Vulnerability index

Browse CVEs

1,003 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.6
CVE-2026-7333

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…

Fix: 147.0.7727.138+
Fix from $2,300 2026-04-28
Chrome CRITICAL 9.6
CVE-2026-6919

Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially…

Fix: 147.0.7727.116+
Fix from $2,300 2026-04-23
Chrome CRITICAL 9.6
CVE-2026-6920

Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to p…

Fix: 147.0.7727.116+
Fix from $2,300 2026-04-23
Chrome CRITICAL 9.6
CVE-2026-6296

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafte…

Fix: 147.0.7727.101+
Fix from $2,300 2026-04-15
Chrome CRITICAL 9.8
CVE-2026-5902

Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media …

Fix: 147.0.7727.55+
Fix from $2,300 2026-04-08
Chrome CRITICAL 9.6
CVE-2026-5874

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Fix: 147.0.7727.55+
Fix from $2,300 2026-04-08
Chrome CRITICAL 9.6
CVE-2026-5288

Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to p…

Fix: 146.0.7680.177+
Fix from $2,300 2026-04-01
Chrome CRITICAL 9.6
CVE-2026-5289

Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 146.0.7680.177+
Fix from $2,300 2026-04-01
Chrome CRITICAL 9.6
CVE-2026-5290

Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentia…

Fix: 146.0.7680.177+
Fix from $2,300 2026-04-01
Chrome CRITICAL 9.6
CVE-2026-3916

Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a craf…

Fix: 146.0.7680.71+
Fix from $2,300 2026-03-11
Android CRITICAL 9.8
CVE-2026-0116

In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code…

Mitigation only
Fix from $2,300 2026-03-10
Android CRITICAL 9.8
CVE-2026-0120

In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execu…

Mitigation only
Fix from $2,300 2026-03-10
Android CRITICAL 9.8
CVE-2026-0110

In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilege with …

Mitigation only
Fix from $2,300 2026-03-10
Android CRITICAL 9.8
CVE-2026-0111

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalat…

Mitigation only
Fix from $2,300 2026-03-10
Android CRITICAL 9.8
CVE-2026-0113

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalat…

Mitigation only
Fix from $2,300 2026-03-10
Android CRITICAL 9.8
CVE-2026-0114

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execu…

Mitigation only
Fix from $2,300 2026-03-10
Chrome CRITICAL 9.6
CVE-2026-3545

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape…

Fix: 145.0.7632.159 / 145.0.7632.160+
Fix from $2,300 2026-03-04
Cloud Build CRITICAL 9.8
CVE-2026-3136

An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execut…

Fix: 2026-1-26+
Fix from $2,300 2026-03-03
Android CRITICAL 9.8
CVE-2026-0006

In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with …

Mitigation only
Fix from $2,300 2026-03-02
Android CRITICAL 9.1
CVE-2025-48609

In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities d…

Mitigation only
Fix from $2,300 2026-03-02
Chrome CRITICAL 9.8
CVE-2026-3062

Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access…

Fix: 145.0.7632.116 / 145.0.7632.117+
Fix from $2,300 2026-02-23
Chrome CRITICAL 9.1
CVE-2026-3061

Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted …

Fix: 145.0.7632.116 / 145.0.7632.117+
Fix from $2,300 2026-02-23
Android CRITICAL 9.3
CVE-2026-0106

In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege …

Mitigation only
Fix from $2,300 2026-02-05
Matter CRITICAL 9.8
CVE-2026-20418

In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additiona…

Fix: after 1.4
Fix from $2,300 2026-02-02
Chrome CRITICAL 9.8
CVE-2026-0906

Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) vi…

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $2,300 2026-01-20
Chrome CRITICAL 9.8
CVE-2026-0907EPSS 8%

Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page.…

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $2,300 2026-01-20
Chrome CRITICAL 9.8
CVE-2026-0905

Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially o…

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $2,300 2026-01-20
Android CRITICAL 9.8
CVE-2025-36937

In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead …

Mitigation only
Fix from $2,300 2025-12-11
Android CRITICAL 9.8
CVE-2025-48626

In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to r…

Patch available
Fix from $2,300 2025-12-08
Chrome CRITICAL 9.8
CVE-2025-10585 KEVEPSS 5%

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 140.0.7339.185+
Fix from $2,300 2025-09-24