91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,651–1,700 of 91,785 · page 34 of 1836

IDTitleSummary
CVE-2026-95375CVE-2026-95375
CVSS 6.3google
Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web …
CVE-2026-95374CVE-2026-95374
CVSS 6.5google
Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chro…
CVE-2026-95373CVE-2026-95373
CVSS 8.8google
Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the…
CVE-2026-95372CVE-2026-95372
CVSS 8.3google
Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute …
CVE-2026-95371CVE-2026-95371
CVSS 5.4google
Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leverag…
CVE-2026-95370CVE-2026-95370
CVSS 5.4google
Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML p…
CVE-2026-9537CVE-2026-9537
CVSS 5.3
Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature…
CVE-2026-95369CVE-2026-95369
CVSS 8.8google
Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox …
CVE-2026-95368CVE-2026-95368
CVSS 4.3google
Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross…
CVE-2026-95367CVE-2026-95367
CVSS 5.3google
Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged socia…
CVE-2026-95366CVE-2026-95366
CVSS 6.5google
Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origi…
CVE-2026-95365CVE-2026-95365
CVSS 8.8google
Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a cr…
CVE-2026-95364CVE-2026-95364
CVSS 5.4google
Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromiu…
CVE-2026-95363CVE-2026-95363
CVSS 5.4google
UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a c…
CVE-2026-95362CVE-2026-95362
CVSS 8.8google
Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin pol…
CVE-2026-95361CVE-2026-95361
CVSS 4.3google
Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a c…
CVE-2026-95360CVE-2026-95360
CVSS 5.3google
Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a…
CVE-2026-95359CVE-2026-95359
CVSS 3.4google
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read …
CVE-2026-95358CVE-2026-95358
CVSS 4.4google
Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a pr…
CVE-2026-95357CVE-2026-95357
CVSS 9.6google
Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sa…
CVE-2026-95356CVE-2026-95356
CVSS 9.6google
Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary…
CVE-2026-95355CVE-2026-95355
CVSS 8.3google
Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to p…
CVE-2026-95354CVE-2026-95354
CVSS 8.3google
Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute ar…
CVE-2026-95353CVE-2026-95353
CVSS 8.8google
Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pa…
CVE-2026-95352CVE-2026-95352
CVSS 5.4google
Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy…
CVE-2026-95351CVE-2026-95351
CVSS 8.3google
Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code ou…
CVE-2026-95350CVE-2026-95350
CVSS 9.6google
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a cr…
CVE-2026-95349CVE-2026-95349
CVSS 9.6google
Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sand…
CVE-2026-95348CVE-2026-95348
CVSS 8.3google
Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute a…
CVE-2026-95347CVE-2026-95347
CVSS 9.6google
Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted…
CVE-2026-95346CVE-2026-95346
CVSS 4.8google
UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromiu…
CVE-2026-95345CVE-2026-95345
CVSS 8.8google
Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.…
CVE-2026-95344CVE-2026-95344
CVSS 8.0google
Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a craft…
CVE-2026-95343CVE-2026-95343
CVSS 8.8google
Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pa…
CVE-2026-95342CVE-2026-95342
CVSS 4.3google
Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium se…
CVE-2026-95341CVE-2026-95341
CVSS 8.3google
Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially …
CVE-2026-95340CVE-2026-95340
CVSS 4.3google
Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origi…
CVE-2026-9534CVE-2026-9534
CVSS 6.3
A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Hand…
CVE-2026-95339CVE-2026-95339
CVSS 9.6google
Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted H…
CVE-2026-95338CVE-2026-95338
CVSS 8.8google
Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file.…
CVE-2026-95337CVE-2026-95337
CVSS 5.4google
UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially s…
CVE-2026-95336CVE-2026-95336
CVSS 6.5google
Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive i…
CVE-2026-95335CVE-2026-95335
CVSS 8.3google
Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitra…
CVE-2026-95334CVE-2026-95334
CVSS 8.3google
Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pote…
CVE-2026-95333CVE-2026-95333
CVSS 8.1google
Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network t…
CVE-2026-95332CVE-2026-95332
CVSS 4.7google
Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a …
CVE-2026-95331CVE-2026-95331
CVSS 9.6google
Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …
CVE-2026-95330CVE-2026-95330
CVSS 6.5google
Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTM…
CVE-2026-9533CVE-2026-9533
CVSS 6.3
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the comp…
CVE-2026-95329CVE-2026-95329
CVSS 9.6google
Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.