VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,735 CVE recordsPage 487 of 1316 · EPSS data 2026.08.12
ReviewHigh
CVE-2026-14006

Google Chrome, chrome

Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14005

Google Chrome, chrome, android

Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13974

Google Chrome, chrome, macos

Integer overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13968

Google Chrome, chrome

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13967

Google Chrome, chrome

Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13965

Google Chrome, chrome

Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13951

Google Chrome, chrome

Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13938

Google Chrome, chrome

Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13934

Google Chrome, chrome

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13928

Google Chrome, chrome

Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13927

Google Chrome, chrome, android

Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13925

Google Chrome, chrome, windows

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13920

Google Chrome, chrome, windows

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13918

Google Chrome, chrome, iphone os

Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13915

Google Chrome, chrome, iphone os

Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.