Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.1
CVE-2021-21205

Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictio…

Fix: 90.0.4430.72+
Fix from $1,950 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21208

Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain s…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21209

Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21210

Inappropriate implementation in Network in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially access local UDP ports via a …

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21211

Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a cr…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21212

Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowed a remote attacker to potentially compromise WiF…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21215EPSS 34%

Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML pag…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21216EPSS 22%

Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML pag…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21221

Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer …

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21222

Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to bypass site i…

Fix: 90.0.4430.85+
Fix from $1,600 2021-04-26
Chrome MEDIUM 5.5
CVE-2021-21217

Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 5.5
CVE-2021-21218

Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Chrome MEDIUM 5.5
CVE-2021-21219

Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Android MEDIUM 5.5
CVE-2021-25382

An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secur…

Mitigation only
Fix from $1,600 2021-04-23
Bazel HIGH 7.8
CVE-2021-22539

An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel allows the workspace path to l…

Fix: 0.4.1+
Fix from $1,950 2021-04-16
Android MEDIUM 6.7
CVE-2021-0488

In pb_write of pb_encode.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege w…

Patch available
Fix from $1,600 2021-04-15
Android HIGH 7.8
CVE-2021-0437

In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in a privileged process with no …

Patch available
Fix from $1,950 2021-04-13
Android HIGH 7.8
CVE-2021-0438

In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is a possible tapjacking attack due to an incorrect …

Patch available
Fix from $1,950 2021-04-13
Android HIGH 7.8
CVE-2021-0439

In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write due to a missing bounds check.…

Patch available
Fix from $1,950 2021-04-13
Android HIGH 7.8
CVE-2021-0442

In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a use after free. This could lead…

Patch available
Fix from $1,950 2021-04-13
Android HIGH 7.8
CVE-2021-0445

In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,950 2021-04-13
Android HIGH 7.5
CVE-2021-0435

In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information di…

Patch available
Fix from $1,950 2021-04-13
Android HIGH 7.3
CVE-2021-0446

In ImportVCardActivity, there is a possible way to bypass user consent due to a tapjacking/overlay attack. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2021-04-13
Android MEDIUM 6.6
CVE-2021-0468

In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege for an attacker…

Mitigation only
Fix from $1,600 2021-04-13
Android MEDIUM 5.5
CVE-2021-0436

In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow. This could lead to local information di…

Patch available
Fix from $1,600 2021-04-13
Android MEDIUM 5.5
CVE-2021-0444

In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent. This could lead to local information disclosure of con…

Patch available
Fix from $1,600 2021-04-13
Android MEDIUM 5.5
CVE-2021-0471

In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosur…

Patch available
Fix from $1,600 2021-04-13
Android CRITICAL 9.8
CVE-2021-0430

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio…

Patch available
Fix from $2,300 2021-04-13
Android HIGH 8.0
CVE-2021-0433

In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth device due to a tapjacking/overlay…

Patch available
Fix from $1,950 2021-04-13
Android HIGH 7.8
CVE-2021-0426

In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to loc…

Patch available
Fix from $1,950 2021-04-13