Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.3 HIGH
CVE-2026-6311 — Google Chrome Uninitialized Use Sandbox Escape

Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…

chrome | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.3 HIGH
CVE-2026-6310 — Google Chrome Use After Free Sandbox Escape

Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…

chrome | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.3 HIGH
CVE-2026-6309 — Google Chrome Viz Use-After-Free Vulnerability

Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr…

chrome | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
7.5 HIGH
CVE-2026-6308 — Google Chrome Media Out-of-Bounds Read Arbitrary Code Execution

Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page…

chrome | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-6307 — Google Chrome Turbofan Type Confusion Arbitrary Code Execution

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-6306 — Google Chrome PDFium Heap Buffer Overflow

Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)

linux_kernel chrome macos windows | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-6305 — Google Chrome PDFium Heap Buffer Overflow

Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)

chrome | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.3 HIGH
CVE-2026-6304 — Google Chrome Graphite Use-After-Free Vulnerability

Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…

chrome | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-6303 — Google Chrome Codecs Use After Free Vulnerability

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-6302 — Google Chrome Use After Free in Video Sandbox Escape

Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-6301 — Google Chrome Turbofan Type Confusion Arbitrary Code Execution Vulnerability

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-6300 — Google Chrome CSS Use-After-Free Vulnerability

Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-6299 — Google Chrome Prerender Use After Free Arbitrary Code Execution

Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

linux_kernel chrome macos windows | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
4.3 MEDIUM
CVE-2026-6298 — Google Chrome Skia Heap Buffer Overflow Information Disclosure

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secu…

linux_kernel chrome macos windows | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.3 HIGH
CVE-2026-6297 — Google Chrome Proxy Use-After-Free Vulnerability

Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a crafted HTML page. (Chromium securi…

linux_kernel chrome macos windows | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
9.6 CRITICAL
CVE-2026-6296 — Google Chrome ANGLE Heap Buffer Overflow

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

linux_kernel chrome macos windows | Remote | Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
6.1 MEDIUM
CVE-2026-40919 — Gimp: gimp: denial of service via specially crafted seattle filmworks file

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacke…

| Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
5.5 MEDIUM
CVE-2026-40918 — Gimp: gimp: denial of service via crafted pvr image file

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bou…

| Denial of Service
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
5.0 MEDIUM
CVE-2026-40917 — Gimp: gimp: application crashes or information disclosure via crafted icns image files

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious …

| Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
5.0 MEDIUM
CVE-2026-40916 — Gimp: gimp: denial of service due to stack buffer overflow in tim image loader

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM…

| Memory Corruption
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
Showing 20 of 6505 Results