Vulnerability index

Browse CVEs

150 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2026-11204 Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11190 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious ex… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11193 Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11197 Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.3 CVE-2026-11187 Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafte… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 8.8 CVE-2026-11179 Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass site isolation via a crafted HTML pag… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 MEDIUM 6.5 CVE-2026-11135 Insufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11078 Inappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11026 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious ex… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11017 Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proce… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 7.8 CVE-2025-22426 In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to lo… Android Mitigation only Fix from $1,9502026-06-01 MEDIUM 5.5 CVE-2026-8586 Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control v… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 MEDIUM 6.5 CVE-2026-5881 Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted… Chrome 147.0.7727.55+ Fix from $1,6002026-04-08 HIGH 8.8 CVE-2026-5863 Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 147.0.7727.55+ Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2026-3934 Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass same origin policy via a … Chrome 146.0.7680.71+ Fix from $1,6002026-03-11 MEDIUM 5.3 CVE-2026-3939 Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a craf… Chrome 146.0.7680.71+ Fix from $1,6002026-03-11 MEDIUM 5.3 CVE-2026-3940 Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a… Chrome 146.0.7680.71+ Fix from $1,6002026-03-11 HIGH 7.5 CVE-2026-3932 Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions… Chrome 146.0.7680.71+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-3541 Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a … Chrome 145.0.7632.159 / 145.0.7632.160+ Fix from $1,9502026-03-04 HIGH 8.8 CVE-2026-3542 Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access… Chrome 145.0.7632.159 / 145.0.7632.160+ Fix from $1,9502026-03-04 HIGH 8.8 CVE-2026-3543 Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory acc… Chrome 145.0.7632.159 / 145.0.7632.160+ Fix from $1,9502026-03-04 MEDIUM 6.2 CVE-2026-0012 In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to… Android Mitigation only Fix from $1,6002026-03-02 HIGH 8.4 CVE-2025-48619 In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate files due to a logic error in the… Android Mitigation only Fix from $1,9502026-03-02 HIGH 8.8 CVE-2025-10201 Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site is… Chrome 140.0.7339.127+ Fix from $1,9502025-09-10 MEDIUM 5.3 CVE-2025-36909 Information disclosure Android No fix yet Fix from $1,6002025-09-04 MEDIUM 6.3 CVE-2025-4051 Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific… Chrome 136.0.7103.59+ Fix from $1,6002025-05-05 HIGH 8.8 CVE-2025-1568 Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit acc… Chrome Os Mitigation only Fix from $1,9502025-04-16 HIGH 7.0 CVE-2024-34725 In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalat… Android Mitigation only Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31320 In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM… Android Patch available Fix from $1,9502024-07-09 MEDIUM 6.5 CVE-2024-5840 Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML pag… Chrome 126.0.6478.54+ Fix from $1,6002024-06-11