Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-44097
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the se…
Nest Doorbell \(battery\) Firmware
1.73c+
HIGH 7.8
CVE-2024-39435
In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional …
Android
No fix yet
HIGH 8.8
CVE-2024-9120
Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a craf…
Chrome
129.0.6668.70+
HIGH 8.8
CVE-2024-9121
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory acce…
Chrome
129.0.6668.70+
HIGH 8.8
CVE-2024-9122EPSS 6%
Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page…
Chrome
129.0.6668.70+
HIGH 8.8
CVE-2024-9123
Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTM…
Chrome
129.0.6668.70+
CRITICAL 9.6
CVE-2024-7024
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a cr…
Chrome
126.0.6478.54+
HIGH 8.8
CVE-2024-7023
Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malici…
Chrome
128.0.6537.0+
HIGH 7.8
CVE-2024-7018
Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PD…
Chrome
124.0.6367.78+
HIGH 8.8
CVE-2021-38023
Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted H…
Chrome
92.0.4515.107+
HIGH 7.8
CVE-2018-20072
Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a cra…
Chrome
73.0.3683.75+
HIGH 7.8
CVE-2024-8375
There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C+…
Reverb
2024-08-05+
HIGH 7.5
CVE-2024-7254
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exce…
Protobuf
3.25.5 / 4.27.5+
HIGH 8.8
CVE-2024-8905
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a cr…
Chrome
129.0.6668.58+
MEDIUM 6.1
CVE-2024-8907
Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage i…
Chrome
129.0.6668.58+
HIGH 8.8
CVE-2024-8904
Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…
Chrome
129.0.6668.58+
MEDIUM 5.3
CVE-2024-22013
U-Boot environment is read from unauthenticated partition.
Nest Wifi Pro Firmware
Mitigation only
HIGH 7.8
CVE-2024-29779
there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional executi…
Android
No fix yet
HIGH 7.8
CVE-2024-44092
There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of pr…
Android
Mitigation only
HIGH 7.8
CVE-2024-44093
In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalati…
Android
Mitigation only
HIGH 7.8
CVE-2024-44094
In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalati…
Android
Mitigation only
HIGH 7.8
CVE-2024-44095
In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation …
Android
Mitigation only
HIGH 8.8
CVE-2024-8638
Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML p…
Chrome
128.0.6613.137+
HIGH 8.8
CVE-2024-8639
Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a…
Chrome
128.0.6613.137+
HIGH 8.8
CVE-2024-8636
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted …
Chrome
128.0.6613.137+
HIGH 8.8
CVE-2024-8637
Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption v…
Chrome
128.0.6613.137+
HIGH 7.8
CVE-2024-31336
In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper input validation. This could lea…
Android
Mitigation only
HIGH 7.8
CVE-2024-40650
In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of p…
Android
Patch available
HIGH 7.8
CVE-2024-40652
In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing pe…
Android
Patch available
HIGH 7.8
CVE-2024-40654
In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit…
Android
Patch available