Security Risk Category

Browser Security Risks — Page 5

Published vulnerability pages connected to Browser. Each page keeps one canonical URL and focused remediation guidance.

215 published Browser risks

Browser risks

Showing 145–180 of 215 published risks.

highEPSS 0.005

CVE-2026-57988 edge chromium vulnerability

Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57988browsermicrosoftpath-traversal

Updated Jul 14, 2026

highEPSS 0.007

CVE-2026-57991 edge chromium vulnerability

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVE-2026-57991browsermicrosoftpath-traversal

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57992 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57992browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-57993 edge chromium vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-57993browsermicrosoftssrf

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58276 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58276browsermicrosoftmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.003

CVE-2026-58278 edge chromium vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58278browsermicrosoftssrf

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58282 edge chromium vulnerability

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58282browsermicrosoftauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58283 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58283browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58284 edge chromium vulnerability

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58284browsermicrosoftauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58285 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58285browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58286 edge chromium vulnerability

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58286browsermicrosoftauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58287 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58287browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58288 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58288browsermicrosoftmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.004

CVE-2026-58289 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58289browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-58290 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58290browsermicrosoftmemory-corruption

Updated Jul 13, 2026

mediumEPSS 0.006

CVE-2026-58291 edge chromium vulnerability

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVE-2026-58291browsermicrosoft

Updated Jul 13, 2026

highEPSS 0.003

CVE-2026-58292 edge chromium vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58292browsermicrosoftinput-validation

Updated Jul 13, 2026

highEPSS 0.004

CVE-2026-58293 edge chromium vulnerability

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58293browsermicrosoftpath-traversal

Updated Jul 13, 2026

highEPSS 0.003

CVE-2026-58294 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58294browsermicrosoftmemory-corruption

Updated Jul 13, 2026

highEPSS 0.004

CVE-2026-58295 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-58295browsermicrosoftmemory-corruption

Updated Jul 13, 2026

highEPSS 0.003

CVE-2026-58296 edge chromium vulnerability

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

CVE-2026-58296browsermicrosoft

Updated Jul 13, 2026

highEPSS 0.003

CVE-2026-58297 edge chromium vulnerability

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

CVE-2026-58297browsermicrosoft

Updated Jul 13, 2026

highEPSS 0.002

CVE-2026-58298 edge chromium vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58298browsermicrosoftxss

Updated Jul 13, 2026

highEPSS 0.003

CVE-2026-58299 edge chromium vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

CVE-2026-58299browsermicrosoftrace-condition

Updated Jul 13, 2026

mediumEPSS 0.003

CVE-2026-58300 edge chromium vulnerability

Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

CVE-2026-58300browsermicrosoftpath-traversal

Updated Jul 13, 2026

mediumEPSS 0.003

CVE-2026-58522 edge chromium vulnerability

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

CVE-2026-58522browsermicrosoftpath-traversal

Updated Jul 13, 2026

mediumEPSS 0.002

CVE-2026-58524 edge chromium vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58524browsermicrosoftxss

Updated Jul 13, 2026

mediumEPSS 0.004

CVE-2026-58597 edge chromium vulnerability

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58597browsermicrosoft

Updated Jul 13, 2026

mediumEPSS 0.005

CVE-2026-58523 edge chromium vulnerability

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-58523browsermicrosoftauthorization-bypass

Updated Jul 13, 2026

medium

CVE-2025-8591 api control plane vulnerability

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.

CVE-2025-8591browserapi-securityxss

Updated Jul 13, 2026

mediumEPSS 0.001

CVE-2026-40257 op-tee vulnerability

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error that can cause a massive heap overflow that corrupts all TEE kernel memory following the hash state. This affects all platforms built with `CFG_CRYPTO_WITH_CE82=y` (ARMv8.2+ with SHA3 Crypto Extensions). Version 4.11.0 contains a patch. As a workaround, disable SHA3 Crypto Extensions with `CFG_CRYPTO_WITH_CE82=n`.

CVE-2026-40257browserlinux

Updated Jul 13, 2026

criticalEPSS 0.005

CVE-2026-57571 crawl4ai vulnerability

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the downloads directory, giving an arbitrary file write with attacker-controlled contents; the HTTP crawler path uses the response Content-Disposition filename and the browser crawler path uses the download's suggested filename. Because the written bytes are attacker-controlled, this can escalate to remote code execution. This issue is fixed in version 0.9.0.

CVE-2026-57571browserremote-code-executionpath-traversalfile-write

Updated Jul 13, 2026

criticalEPSS 0.005

CVE-2026-57572 crawl4ai vulnerability

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's runtime user. The Docker API is unauthenticated by default, so a single request yields arbitrary command execution. This issue is fixed in version 0.9.0.

CVE-2026-57572browserapi-securityremote-code-execution

Updated Jul 13, 2026

medium

CVE-2026-13356 Firefox for iOS vulnerability

A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.

CVE-2026-13356browser

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-55430 coder vulnerability

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `fetch()` calls. Practical exploitation requires subdomain app routing (wildcard hostname) enabled, a victim who visits the attacker's shared app and a deployment whose upstream proxy does not strip `X-Forwarded-Host`. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 trusts `X-Forwarded-Host` only from configured trusted proxies and otherwise resolves the routing host from the verified request host. As a workaround, place an upstream reverse proxy that strips or overwrites `X-Forwarded-Host` on untrusted requests.

CVE-2026-55430browserapi-securitydevopscryptography

Updated Jul 12, 2026

mediumEPSS 0.001

CVE-2026-56359 n8n vulnerability

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authorization button, executing arbitrary scripts in their browser session with the victim's privileges.

CVE-2026-56359npmbrowserxss

Updated Jul 11, 2026