Every CVE whose affected-product data names Google A2ui/web Core, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (1)
CVE-2026-10032 — CVSS 6.1 (medium): The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A…