Vulnerabilities

Summary — last 7 days

New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
–

6,757 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.6)0.24%—Mcp-chrome-bridgeAI9/29/20269/30/2026
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content…
AnalyzedCritical (9.6)0.40%—Google Chrome9/29/20269/30/2026
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
AnalyzedMedium (6.5)0.22%—Google Chrome9/29/20269/30/2026
Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
AnalyzedMedium (6.1)0.24%—Google Chrome9/29/20269/30/2026
Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (8.8)0.30%—Google Chrome9/29/20269/30/2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (7.5)0.27%—Google Chrome9/29/20269/30/2026
Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
AnalyzedHigh (8.8)0.30%—Google Chrome9/29/20269/30/2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedMedium (4.3)0.21%—Google Chrome9/29/20269/30/2026
Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (8.3)0.26%—Google Chrome9/29/20269/30/2026
Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (8.8)0.36%—Google Chrome9/29/20269/30/2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (8.8)0.30%—Google Chrome9/29/20269/30/2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedMedium (6.5)0.22%—Google Chrome9/29/20269/30/2026
Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
AnalyzedLow (3.4)0.20%—Google Chrome9/29/20269/30/2026
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedMedium (4.7)0.19%—Google Chrome9/29/20269/30/2026
Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (8.6)0.09%—Google Chrome9/29/20269/30/2026
Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
AnalyzedCritical (9.6)0.27%—Google Chrome9/29/20269/30/2026
Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedLow (3.4)0.20%—Google Chrome9/29/20269/30/2026
Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedMedium (5.4)0.18%—Google Chrome9/29/20269/30/2026
UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
AnalyzedMedium (4.7)0.24%—Google Chrome9/29/20269/30/2026
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedMedium (4.3)0.22%—Google Chrome9/29/20269/30/2026
UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)
AnalyzedLow (3.4)0.24%—Google Chrome9/29/20269/30/2026
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedMedium (6.5)0.22%—Google Chrome9/29/20269/30/2026
Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
AnalyzedCritical (9.6)0.27%—Google Chrome9/29/20269/30/2026
Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedCritical (9.6)0.27%—Google Chrome9/29/20269/30/2026
Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedMedium (4.7)0.24%—Google Chrome9/29/20269/30/2026
Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)