Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nest Doorbell \(battery\) Firmware CRITICAL 9.8
CVE-2024-44097

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the se…

Fix: 1.73c+
Fix from $2,300 2024-10-02
Android HIGH 7.8
CVE-2024-39435

In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional …

No fix yet
Fix from $1,950 2024-09-27
Chrome HIGH 8.8
CVE-2024-9120

Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 129.0.6668.70+
Fix from $1,950 2024-09-25
Chrome HIGH 8.8
CVE-2024-9121

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory acce…

Fix: 129.0.6668.70+
Fix from $1,950 2024-09-25
Chrome HIGH 8.8
CVE-2024-9122EPSS 6%

Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page…

Fix: 129.0.6668.70+
Fix from $1,950 2024-09-25
Chrome HIGH 8.8
CVE-2024-9123

Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTM…

Fix: 129.0.6668.70+
Fix from $1,950 2024-09-25
Chrome CRITICAL 9.6
CVE-2024-7024

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a cr…

Fix: 126.0.6478.54+
Fix from $2,300 2024-09-23
Chrome HIGH 8.8
CVE-2024-7023

Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malici…

Fix: 128.0.6537.0+
Fix from $1,950 2024-09-23
Chrome HIGH 7.8
CVE-2024-7018

Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PD…

Fix: 124.0.6367.78+
Fix from $1,950 2024-09-23
Chrome HIGH 8.8
CVE-2021-38023

Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 92.0.4515.107+
Fix from $1,950 2024-09-23
Chrome HIGH 7.8
CVE-2018-20072

Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a cra…

Fix: 73.0.3683.75+
Fix from $1,950 2024-09-23
Reverb HIGH 7.8
CVE-2024-8375

There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C+…

Fix: 2024-08-05+
Fix from $1,950 2024-09-19
Protobuf HIGH 7.5
CVE-2024-7254

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exce…

Fix: 3.25.5 / 4.27.5+
Fix from $1,950 2024-09-19
Chrome HIGH 8.8
CVE-2024-8905

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a cr…

Fix: 129.0.6668.58+
Fix from $1,950 2024-09-17
Chrome MEDIUM 6.1
CVE-2024-8907

Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage i…

Fix: 129.0.6668.58+
Fix from $1,600 2024-09-17
Chrome HIGH 8.8
CVE-2024-8904

Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 129.0.6668.58+
Fix from $1,950 2024-09-17
Nest Wifi Pro Firmware MEDIUM 5.3
CVE-2024-22013

U-Boot environment is read from unauthenticated partition.

Mitigation only
Fix from $1,600 2024-09-16
Android HIGH 7.8
CVE-2024-29779

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional executi…

No fix yet
Fix from $1,950 2024-09-13
Android HIGH 7.8
CVE-2024-44092

There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2024-09-13
Android HIGH 7.8
CVE-2024-44093

In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalati…

Mitigation only
Fix from $1,950 2024-09-13
Android HIGH 7.8
CVE-2024-44094

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalati…

Mitigation only
Fix from $1,950 2024-09-13
Android HIGH 7.8
CVE-2024-44095

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation …

Mitigation only
Fix from $1,950 2024-09-13
Chrome HIGH 8.8
CVE-2024-8638

Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML p…

Fix: 128.0.6613.137+
Fix from $1,950 2024-09-11
Chrome HIGH 8.8
CVE-2024-8639

Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 128.0.6613.137+
Fix from $1,950 2024-09-11
Chrome HIGH 8.8
CVE-2024-8636

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 128.0.6613.137+
Fix from $1,950 2024-09-11
Chrome HIGH 8.8
CVE-2024-8637

Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption v…

Fix: 128.0.6613.137+
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-31336

In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper input validation. This could lea…

Mitigation only
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40650

In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of p…

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40652

In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing pe…

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40654

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit…

Patch available
Fix from $1,950 2024-09-11