Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.8
CVE-2026-13038

Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome CRITICAL 9.6
CVE-2026-13028

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 149.0.7827.197+
Fix from $2,300 2026-06-24
Chrome CRITICAL 9.6
CVE-2026-13032

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 149.0.7827.197+
Fix from $2,300 2026-06-24
Chrome HIGH 8.8
CVE-2026-13031

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome HIGH 8.8
CVE-2026-13033

Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome HIGH 8.8
CVE-2026-13035

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious perip…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome HIGH 8.8
CVE-2026-13036

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome HIGH 7.8
CVE-2026-13037

Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome HIGH 7.5
CVE-2026-13029

Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extensi…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome MEDIUM 5.3
CVE-2026-13030

Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information fr…

Fix: 149.0.7827.197+
Fix from $1,600 2026-06-24
Chrome HIGH 8.8
CVE-2026-13026

Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruptio…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome HIGH 8.8
CVE-2026-13027

Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome HIGH 8.3
CVE-2026-13025

Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Chrome MEDIUM 6.5
CVE-2026-13022

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process …

Fix: 149.0.7827.197+
Fix from $1,600 2026-06-24
Chrome MEDIUM 5.3
CVE-2026-13023

Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potent…

Fix: 149.0.7827.197+
Fix from $1,600 2026-06-24
Gemini Cli HIGH 7.8
CVE-2026-12537

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Act…

Fix: 0.1.22 / 0.39.1+
Fix from $1,950 2026-06-24
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11717

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When veri…

Fix: after 1.3.0
Fix from $2,300 2026-06-18
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11718

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the …

Fix: after 1.3.0
Fix from $2,300 2026-06-18
Mcp Toolbox For Databases HIGH 8.1
CVE-2026-11719

An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handle…

Patch available
Fix from $1,950 2026-06-18
Android MEDIUM 5.5
CVE-2026-28573

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of servic…

Mitigation only
Fix from $1,600 2026-06-18
Android HIGH 7.8
CVE-2026-28615

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privi…

Mitigation only
Fix from $1,950 2026-06-17
Android MEDIUM 5.5
CVE-2026-28575

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible me…

Mitigation only
Fix from $1,600 2026-06-17
Android MEDIUM 5.5
CVE-2026-28576

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure w…

Mitigation only
Fix from $1,600 2026-06-17
Android MEDIUM 5.5
CVE-2026-28587

In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lea…

Mitigation only
Fix from $1,600 2026-06-17
Chrome HIGH 8.3
CVE-2026-12468

Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 149.0.7827.155+
Fix from $1,950 2026-06-17
Chrome HIGH 8.8
CVE-2026-12466

Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted …

Fix: 149.0.7827.155+
Fix from $1,950 2026-06-17
Chrome HIGH 8.3
CVE-2026-12464

Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 149.0.7827.155+
Fix from $1,950 2026-06-17
Chrome HIGH 8.3
CVE-2026-12465

Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 149.0.7827.155+
Fix from $1,950 2026-06-17
Chrome HIGH 8.3
CVE-2026-12467

Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 149.0.7827.155+
Fix from $1,950 2026-06-17
Chrome HIGH 7.5
CVE-2026-12462

Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execute arbitr…

Fix: 149.0.7827.155+
Fix from $1,950 2026-06-17