Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android MEDIUM 5.5
CVE-2025-26429

In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial…

Patch available
Fix from $1,600 2025-09-04
Android MEDIUM 5.1
CVE-2025-26426

In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due t…

Mitigation only
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2024-56190

In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escal…

Mitigation only
Fix from $1,950 2025-09-04
Chrome HIGH 8.8
CVE-2025-6558 KEVEPSS 9%

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform…

Fix: 2.6 / 11.6+
Fix from $1,950 2025-07-15
Web Designer HIGH 8.8
CVE-2025-4613

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b…

Fix: 16.3.0.0407+
Fix from $1,950 2025-06-12
Chrome HIGH 8.8
CVE-2025-3068

Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation …

Fix: 135.0.7049.52+
Fix from $1,950 2025-04-02
Chrome MEDIUM 6.5
CVE-2025-3070

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escal…

Fix: 135.0.7049.52+
Fix from $1,600 2025-04-02
Chrome HIGH 8.8
CVE-2024-7023

Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malici…

Fix: 128.0.6537.0+
Fix from $1,950 2024-09-23
Android HIGH 7.8
CVE-2024-44094

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalati…

Mitigation only
Fix from $1,950 2024-09-13
Chrome HIGH 8.8
CVE-2024-7974

Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 7.8
CVE-2024-7977

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 7.8
CVE-2024-7980

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation…

Fix: 128.0.6613.84+
Fix from $1,950 2024-08-21
Chrome HIGH 8.8
CVE-2024-3173

Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation vi…

Fix: 120.0.6099.62+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-3172

Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific…

Fix: 121.0.6167.85+
Fix from $1,950 2024-07-16
Chrome CRITICAL 9.6
CVE-2023-7012

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a mali…

Fix: 117.0.5938.62+
Fix from $2,300 2024-07-16
Android HIGH 7.8
CVE-2024-31310

In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service s…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-32903

In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local …

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.8
CVE-2024-32907

In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege wi…

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.8
CVE-2024-23705

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local…

Patch available
Fix from $1,950 2024-05-07
Android HIGH 7.8
CVE-2024-23706

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation…

Patch available
Fix from $1,950 2024-05-07
Android HIGH 7.8
CVE-2024-23707

In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with…

Patch available
Fix from $1,950 2024-05-07
Android MEDIUM 5.5
CVE-2024-0022

In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profil…

Patch available
Fix from $1,600 2024-05-07
Android HIGH 7.8
CVE-2024-20064

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no a…

Mitigation only
Fix from $1,950 2024-05-06
Chrome MEDIUM 6.1
CVE-2024-3841

Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a p…

Fix: 124.0.6367.60+
Fix from $1,600 2024-04-17
Android HIGH 8.8
CVE-2024-23717

In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This …

Patch available
Fix from $1,950 2024-03-11
Android MEDIUM 6.5
CVE-2024-0045

In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjac…

Patch available
Fix from $1,600 2024-03-11
Android HIGH 7.2
CVE-2024-20034

In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System e…

Mitigation only
Fix from $1,950 2024-03-04
Android HIGH 7.8
CVE-2024-0021

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener se…

Patch available
Fix from $1,950 2024-02-16
Android CRITICAL 9.8
CVE-2024-0031

In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead t…

Patch available
Fix from $2,300 2024-02-16
Android MEDIUM 5.5
CVE-2023-48354

In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution pri…

Mitigation only
Fix from $1,600 2024-01-18