Skip to main content

CWE archive

CWE-346 CVEs

Programmatic archive

663 CVEs tagged with CWE-34664 Critical, 220 High, 357 Medium, 21 Low, 1 Unrated.

CVE-2026-17895

Published Jul 30, 2026

Inappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17889

Published Jul 30, 2026

Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17885

Published Jul 30, 2026

Inappropriate implementation in Paint in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security sever…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17880

Published Jul 30, 2026

Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security se…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17879

Published Jul 30, 2026

Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security se…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17876

Published Jul 30, 2026

Inappropriate implementation in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security se…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17871

Published Jul 30, 2026

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-or…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17859

Published Jul 30, 2026

Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security se…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17858

Published Jul 30, 2026

Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security sever…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17857

Published Jul 30, 2026

Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security sev…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17802

Published Jul 30, 2026

Side-channel information leakage in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium s…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17798

Published Jul 30, 2026

Inappropriate implementation in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severi…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17795

Published Jul 30, 2026

Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data v…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17788

Published Jul 30, 2026

Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security sever…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17785

Published Jul 30, 2026

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17783

Published Jul 30, 2026

Inappropriate implementation in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security seve…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17777

Published Jul 30, 2026

Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security se…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17775

Published Jul 30, 2026

Inappropriate implementation in PresentationAPI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium secu…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17773

Published Jul 30, 2026

Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium s…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17771

Published Jul 30, 2026

Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17769

Published Jul 30, 2026

Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium s…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17767

Published Jul 30, 2026

Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17765

Published Jul 30, 2026

Inappropriate implementation in WebProtect in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17763

Published Jul 30, 2026

Inappropriate implementation in GPU in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a craf…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17762

Published Jul 30, 2026

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromiu…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Showing 1-25 of 663 CVEsPage 1 of 27