Vulnerability index

Browse CVEs

1,003 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.1
CVE-2025-10890

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTM…

Fix: 140.0.7339.207+
Fix from $2,300 2025-09-24
Android CRITICAL 9.8
CVE-2025-36897

In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executi…

Mitigation only
Fix from $2,300 2025-09-04
Android CRITICAL 9.8
CVE-2025-36904

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.

Mitigation only
Fix from $2,300 2025-09-04
Android CRITICAL 9.8
CVE-2025-36890

Elevation of Privilege

No fix yet
Fix from $2,300 2025-09-04
Android CRITICAL 9.8
CVE-2025-36896

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.

Mitigation only
Fix from $2,300 2025-09-04
Android CRITICAL 9.8
CVE-2025-26416

In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote esc…

Mitigation only
Fix from $2,300 2025-09-02
Android CRITICAL 9.8
CVE-2025-22429

In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of pri…

Mitigation only
Fix from $2,300 2025-09-02
Android CRITICAL 9.8
CVE-2025-22435

In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege…

Mitigation only
Fix from $2,300 2025-09-02
Android CRITICAL 9.8
CVE-2025-22408

In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code exec…

Mitigation only
Fix from $2,300 2025-08-26
Android CRITICAL 9.8
CVE-2025-22403

In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remo…

Mitigation only
Fix from $2,300 2025-08-26
Android CRITICAL 9.8
CVE-2025-0074

In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote…

Mitigation only
Fix from $2,300 2025-08-26
Android CRITICAL 9.8
CVE-2025-0075

In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to re…

Mitigation only
Fix from $2,300 2025-08-26
Chrome CRITICAL 9.6
CVE-2025-4609

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to poten…

Fix: 136.0.7103.113+
Fix from $2,300 2025-08-22
Chrome Os CRITICAL 9.8
CVE-2025-6179

Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensi…

Mitigation only
Fix from $2,300 2025-06-16
Chrome CRITICAL 9.8
CVE-2025-4052

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific…

Fix: 136.0.7103.59+
Fix from $2,300 2025-05-05
Application Integration CRITICAL 10.0
CVE-2025-0982

Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via craft…

Fix: after 2025-01-23
Fix from $2,300 2025-02-06
Android CRITICAL 9.8
CVE-2024-49747

In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote …

Mitigation only
Fix from $2,300 2025-01-21
Android CRITICAL 9.8
CVE-2024-49748

In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote …

Mitigation only
Fix from $2,300 2025-01-21
Android CRITICAL 9.8
CVE-2024-53842

In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote c…

Mitigation only
Fix from $2,300 2025-01-03
Android CRITICAL 9.8
CVE-2018-9388

In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer und…

Mitigation only
Fix from $2,300 2024-12-05
Android CRITICAL 9.8
CVE-2018-9430

In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution wi…

Patch available
Fix from $2,300 2024-12-02
Android CRITICAL 9.8
CVE-2018-9418

In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code…

Patch available
Fix from $2,300 2024-12-02
Chrome CRITICAL 9.6
CVE-2024-9369

Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to pe…

Fix: 129.0.6668.89+
Fix from $2,300 2024-11-27
Android CRITICAL 9.8
CVE-2018-9478

In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This…

Patch available
Fix from $2,300 2024-11-20
Android CRITICAL 9.8
CVE-2018-9479

In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This…

Patch available
Fix from $2,300 2024-11-20
Android CRITICAL 9.8
CVE-2018-9467

In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security deci…

Mitigation only
Fix from $2,300 2024-11-20
Android CRITICAL 9.8
CVE-2024-43091

In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution…

Patch available
Fix from $2,300 2024-11-13
Nest Doorbell \(battery\) Firmware CRITICAL 9.8
CVE-2024-44097

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the se…

Fix: 1.73c+
Fix from $2,300 2024-10-02
Chrome CRITICAL 9.6
CVE-2024-7024

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a cr…

Fix: 126.0.6478.54+
Fix from $2,300 2024-09-23
Chrome CRITICAL 9.6
CVE-2024-7971 KEVEPSS 21%

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium …

Fix: 128.0.2739.42 / 128.0.6613.84+
Fix from $2,300 2024-08-21