Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2025-12664 — Improper Validation of Specified Quantity in Input in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause de…

gitlab | Remote | Denial of Service
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
6.5 MEDIUM
CVE-2026-5919 — Google Chrome WebSockets Origin Bypass

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a …

chrome | Remote | Misconfiguration
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
4.3 MEDIUM
CVE-2026-5918 — Google Chrome Navigation Cross-Origin Data Leak Vulnerability

Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page…

chrome | Remote | Information Disclosure
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
8.1 HIGH
CVE-2026-5915 — Google Chrome WebML Out-of-Bounds Memory Write Vulnerability

Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium secur…

chrome | Remote | Memory Corruption
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
8.8 HIGH
CVE-2026-5914 — Google Chrome Type Confusion Heap Corruption Vulnerability

Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Ext…

chrome | Remote | Memory Corruption
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
0.0 NA
CVE-2026-5913 — Google Chrome Blink Out-of-Bounds Read Vulnerability

Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)

chrome | Memory Corruption
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
8.8 HIGH
CVE-2026-5912 — Google Chrome WebRTC Integer Overflow

Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)

chrome | Remote | Memory Corruption
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
4.3 MEDIUM
CVE-2026-5911 — Google Chrome Policy Bypass Vulnerability

Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

chrome | Remote | Misconfiguration
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
8.8 HIGH
CVE-2026-5910 — Google Chrome Media Integer Overflow Vulnerability

Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)

chrome | Remote | Memory Corruption
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
8.8 HIGH
CVE-2026-5909 — Google Chrome Media Integer Overflow Vulnerability

Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)

chrome | Remote | Memory Corruption
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
8.8 HIGH
CVE-2026-5908 — Google Chrome Media Integer Overflow

Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)

chrome | Remote | Memory Corruption
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
8.1 HIGH
CVE-2026-5907 — Google Chrome Media Out-of-Bounds Memory Read Vulnerability

Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: …

chrome | Remote | Memory Corruption
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
4.3 MEDIUM
CVE-2026-5906 — Google Chrome Android Spoofing Vulnerability

Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium securit…

chrome | Remote | Misconfiguration
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
6.5 MEDIUM
CVE-2026-5905 — Google Chrome Domain Spoofing Vulnerability

Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

chrome | Remote | Information Disclosure
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
0.0 NA
CVE-2026-5904 — Google Chrome V8 Use-After-Free Vulnerability

Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Exte…

chrome | Memory Corruption
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
0.0 NA
CVE-2026-5903 — Google Chrome IFrameSandbox Policy Bypass

Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted…

chrome | Misconfiguration
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
0.0 NA
CVE-2026-5902 — Google Chrome Android Media Stream Metadata Corruption

Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium…

chrome | Race Condition
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
0.0 NA
CVE-2026-5901 — Google Chrome DevTools Extension Cookie Modification Bypass

Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions fo…

chrome | Misconfiguration
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
0.0 NA
CVE-2026-5900 — Google Chrome Policy Bypass Vulnerability

Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low)

chrome | Authorization
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
0.0 NA
CVE-2026-5899 — Google Chrome UXSS History Navigation Vulnerability

Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scri…

chrome | Cross-Site Scripting
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
Showing 20 of 6448 Results