Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-6179
Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensi…
Chrome Os
Mitigation only
HIGH 7.4
CVE-2025-6177
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code e…
Chrome Os
Mitigation only
MEDIUM 5.3
CVE-2025-4565
Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recur…
Protobuf Python
4.25.8 / 5.29.5+
HIGH 8.8
CVE-2025-4613
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b…
Web Designer
16.3.0.0407+
HIGH 8.8
CVE-2025-5959EPSS 12%
Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…
Chrome
137.0.7151.103+
HIGH 8.8
CVE-2025-5958
Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …
Chrome
137.0.7151.103+
HIGH 8.4
CVE-2025-31710
In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege wit…
Android
Mitigation only
MEDIUM 6.2
CVE-2025-31711
In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional exe…
Android
Mitigation only
MEDIUM 6.2
CVE-2025-31712
In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additiona…
Android
Mitigation only
HIGH 8.8
CVE-2025-5419 KEVEPSS 8%
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a cra…
Chrome
137.0.3296.62 / 137.0.7151.68+
HIGH 8.8
CVE-2025-5068
Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…
Chrome
137.0.7151.68+
HIGH 8.8
CVE-2025-5280
Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…
Chrome
137.0.7151.55+
MEDIUM 5.4
CVE-2025-5281
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via …
Chrome
137.0.7151.55+
MEDIUM 5.4
CVE-2025-5283
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …
Chrome
137.0.7151.55+
HIGH 8.8
CVE-2025-5063
Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted …
Chrome
137.0.7151.55+
MEDIUM 6.5
CVE-2025-5065
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a c…
Chrome
137.0.7151.55+
MEDIUM 6.5
CVE-2025-5066
Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage …
Chrome
137.0.7151.55+
MEDIUM 5.4
CVE-2025-5064
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via …
Chrome
137.0.7151.55+
MEDIUM 5.4
CVE-2025-5067
Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML…
Chrome
137.0.7151.55+
HIGH 8.4
CVE-2025-27700
There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional …
Android
No fix yet
MEDIUM 5.5
CVE-2025-27701
In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Late…
Android
Mitigation only
MEDIUM 5.1
CVE-2024-56193
There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no addi…
Android
Mitigation only
HIGH 7.5
CVE-2025-4600
A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requ…
Application Load Balancer
2025-04-26+
HIGH 7.8
CVE-2025-1079
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
Web Designer
16.2.0.0128+
HIGH 7.8
CVE-2025-20979
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.
Android
15.0+
MEDIUM 5.5
CVE-2025-20980
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.
Android
15.0+
HIGH 8.8
CVE-2025-4372
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…
Chrome
136.0.7103.92+
HIGH 7.5
CVE-2025-0649
Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to serve…
Tensorflow Serving
after 2.18.0
HIGH 7.8
CVE-2025-2509
Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandbox…
Chrome Os
No fix yet
CRITICAL 9.8
CVE-2025-4052
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific…
Chrome
136.0.7103.59+