VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,735 CVE recordsPage 486 of 1316 · EPSS data 2026.08.12
ReviewCritical
CVE-2026-14044

Google Chrome, chrome

Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14043

Google Chrome, chrome

Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14041

Google Chrome, chrome

Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14040

Google Chrome, chrome

Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14038

Google Chrome, chrome

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14037

Google Chrome, chrome

Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14036

Google Chrome, chrome

Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14032

Google Chrome, chrome, macos

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14027

Google Chrome, chrome

Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14025

Google Chrome, chrome, macos

Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14024

Google Chrome, chrome, linux kernel

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14018

Google Chrome, chrome, windows

Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14017

Google Chrome, chrome

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14011

Google Chrome, chrome

Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14009

Google Chrome, chrome

Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.