Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.8
CVE-2025-4096

Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 136.0.7103.59+
Fix from $1,950 2025-05-05
Chrome MEDIUM 6.3
CVE-2025-4051

Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific…

Fix: 136.0.7103.59+
Fix from $1,600 2025-05-05
Chrome HIGH 8.8
CVE-2025-4050

Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific …

Fix: 136.0.7103.59+
Fix from $1,950 2025-05-05
Android HIGH 7.8
CVE-2025-20668

In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor …

Mitigation only
Fix from $1,950 2025-05-05
Android HIGH 7.0
CVE-2025-20671

In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor ha…

Mitigation only
Fix from $1,950 2025-05-05
Android MEDIUM 5.5
CVE-2025-20665

In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device ide…

Mitigation only
Fix from $1,600 2025-05-05
Chrome Os HIGH 8.1
CVE-2025-1290

A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allo…

No fix yet
Fix from $1,950 2025-04-17
Chrome Os HIGH 8.8
CVE-2025-2073

Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an…

No fix yet
Fix from $1,950 2025-04-16
Chrome Os HIGH 8.8
CVE-2025-1568

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit acc…

Mitigation only
Fix from $1,950 2025-04-16
Chrome Os HIGH 7.5
CVE-2025-1566

DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via fail…

Mitigation only
Fix from $1,950 2025-04-16
Chrome Os MEDIUM 6.5
CVE-2025-1704

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenrol…

No fix yet
Fix from $1,600 2025-04-16
Chrome HIGH 8.8
CVE-2025-3620

Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 135.0.7049.95+
Fix from $1,950 2025-04-16
Chrome HIGH 8.8
CVE-2025-3619

Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption vi…

Fix: 135.0.7049.95+
Fix from $1,950 2025-04-16
Chrome MEDIUM 6.7
CVE-2025-1122

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persis…

No fix yet
Fix from $1,600 2025-04-15
Chrome MEDIUM 6.7
CVE-2025-1292

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain pe…

No fix yet
Fix from $1,600 2025-04-15
Android MEDIUM 6.7
CVE-2025-20661

In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a maliciou…

Mitigation only
Fix from $1,600 2025-04-07
Android MEDIUM 6.7
CVE-2025-20662

In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a maliciou…

Mitigation only
Fix from $1,600 2025-04-07
Android MEDIUM 6.7
CVE-2025-20657

In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious acto…

Mitigation only
Fix from $1,600 2025-04-07
Android MEDIUM 6.7
CVE-2025-20660

In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a maliciou…

Mitigation only
Fix from $1,600 2025-04-07
Android MEDIUM 6.0
CVE-2025-20658

In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical acce…

Mitigation only
Fix from $1,600 2025-04-07
Android MEDIUM 5.3
CVE-2025-20655

In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious ac…

Mitigation only
Fix from $1,600 2025-04-07
Chrome HIGH 8.8
CVE-2025-3067

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to enga…

Fix: 135.0.7049.52+
Fix from $1,950 2025-04-02
Chrome HIGH 8.8
CVE-2025-3068

Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation …

Fix: 135.0.7049.52+
Fix from $1,950 2025-04-02
Chrome HIGH 8.8
CVE-2025-3069

Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a cr…

Fix: 135.0.7049.52+
Fix from $1,950 2025-04-02
Chrome MEDIUM 6.5
CVE-2025-3070

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escal…

Fix: 135.0.7049.52+
Fix from $1,600 2025-04-02
Chrome MEDIUM 5.4
CVE-2025-3071

Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in speci…

Fix: 135.0.7049.52+
Fix from $1,600 2025-04-02
Chrome MEDIUM 5.4
CVE-2025-3072

Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in speci…

Fix: 135.0.7049.52+
Fix from $1,600 2025-04-02
Chrome MEDIUM 5.4
CVE-2025-3073

Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific…

Fix: 135.0.7049.52+
Fix from $1,600 2025-04-02
Chrome MEDIUM 5.4
CVE-2025-3074

Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML…

Fix: 135.0.7049.52+
Fix from $1,600 2025-04-02
Chrome HIGH 8.8
CVE-2025-3066

Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 135.0.7049.52+
Fix from $1,950 2025-04-02