NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3051 5.3 MEDIUM
Network
- - On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgo… CWE-284
Improper Access Control
CVE-2024-27891 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3052 9.6 CRITICAL
Network
- - Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the swi… CWE-306
Missing Authentication for Critical Function
CVE-2024-27892 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3053 7.5 HIGH
Network
- - On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, a… CWE-1286
 Improper Validation of Syntactic Correctness of Input
CVE-2025-8873 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3054 8.1 HIGH
Network
- - Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) CWE-416
 Use After Free
CVE-2026-10887 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3055 8.8 HIGH
Adjacent
- - Use after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security s… CWE-416
 Use After Free
CVE-2026-10888 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3056 8.3 HIGH
Network
- - Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.… CWE-125
Out-of-bounds Read
CVE-2026-10889 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3057 8.8 HIGH
Adjacent
- - Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium securit… CWE-416
 Use After Free
CVE-2026-10890 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3058 8.8 HIGH
Network
- - Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CWE-416
 Use After Free
CVE-2026-10891 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3059 8.3 HIGH
Network
- - Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT… CWE-416
 Use After Free
CVE-2026-10894 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3060 8.8 HIGH
Network
- - Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CWE-416
 Use After Free
CVE-2026-10895 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3061 8.8 HIGH
Network
- - Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CWE-416
 Use After Free
CVE-2026-10896 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3062 8.3 HIGH
Network
- - Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page… CWE-121
Stack-based Buffer Overflow
CVE-2026-10898 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3063 7.5 HIGH
Network
- - Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a … CWE-416
 Use After Free
CVE-2026-10899 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3064 7.5 HIGH
Network
- - Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via … CWE-416
 Use After Free
CVE-2026-10900 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3065 7.5 HIGH
Network
- - Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTM… CWE-416
 Use After Free
CVE-2026-10901 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3066 8.8 HIGH
Network
- - Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CWE-416
 Use After Free
CVE-2026-10902 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3067 8.8 HIGH
Network
- - Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-416
 Use After Free
CVE-2026-10903 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3068 8.3 HIGH
Network
- - Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (… CWE-416
 Use After Free
CVE-2026-10905 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3069 7.5 HIGH
Network
- - Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via… CWE-416
 Use After Free
CVE-2026-10906 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3070 8.8 HIGH
Network
- - Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-787
 Out-of-bounds Write
CVE-2026-10907 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3071 8.3 HIGH
Network
- - Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte… CWE-416
 Use After Free
CVE-2026-10908 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3072 8.3 HIGH
Network
- - Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr… CWE-416
 Use After Free
CVE-2026-10909 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3073 8.8 HIGH
Network
- - Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CWE-843
Type Confusion
CVE-2026-10910 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3074 8.3 HIGH
Network
- - Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape … CWE-20
 Improper Input Validation 
CVE-2026-10911 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3075 8.8 HIGH
Network
- - Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H… CWE-416
 Use After Free
CVE-2026-10913 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3076 8.8 HIGH
Network
- - Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H… CWE-416
 Use After Free
CVE-2026-10914 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3077 8.3 HIGH
Network
- - Use after free in Core in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag… CWE-416
 Use After Free
CVE-2026-10915 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3078 8.8 HIGH
Network
- - Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CWE-94
Code Injection
CVE-2026-10928 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3079 8.3 HIGH
Network
- - Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craft… CWE-122
Heap-based Buffer Overflow
CVE-2026-10929 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3080 - -
- - Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) CWE-125
Out-of-bounds Read
CVE-2026-10930 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3081 - -
- - Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CWE-416
 Use After Free
CVE-2026-10931 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3082 8.8 HIGH
Network
- - Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CWE-416
 Use After Free
CVE-2026-10932 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3083 8.3 HIGH
Network
- - Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM… CWE-416
 Use After Free
CVE-2026-10933 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3084 8.3 HIGH
Network
- - Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted … CWE-416
 Use After Free
CVE-2026-10934 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3085 - -
- - Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) - CVE-2026-10937 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3086 - -
- - Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chr… CWE-20
 Improper Input Validation 
CVE-2026-10938 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3087 - -
- - Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securi… CWE-20
 Improper Input Validation 
CVE-2026-10974 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3088 - -
- - Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security… CWE-457
 Use of Uninitialized Variable
CVE-2026-10976 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3089 - -
- - Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium secur… CWE-457
 Use of Uninitialized Variable
CVE-2026-10977 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3090 - -
- - Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium securi… CWE-125
Out-of-bounds Read
CVE-2026-10979 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3091 - -
- - Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a cr… CWE-20
 Improper Input Validation 
CVE-2026-10980 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3092 8.8 HIGH
Network
- - Use after free in Fonts in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Med… CWE-416
 Use After Free
CVE-2026-11000 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3093 8.8 HIGH
Network
- - Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium) CWE-416
 Use After Free
CVE-2026-11117 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3094 8.8 HIGH
Network
- - Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CWE-416
 Use After Free
CVE-2026-11118 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3095 8.8 HIGH
Network
- - Use after free in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CWE-416
 Use After Free
CVE-2026-11125 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3096 8.8 HIGH
Network
- - Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CWE-416
 Use After Free
CVE-2026-11130 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3097 8.8 HIGH
Network
- - Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CWE-416
 Use After Free
CVE-2026-11136 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3098 8.8 HIGH
Network
- - Use after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: M… CWE-416
 Use After Free
CVE-2026-11147 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3099 7.5 HIGH
Network
- - Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via… CWE-20
 Improper Input Validation 
CVE-2026-11149 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm
3100 8.8 HIGH
Network
- - Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CWE-416
 Use After Free
CVE-2026-11164 2026-06-6 00:02 2026-06-5 Show GitHub Exploit DB Packet Storm