CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-2783HIGH | Google Chromium Mojo Sandbox Escape VulnerabilityIncorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High) Mar 26, 2025 | CVSS8.3v3.1 | EPSS8.4% | PoCs5 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3075CRITICAL | Google Chromium Mojo Insufficient Data Validation VulnerabilityInsufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. CWE-20Sep 26, 2022 | CVSS9.6v3.1 | EPSS5.68% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |