Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.5 CVE-2025-26429 In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial… Android Patch available Fix from $1,6002025-09-04 MEDIUM 5.1 CVE-2025-26426 In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due t… Android Mitigation only Fix from $1,6002025-09-04 HIGH 7.8 CVE-2024-56190 In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escal… Android Mitigation only Fix from $1,9502025-09-04 HIGH 8.8 CVE-2025-6558 KEVEPSS 9% Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform… Chrome 2.6 / 11.6+ Fix from $1,9502025-07-15 HIGH 8.8 CVE-2025-4613 Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b… Web Designer 16.3.0.0407+ Fix from $1,9502025-06-12 HIGH 8.8 CVE-2025-3068 Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation … Chrome 135.0.7049.52+ Fix from $1,9502025-04-02 MEDIUM 6.5 CVE-2025-3070 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escal… Chrome 135.0.7049.52+ Fix from $1,6002025-04-02 HIGH 8.8 CVE-2024-7023 Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malici… Chrome 128.0.6537.0+ Fix from $1,9502024-09-23 HIGH 7.8 CVE-2024-44094 In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalati… Android Mitigation only Fix from $1,9502024-09-13 HIGH 8.8 CVE-2024-7974 Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a… Chrome 128.0.6613.84+ Fix from $1,9502024-08-21 HIGH 7.8 CVE-2024-7977 Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation… Chrome 128.0.6613.84+ Fix from $1,9502024-08-21 HIGH 7.8 CVE-2024-7980 Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation… Chrome 128.0.6613.84+ Fix from $1,9502024-08-21 HIGH 8.8 CVE-2024-3173 Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation vi… Chrome 120.0.6099.62+ Fix from $1,9502024-07-16 HIGH 8.8 CVE-2024-3172 Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific… Chrome 121.0.6167.85+ Fix from $1,9502024-07-16 CRITICAL 9.6 CVE-2023-7012 Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a mali… Chrome 117.0.5938.62+ Fix from $2,3002024-07-16 HIGH 7.8 CVE-2024-31310 In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service s… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-32903 In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local … Android Mitigation only Fix from $1,9502024-06-13 HIGH 7.8 CVE-2024-32907 In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege wi… Android Mitigation only Fix from $1,9502024-06-13 HIGH 7.8 CVE-2024-23705 In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local… Android Patch available Fix from $1,9502024-05-07 HIGH 7.8 CVE-2024-23706 In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation… Android Patch available Fix from $1,9502024-05-07 HIGH 7.8 CVE-2024-23707 In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with… Android Patch available Fix from $1,9502024-05-07 MEDIUM 5.5 CVE-2024-0022 In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profil… Android Patch available Fix from $1,6002024-05-07 HIGH 7.8 CVE-2024-20064 In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no a… Android Mitigation only Fix from $1,9502024-05-06 MEDIUM 6.1 CVE-2024-3841 Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a p… Chrome 124.0.6367.60+ Fix from $1,6002024-04-17 HIGH 8.8 CVE-2024-23717 In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This … Android Patch available Fix from $1,9502024-03-11 MEDIUM 6.5 CVE-2024-0045 In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjac… Android Patch available Fix from $1,6002024-03-11 HIGH 7.2 CVE-2024-20034 In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System e… Android Mitigation only Fix from $1,9502024-03-04 HIGH 7.8 CVE-2024-0021 In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener se… Android Patch available Fix from $1,9502024-02-16 CRITICAL 9.8 CVE-2024-0031 In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead t… Android Patch available Fix from $2,3002024-02-16 MEDIUM 5.5 CVE-2023-48354 In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution pri… Android Mitigation only Fix from $1,6002024-01-18