Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2026-17922 Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a crafted … Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-14407 Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 150.0.7871.46+ Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-14383 Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 150.0.7871.46+ Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-11688 Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via… Chrome 149.0.7827.103+ Fix from $1,9502026-06-09 HIGH 8.1 CVE-2026-11231 Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via … Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 MEDIUM 6.8 CVE-2026-11218 Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who convinced a user… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 5.4 CVE-2026-11157 Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension t… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 8.8 CVE-2026-10928 Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Ch… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10904 Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-9976 Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML p… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9938 Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via … Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 MEDIUM 5.4 CVE-2026-8539 Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (U… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 HIGH 8.8 CVE-2026-3910 KEV Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 146.0.7680.75+ Fix from $1,9502026-03-13 MEDIUM 6.5 CVE-2024-40673 In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper inp… Android Mitigation only Fix from $1,6002025-01-28 CRITICAL 9.8 CVE-2024-49747 In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote … Android Mitigation only Fix from $2,3002025-01-21 HIGH 8.8 CVE-2024-43770 In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/… Android Mitigation only Fix from $1,9502025-01-21 HIGH 8.8 CVE-2024-43771 In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/a… Android Mitigation only Fix from $1,9502025-01-21 HIGH 8.8 CVE-2024-43767 In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input validation. This could lead to remo… Android Mitigation only Fix from $1,9502025-01-03 HIGH 7.5 CVE-2024-10382 There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction… Androidx.car.app after 1.4.0 Fix from $1,9502024-11-20 HIGH 7.8 CVE-2024-40671 In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This … Android Mitigation only Fix from $1,9502024-11-13 HIGH 8.8 CVE-2024-32925 In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code e… Android Mitigation only Fix from $1,9502024-06-13 HIGH 8.8 CVE-2024-5834 Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML p… Chrome 126.0.6478.54+ Fix from $1,9502024-06-11 CRITICAL 9.8 CVE-2022-42541 Remote code execution Android No fix yet Fix from $2,3002023-11-29 MEDIUM 5.5 CVE-2022-33721 A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege. Android Mitigation only Fix from $1,6002022-08-05 HIGH 7.8 CVE-2022-29216 TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is … Tensorflow 2.6.4 / 2.7.2+ Fix from $1,9502022-05-21 MEDIUM 6.0 CVE-2022-23426 A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege. Android Mitigation only Fix from $1,6002022-02-11 HIGH 7.8 CVE-2021-41228 TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is vulnerable to a code injectio… Tensorflow 2.4.4 / 2.5.2+ Fix from $1,9502021-11-05 HIGH 7.9 CVE-2021-25470 An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE. Android Mitigation only Fix from $1,9502021-10-06 HIGH 7.8 CVE-2021-22557 SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Genera… Slo Generator 2.0.1+ Fix from $1,9502021-10-04 MEDIUM 6.5 CVE-2021-25416 Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel… Android Mitigation only Fix from $1,6002021-06-11