Vulnerability index

Browse CVEs

1,003 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-10890 Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTM… Chrome 140.0.7339.207+ Fix from $2,3002025-09-24 CRITICAL 9.8 CVE-2025-36897 In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executi… Android Mitigation only Fix from $2,3002025-09-04 CRITICAL 9.8 CVE-2025-36904 WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384. Android Mitigation only Fix from $2,3002025-09-04 CRITICAL 9.8 CVE-2025-36890 Elevation of Privilege Android No fix yet Fix from $2,3002025-09-04 CRITICAL 9.8 CVE-2025-36896 WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106. Android Mitigation only Fix from $2,3002025-09-04 CRITICAL 9.8 CVE-2025-26416 In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote esc… Android Mitigation only Fix from $2,3002025-09-02 CRITICAL 9.8 CVE-2025-22429 In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of pri… Android Mitigation only Fix from $2,3002025-09-02 CRITICAL 9.8 CVE-2025-22435 In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege… Android Mitigation only Fix from $2,3002025-09-02 CRITICAL 9.8 CVE-2025-22408 In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code exec… Android Mitigation only Fix from $2,3002025-08-26 CRITICAL 9.8 CVE-2025-22403 In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remo… Android Mitigation only Fix from $2,3002025-08-26 CRITICAL 9.8 CVE-2025-0074 In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote… Android Mitigation only Fix from $2,3002025-08-26 CRITICAL 9.8 CVE-2025-0075 In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to re… Android Mitigation only Fix from $2,3002025-08-26 CRITICAL 9.6 CVE-2025-4609 Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to poten… Chrome 136.0.7103.113+ Fix from $2,3002025-08-22 CRITICAL 9.8 CVE-2025-6179 Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensi… Chrome Os Mitigation only Fix from $2,3002025-06-16 CRITICAL 9.8 CVE-2025-4052 Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific… Chrome 136.0.7103.59+ Fix from $2,3002025-05-05 CRITICAL 10.0 CVE-2025-0982 Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via craft… Application Integration after 2025-01-23 Fix from $2,3002025-02-06 CRITICAL 9.8 CVE-2024-49747 In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote … Android Mitigation only Fix from $2,3002025-01-21 CRITICAL 9.8 CVE-2024-49748 In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote … Android Mitigation only Fix from $2,3002025-01-21 CRITICAL 9.8 CVE-2024-53842 In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote c… Android Mitigation only Fix from $2,3002025-01-03 CRITICAL 9.8 CVE-2018-9388 In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer und… Android Mitigation only Fix from $2,3002024-12-05 CRITICAL 9.8 CVE-2018-9430 In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution wi… Android Patch available Fix from $2,3002024-12-02 CRITICAL 9.8 CVE-2018-9418 In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code… Android Patch available Fix from $2,3002024-12-02 CRITICAL 9.6 CVE-2024-9369 Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to pe… Chrome 129.0.6668.89+ Fix from $2,3002024-11-27 CRITICAL 9.8 CVE-2018-9478 In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This… Android Patch available Fix from $2,3002024-11-20 CRITICAL 9.8 CVE-2018-9479 In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This… Android Patch available Fix from $2,3002024-11-20 CRITICAL 9.8 CVE-2018-9467 In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security deci… Android Mitigation only Fix from $2,3002024-11-20 CRITICAL 9.8 CVE-2024-43091 In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution… Android Patch available Fix from $2,3002024-11-13 CRITICAL 9.8 CVE-2024-44097 According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the se… Nest Doorbell \(battery\) Firmware 1.73c+ Fix from $2,3002024-10-02 CRITICAL 9.6 CVE-2024-7024 Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a cr… Chrome 126.0.6478.54+ Fix from $2,3002024-09-23 CRITICAL 9.6 CVE-2024-7971 KEVEPSS 21% Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium … Chrome 128.0.2739.42 / 128.0.6613.84+ Fix from $2,3002024-08-21