Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.8
CVE-2024-3174

Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a …

Fix: 119.0.6045.105+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-3176

Out of bounds write in SwiftShader in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to perform an out of bounds memory write via a c…

Fix: 117.0.5938.62+
Fix from $1,950 2024-07-16
Chrome MEDIUM 6.5
CVE-2024-5500

Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attacker to bypass navigation restrictions via a crafte…

Fix: 122.0.6261.57+
Fix from $1,600 2024-07-16
Chrome MEDIUM 6.3
CVE-2024-3175

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a cr…

Fix: 120.0.6099.62+
Fix from $1,600 2024-07-16
Chrome HIGH 8.8
CVE-2024-3168

Use after free in DevTools in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 122.0.6261.57+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-3169

Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 121.0.6167.139+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-3170

Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 121.0.6167.85+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-3171

Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who convinced a user to engage in specific UI gestu…

Fix: 122.0.6261.57+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-3172

Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific…

Fix: 121.0.6167.85+
Fix from $1,950 2024-07-16
Chrome MEDIUM 6.5
CVE-2024-2884

Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a …

Fix: 121.0.6167.139+
Fix from $1,600 2024-07-16
Chrome CRITICAL 9.6
CVE-2023-4860

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to po…

Fix: 115.0.5790.98+
Fix from $2,300 2024-07-16
Chrome CRITICAL 9.6
CVE-2023-7012

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a mali…

Fix: 117.0.5938.62+
Fix from $2,300 2024-07-16
Chrome HIGH 8.8
CVE-2023-7010

Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 117.0.5938.62+
Fix from $1,950 2024-07-16
Chrome MEDIUM 6.5
CVE-2023-7011

Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Om…

Fix: 119.0.6045.105+
Fix from $1,600 2024-07-16
Chrome CRITICAL 9.6
CVE-2019-25154

Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 77.0.3865.75+
Fix from $2,300 2024-07-16
Chrome MEDIUM 6.5
CVE-2020-36765

Insufficient policy enforcement in Navigation in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafte…

Fix: 85.0.4183.83+
Fix from $1,600 2024-07-16
Chrome CRITICAL 9.6
CVE-2024-6779EPSS 6%

Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a cr…

Fix: 126.0.6478.182+
Fix from $2,300 2024-07-16
Chrome HIGH 8.8
CVE-2024-6775

Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestu…

Fix: 126.0.6478.182+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-6776

Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 126.0.6478.182+
Fix from $1,950 2024-07-16
Chrome HIGH 7.5
CVE-2024-6778

Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts…

Fix: 126.0.6478.182+
Fix from $1,950 2024-07-16
Chrome MEDIUM 6.5
CVE-2024-6777

Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to po…

Fix: 126.0.6478.182+
Fix from $1,600 2024-07-16
Chrome HIGH 8.8
CVE-2024-6772

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a cr…

Fix: 126.0.6478.182+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-6773

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 126.0.6478.182+
Fix from $1,950 2024-07-16
Chrome HIGH 8.8
CVE-2024-6774

Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI ges…

Fix: 126.0.6478.182+
Fix from $1,950 2024-07-16
Android HIGH 8.8
CVE-2024-34722

In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. Th…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31334

In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead …

Mitigation only
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31335

In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to lo…

Mitigation only
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31339

In multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of priv…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-34720

In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, there is a possible method to…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-34723

In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from background due to a logic error i…

Patch available
Fix from $1,950 2024-07-09