2026-95342 CVSS 4.3google | Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium se… |
| CVE-2026-95341 | CVE-2026-95341 CVSS 8.3google | Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially … |
| CVE-2026-95340 | CVE-2026-95340 CVSS 4.3google | Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origi… |
| CVE-2026-9534 | CVE-2026-9534 CVSS 6.3 | A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Hand… |
| CVE-2026-95339 | CVE-2026-95339 CVSS 9.6google | Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted H… |
| CVE-2026-95338 | CVE-2026-95338 CVSS 8.8google | Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file.… |
| CVE-2026-95337 | CVE-2026-95337 CVSS 5.4google | UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially s… |
| CVE-2026-95336 | CVE-2026-95336 CVSS 6.5google | Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive i… |
| CVE-2026-95335 | CVE-2026-95335 CVSS 8.3google | Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitra… |
| CVE-2026-95334 | CVE-2026-95334 CVSS 8.3google | Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pote… |
| CVE-2026-95333 | CVE-2026-95333 CVSS 8.1google | Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network t… |
| CVE-2026-95332 | CVE-2026-95332 CVSS 4.7google | Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a … |
| CVE-2026-95331 | CVE-2026-95331 CVSS 9.6google | Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a … |
| CVE-2026-95330 | CVE-2026-95330 CVSS 6.5google | Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTM… |
| CVE-2026-9533 | CVE-2026-9533 CVSS 6.3 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the comp… |
| CVE-2026-95329 | CVE-2026-95329 CVSS 9.6google | Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the … |