Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Chrome HIGH 8.8
CVE-2026-17922

Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a crafted …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-14407

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Chrome HIGH 8.8
CVE-2026-14383

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Chrome HIGH 8.8
CVE-2026-11688

Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via…

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Chrome HIGH 8.1
CVE-2026-11231

Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via …

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome MEDIUM 6.8
CVE-2026-11218

Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who convinced a user…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 5.4
CVE-2026-11157

Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension t…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome HIGH 8.8
CVE-2026-10928

Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Ch…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10904

Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-9976

Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML p…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9938

Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome MEDIUM 5.4
CVE-2026-8539

Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (U…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Chrome HIGH 8.8
CVE-2026-3910 KEV

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 146.0.7680.75+
Fix from $1,950 2026-03-13
Android MEDIUM 6.5
CVE-2024-40673

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper inp…

Mitigation only
Fix from $1,600 2025-01-28
Android CRITICAL 9.8
CVE-2024-49747

In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote …

Mitigation only
Fix from $2,300 2025-01-21
Android HIGH 8.8
CVE-2024-43770

In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 8.8
CVE-2024-43771

In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/a…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 8.8
CVE-2024-43767

In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input validation. This could lead to remo…

Mitigation only
Fix from $1,950 2025-01-03
Androidx.car.app HIGH 7.5
CVE-2024-10382

There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction…

Fix: after 1.4.0
Fix from $1,950 2024-11-20
Android HIGH 7.8
CVE-2024-40671

In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This …

Mitigation only
Fix from $1,950 2024-11-13
Android HIGH 8.8
CVE-2024-32925

In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code e…

Mitigation only
Fix from $1,950 2024-06-13
Chrome HIGH 8.8
CVE-2024-5834

Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML p…

Fix: 126.0.6478.54+
Fix from $1,950 2024-06-11
Android CRITICAL 9.8
CVE-2022-42541

Remote code execution

No fix yet
Fix from $2,300 2023-11-29
Android MEDIUM 5.5
CVE-2022-33721

A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege.

Mitigation only
Fix from $1,600 2022-08-05
Tensorflow HIGH 7.8
CVE-2022-29216

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is …

Fix: 2.6.4 / 2.7.2+
Fix from $1,950 2022-05-21
Android MEDIUM 6.0
CVE-2022-23426

A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.

Mitigation only
Fix from $1,600 2022-02-11
Tensorflow HIGH 7.8
CVE-2021-41228

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is vulnerable to a code injectio…

Fix: 2.4.4 / 2.5.2+
Fix from $1,950 2021-11-05
Android HIGH 7.9
CVE-2021-25470

An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

Mitigation only
Fix from $1,950 2021-10-06
Slo Generator HIGH 7.8
CVE-2021-22557

SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Genera…

Fix: 2.0.1+
Fix from $1,950 2021-10-04
Android MEDIUM 6.5
CVE-2021-25416

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel…

Mitigation only
Fix from $1,600 2021-06-11