boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Google

Vendor reference — Google · sector: Operating Systems & Platforms. Cumulative disclosure record across the archive.

Follow Google — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs18921824
KEV entries746
Rate & severity
KEV/100Med CVSSMed EPSSCHML
3.97.5.002422475578657

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▄▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-091
2025-100
2025-111
2025-121
2026-010
2026-021
2026-034
2026-041
2026-05168
2026-061090
2026-07496
2026-0864

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2023-4863100.0YES2023-09-13
CVE-2018-1746399.7YES2022-06-08
CVE-2020-641899.6YES2021-11-03
CVE-2022-22948.899.3HIGHYES2022-08-25
CVE-2021-2122099.3YES2021-11-03
CVE-2021-3055199.2YES2021-11-03
CVE-2021-3063299.2YES2021-11-03
CVE-2019-578699.1YES2022-05-23
CVE-2018-606599.1YES2022-06-08
CVE-2021-2122499.0YES2021-11-03
CVE-2019-582599.0YES2022-06-08
CVE-2019-1372098.8YES2022-05-23
CVE-2023-521798.8YES2023-10-02
CVE-2020-1600998.8YES2021-11-03
CVE-2016-164698.8YES2022-06-08

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-760478.832.1HIGH2026-08-18
CVE-2026-760458.825.6HIGH2026-08-18
CVE-2026-760414.329.7MEDIUM2026-08-18
CVE-2026-760438.832.1HIGH2026-08-18
CVE-2026-760468.329.2HIGH2026-08-18
CVE-2026-760448.326.2HIGH2026-08-18
CVE-2026-760408.836.1HIGH2026-08-18
CVE-2026-760396.536.1MEDIUM2026-08-18
CVE-2026-760378.411.8HIGH2026-08-18
CVE-2026-760359.629.4CRITICAL2026-08-18
CVE-2026-760423.130.8LOW2026-08-18
CVE-2026-760369.634.7CRITICAL2026-08-18
CVE-2026-760348.834.7HIGH2026-08-18
CVE-2026-760334.228.5MEDIUM2026-08-18
CVE-2026-760388.832.8HIGH2026-08-18

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Chrome16823
Android1201
Chromium V83838
Chromium66
MCP Toolbox For Databases (googleapis/mcp-toolbox)60
Mcp-toolbox50
Chromium Blink22
Chromium Intents22
Chromium Mojo22
Chromium Skia22
MCP Toolbox For Databases20

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-116452026-06-098.881.0HIGH
CVE-2025-485952026-06-028.475.6HIGH
CVE-2026-52812026-04-018.891.5HIGH
CVE-2026-39092026-03-1374.3
CVE-2026-39102026-03-1379.1
CVE-2026-24412026-02-1797.5
CVE-2025-141742025-12-1297.5
CVE-2025-132232025-11-1991.6
CVE-2025-105852025-09-2392.1
CVE-2025-65582025-07-2294.9
CVE-2025-65542025-07-0295.9
CVE-2025-54192025-06-0594.1
CVE-2025-27832025-03-2794.5
CVE-2024-79652024-08-2897.0
CVE-2024-79712024-08-2697.3
CVE-2024-52742024-05-2894.0
CVE-2024-49472024-05-2096.5
CVE-2024-47612024-05-1695.5
CVE-2024-46712024-05-1394.5
CVE-2023-47622024-02-0698.5
CVE-2024-05192024-01-1789.1
CVE-2023-70242024-01-0293.9
CVE-2023-63452023-11-3096.7
CVE-2023-52172023-10-0298.8
CVE-2023-48632023-09-13100.0

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2020-159992021-11-171736
CVE-2021-211662021-11-171736
CVE-2021-379762021-11-171736
CVE-2021-306322021-11-171736
CVE-2021-306332021-11-171736
CVE-2021-211482021-11-171736
CVE-2021-379732021-11-171736
CVE-2021-305512021-11-171736
CVE-2021-379752021-11-171736
CVE-2021-305542021-11-171736

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.