Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-4096 Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted H… Chrome 136.0.7103.59+ Fix from $1,9502025-05-05 MEDIUM 6.3 CVE-2025-4051 Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific… Chrome 136.0.7103.59+ Fix from $1,6002025-05-05 HIGH 8.8 CVE-2025-4050 Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific … Chrome 136.0.7103.59+ Fix from $1,9502025-05-05 HIGH 7.8 CVE-2025-20668 In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor … Android Mitigation only Fix from $1,9502025-05-05 HIGH 7.0 CVE-2025-20671 In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor ha… Android Mitigation only Fix from $1,9502025-05-05 MEDIUM 5.5 CVE-2025-20665 In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device ide… Android Mitigation only Fix from $1,6002025-05-05 HIGH 8.1 CVE-2025-1290 A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allo… Chrome Os No fix yet Fix from $1,9502025-04-17 HIGH 8.8 CVE-2025-2073 Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an… Chrome Os No fix yet Fix from $1,9502025-04-16 HIGH 8.8 CVE-2025-1568 Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit acc… Chrome Os Mitigation only Fix from $1,9502025-04-16 HIGH 7.5 CVE-2025-1566 DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via fail… Chrome Os Mitigation only Fix from $1,9502025-04-16 MEDIUM 6.5 CVE-2025-1704 ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenrol… Chrome Os No fix yet Fix from $1,6002025-04-16 HIGH 8.8 CVE-2025-3620 Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… Chrome 135.0.7049.95+ Fix from $1,9502025-04-16 HIGH 8.8 CVE-2025-3619 Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption vi… Chrome 135.0.7049.95+ Fix from $1,9502025-04-16 MEDIUM 6.7 CVE-2025-1122 Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persis… Chrome No fix yet Fix from $1,6002025-04-15 MEDIUM 6.7 CVE-2025-1292 Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain pe… Chrome No fix yet Fix from $1,6002025-04-15 MEDIUM 6.7 CVE-2025-20661 In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a maliciou… Android Mitigation only Fix from $1,6002025-04-07 MEDIUM 6.7 CVE-2025-20662 In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a maliciou… Android Mitigation only Fix from $1,6002025-04-07 MEDIUM 6.7 CVE-2025-20657 In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious acto… Android Mitigation only Fix from $1,6002025-04-07 MEDIUM 6.7 CVE-2025-20660 In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a maliciou… Android Mitigation only Fix from $1,6002025-04-07 MEDIUM 6.0 CVE-2025-20658 In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical acce… Android Mitigation only Fix from $1,6002025-04-07 MEDIUM 5.3 CVE-2025-20655 In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious ac… Android Mitigation only Fix from $1,6002025-04-07 HIGH 8.8 CVE-2025-3067 Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to enga… Chrome 135.0.7049.52+ Fix from $1,9502025-04-02 HIGH 8.8 CVE-2025-3068 Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation … Chrome 135.0.7049.52+ Fix from $1,9502025-04-02 HIGH 8.8 CVE-2025-3069 Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a cr… Chrome 135.0.7049.52+ Fix from $1,9502025-04-02 MEDIUM 6.5 CVE-2025-3070 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escal… Chrome 135.0.7049.52+ Fix from $1,6002025-04-02 MEDIUM 5.4 CVE-2025-3071 Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in speci… Chrome 135.0.7049.52+ Fix from $1,6002025-04-02 MEDIUM 5.4 CVE-2025-3072 Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in speci… Chrome 135.0.7049.52+ Fix from $1,6002025-04-02 MEDIUM 5.4 CVE-2025-3073 Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific… Chrome 135.0.7049.52+ Fix from $1,6002025-04-02 MEDIUM 5.4 CVE-2025-3074 Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML… Chrome 135.0.7049.52+ Fix from $1,6002025-04-02 HIGH 8.8 CVE-2025-3066 Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption via a craft… Chrome 135.0.7049.52+ Fix from $1,9502025-04-02