Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android MEDIUM 5.5
CVE-2024-49740

In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execu…

No fix yet
Fix from $1,600 2025-08-26
Android HIGH 8.0
CVE-2023-21125

In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2025-08-26
Chrome HIGH 8.8
CVE-2025-9478

Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 139.0.7258.154+
Fix from $1,950 2025-08-26
Chrome CRITICAL 9.6
CVE-2025-4609

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to poten…

Fix: 136.0.7103.113+
Fix from $2,300 2025-08-22
Chrome HIGH 8.8
CVE-2025-9132

Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 139.0.7258.138+
Fix from $1,950 2025-08-20
Chrome HIGH 8.8
CVE-2025-8901

Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted …

Fix: 139.0.7258.127+
Fix from $1,950 2025-08-13
Chrome HIGH 8.8
CVE-2025-8882

Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to p…

Fix: 139.0.7258.127+
Fix from $1,950 2025-08-13
Chrome MEDIUM 6.5
CVE-2025-8881

Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in spec…

Fix: 139.0.7258.127+
Fix from $1,600 2025-08-13
Chrome HIGH 8.8
CVE-2025-8880

Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…

Fix: 139.0.7258.127+
Fix from $1,950 2025-08-13
Chrome HIGH 8.8
CVE-2025-8879

Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curate…

Fix: 139.0.7258.127+
Fix from $1,950 2025-08-13
Chrome HIGH 8.8
CVE-2025-8576

Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted C…

Fix: 139.0.7258.66+
Fix from $1,950 2025-08-07
Chrome HIGH 8.8
CVE-2025-8578

Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

Fix: 139.0.7258.66+
Fix from $1,950 2025-08-07
Android MEDIUM 5.5
CVE-2025-21024

Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.

Fix: 16.0+
Fix from $1,600 2025-08-06
Android MEDIUM 6.7
CVE-2025-20698

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious …

Mitigation only
Fix from $1,600 2025-08-04
Android MEDIUM 6.7
CVE-2025-20697

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious …

Mitigation only
Fix from $1,600 2025-08-04
Firebase Php Jwt MEDIUM 6.5
CVE-2025-45769

php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by…

Fix: after 6.11.0
Fix from $1,600 2025-07-31
Chrome HIGH 8.8
CVE-2025-8292

Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 138.0.7204.183+
Fix from $1,950 2025-07-30
Chrome HIGH 8.8
CVE-2025-8011

Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 138.0.7204.168+
Fix from $1,950 2025-07-22
Chrome HIGH 8.8
CVE-2025-8010

Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 138.0.7204.168+
Fix from $1,950 2025-07-22
Chrome HIGH 8.8
CVE-2025-6558 KEVEPSS 9%

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform…

Fix: 2.6 / 11.6+
Fix from $1,950 2025-07-15
Chrome HIGH 8.8
CVE-2025-7656EPSS 9%

Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 138.0.7204.157+
Fix from $1,950 2025-07-15
Chrome HIGH 8.8
CVE-2025-7657

Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 138.0.7204.157+
Fix from $1,950 2025-07-15
Chrome Os MEDIUM 6.1
CVE-2025-6044

An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a p…

Mitigation only
Fix from $1,600 2025-07-07
Chrome HIGH 8.1
CVE-2025-6554 KEVEPSS 13%

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chro…

Fix: 138.0.7204.92 / 138.0.7204.96+
Fix from $1,950 2025-06-30
Chrome MEDIUM 5.4
CVE-2025-6555

Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 138.0.7204.49+
Fix from $1,600 2025-06-24
Chrome MEDIUM 5.4
CVE-2025-6556

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a c…

Fix: 138.0.7204.49+
Fix from $1,600 2025-06-24
Chrome MEDIUM 5.4
CVE-2025-6557

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage …

Fix: 138.0.7204.49+
Fix from $1,600 2025-06-24
Chrome HIGH 8.8
CVE-2025-6191EPSS 10%

Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a cr…

Fix: 137.0.7151.119+
Fix from $1,950 2025-06-18
Chrome HIGH 8.8
CVE-2025-6192

Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 137.0.7151.119+
Fix from $1,950 2025-06-18
Osv Scalibr MEDIUM 6.5
CVE-2025-5981

Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for con…

Fix: 0.1.8+
Fix from $1,600 2025-06-18