Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome Os CRITICAL 9.8
CVE-2025-6179

Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensi…

Mitigation only
Fix from $2,300 2025-06-16
Chrome Os HIGH 7.4
CVE-2025-6177

Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code e…

Mitigation only
Fix from $1,950 2025-06-16
Protobuf Python MEDIUM 5.3
CVE-2025-4565

Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recur…

Fix: 4.25.8 / 5.29.5+
Fix from $1,600 2025-06-16
Web Designer HIGH 8.8
CVE-2025-4613

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b…

Fix: 16.3.0.0407+
Fix from $1,950 2025-06-12
Chrome HIGH 8.8
CVE-2025-5959EPSS 12%

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 137.0.7151.103+
Fix from $1,950 2025-06-11
Chrome HIGH 8.8
CVE-2025-5958

Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 137.0.7151.103+
Fix from $1,950 2025-06-11
Android HIGH 8.4
CVE-2025-31710

In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,950 2025-06-03
Android MEDIUM 6.2
CVE-2025-31711

In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional exe…

Mitigation only
Fix from $1,600 2025-06-03
Android MEDIUM 6.2
CVE-2025-31712

In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additiona…

Mitigation only
Fix from $1,600 2025-06-03
Chrome HIGH 8.8
CVE-2025-5419 KEVEPSS 8%

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 137.0.3296.62 / 137.0.7151.68+
Fix from $1,950 2025-06-03
Chrome HIGH 8.8
CVE-2025-5068

Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 137.0.7151.68+
Fix from $1,950 2025-06-03
Chrome HIGH 8.8
CVE-2025-5280

Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 137.0.7151.55+
Fix from $1,950 2025-05-27
Chrome MEDIUM 5.4
CVE-2025-5281

Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via …

Fix: 137.0.7151.55+
Fix from $1,600 2025-05-27
Chrome MEDIUM 5.4
CVE-2025-5283

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 137.0.7151.55+
Fix from $1,600 2025-05-27
Chrome HIGH 8.8
CVE-2025-5063

Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 137.0.7151.55+
Fix from $1,950 2025-05-27
Chrome MEDIUM 6.5
CVE-2025-5065

Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a c…

Fix: 137.0.7151.55+
Fix from $1,600 2025-05-27
Chrome MEDIUM 6.5
CVE-2025-5066

Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage …

Fix: 137.0.7151.55+
Fix from $1,600 2025-05-27
Chrome MEDIUM 5.4
CVE-2025-5064

Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via …

Fix: 137.0.7151.55+
Fix from $1,600 2025-05-27
Chrome MEDIUM 5.4
CVE-2025-5067

Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML…

Fix: 137.0.7151.55+
Fix from $1,600 2025-05-27
Android HIGH 8.4
CVE-2025-27700

There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional …

No fix yet
Fix from $1,950 2025-05-27
Android MEDIUM 5.5
CVE-2025-27701

In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Late…

Mitigation only
Fix from $1,600 2025-05-27
Android MEDIUM 5.1
CVE-2024-56193

There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no addi…

Mitigation only
Fix from $1,600 2025-05-27
Application Load Balancer HIGH 7.5
CVE-2025-4600

A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requ…

Fix: 2025-04-26+
Fix from $1,950 2025-05-16
Web Designer HIGH 7.8
CVE-2025-1079

Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature

Fix: 16.2.0.0128+
Fix from $1,950 2025-05-12
Android HIGH 7.8
CVE-2025-20979

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.

Fix: 15.0+
Fix from $1,950 2025-05-07
Android MEDIUM 5.5
CVE-2025-20980

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

Fix: 15.0+
Fix from $1,600 2025-05-07
Chrome HIGH 8.8
CVE-2025-4372

Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 136.0.7103.92+
Fix from $1,950 2025-05-06
Tensorflow Serving HIGH 7.5
CVE-2025-0649

Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to serve…

Fix: after 2.18.0
Fix from $1,950 2025-05-06
Chrome Os HIGH 7.8
CVE-2025-2509

Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandbox…

No fix yet
Fix from $1,950 2025-05-06
Chrome CRITICAL 9.8
CVE-2025-4052

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific…

Fix: 136.0.7103.59+
Fix from $2,300 2025-05-05