Vulnerability index

Browse CVEs

161 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Android MEDIUM 6.2
CVE-2026-0055

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory du…

Mitigation only
Fix from $1,600 2026-06-01
Android HIGH 7.8
CVE-2026-0009

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no addi…

Mitigation only
Fix from $1,950 2026-06-01
Chrome HIGH 8.8
CVE-2026-9999

Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sa…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9918

Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome HIGH 8.3
CVE-2026-9892

Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer p…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 7.8
CVE-2026-7994

Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege …

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Chrome MEDIUM 6.3
CVE-2026-7977

Inappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a crafted H…

Fix: 148.0.7778.96+
Fix from $1,600 2026-05-06
Chrome MEDIUM 6.3
CVE-2026-7971

Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML pag…

Fix: 148.0.7778.96+
Fix from $1,600 2026-05-06
Android HIGH 8.4
CVE-2026-0029

In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege…

Patch available
Fix from $1,950 2026-03-02
Android HIGH 7.8
CVE-2026-0032

In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation…

Patch available
Fix from $1,950 2026-03-02
Android HIGH 7.8
CVE-2026-0023

In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission chec…

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 7.8
CVE-2025-48645

In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalat…

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 7.8
CVE-2025-48613

In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the same key.…

Mitigation only
Fix from $1,950 2026-03-02
Chrome HIGH 7.5
CVE-2025-12726

Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer …

Fix: 142.0.7444.134+
Fix from $1,950 2025-11-10
Android HIGH 7.8
CVE-2025-32345

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's decept…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-26462

In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to local esc…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-26435

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's decept…

Patch available
Fix from $1,950 2025-09-04
Android CRITICAL 9.8
CVE-2025-36904

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.

Mitigation only
Fix from $2,300 2025-09-04
Android HIGH 8.8
CVE-2025-36901

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.

Mitigation only
Fix from $1,950 2025-09-04
Android CRITICAL 9.8
CVE-2025-36890

Elevation of Privilege

No fix yet
Fix from $2,300 2025-09-04
Android CRITICAL 9.8
CVE-2025-36896

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.

Mitigation only
Fix from $2,300 2025-09-04
Android HIGH 8.8
CVE-2025-36891

Elevation of privilege

No fix yet
Fix from $1,950 2025-09-04
Chrome Os HIGH 7.4
CVE-2025-6177

Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code e…

Mitigation only
Fix from $1,950 2025-06-16
Chrome Os MEDIUM 6.8
CVE-2025-1121

Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access…

Mitigation only
Fix from $1,600 2025-03-07
Android HIGH 7.8
CVE-2024-49742

In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a mis…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2018-9375

In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy…

Mitigation only
Fix from $1,950 2025-01-17
Nest Doorbell \(battery\) Firmware CRITICAL 9.8
CVE-2024-44097

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the se…

Fix: 1.73c+
Fix from $2,300 2024-10-02
Android HIGH 7.8
CVE-2024-29779

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional executi…

No fix yet
Fix from $1,950 2024-09-13
Android HIGH 7.8
CVE-2024-40657

In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This …

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40658

In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local esc…

Patch available
Fix from $1,950 2024-09-11