Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-44097 According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the se… Nest Doorbell \(battery\) Firmware 1.73c+ Fix from $2,3002024-10-02 HIGH 7.8 CVE-2024-39435 In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional … Android No fix yet Fix from $1,9502024-09-27 HIGH 8.8 CVE-2024-9120 Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a craf… Chrome 129.0.6668.70+ Fix from $1,9502024-09-25 HIGH 8.8 CVE-2024-9121 Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory acce… Chrome 129.0.6668.70+ Fix from $1,9502024-09-25 HIGH 8.8 CVE-2024-9122EPSS 6% Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page… Chrome 129.0.6668.70+ Fix from $1,9502024-09-25 HIGH 8.8 CVE-2024-9123 Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTM… Chrome 129.0.6668.70+ Fix from $1,9502024-09-25 CRITICAL 9.6 CVE-2024-7024 Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a cr… Chrome 126.0.6478.54+ Fix from $2,3002024-09-23 HIGH 8.8 CVE-2024-7023 Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malici… Chrome 128.0.6537.0+ Fix from $1,9502024-09-23 HIGH 7.8 CVE-2024-7018 Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PD… Chrome 124.0.6367.78+ Fix from $1,9502024-09-23 HIGH 8.8 CVE-2021-38023 Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted H… Chrome 92.0.4515.107+ Fix from $1,9502024-09-23 HIGH 7.8 CVE-2018-20072 Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a cra… Chrome 73.0.3683.75+ Fix from $1,9502024-09-23 HIGH 7.8 CVE-2024-8375 There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C+… Reverb 2024-08-05+ Fix from $1,9502024-09-19 HIGH 7.5 CVE-2024-7254 Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exce… Protobuf 3.25.5 / 4.27.5+ Fix from $1,9502024-09-19 HIGH 8.8 CVE-2024-8905 Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a cr… Chrome 129.0.6668.58+ Fix from $1,9502024-09-17 MEDIUM 6.1 CVE-2024-8907 Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage i… Chrome 129.0.6668.58+ Fix from $1,6002024-09-17 HIGH 8.8 CVE-2024-8904 Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… Chrome 129.0.6668.58+ Fix from $1,9502024-09-17 MEDIUM 5.3 CVE-2024-22013 U-Boot environment is read from unauthenticated partition. Nest Wifi Pro Firmware Mitigation only Fix from $1,6002024-09-16 HIGH 7.8 CVE-2024-29779 there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional executi… Android No fix yet Fix from $1,9502024-09-13 HIGH 7.8 CVE-2024-44092 There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of pr… Android Mitigation only Fix from $1,9502024-09-13 HIGH 7.8 CVE-2024-44093 In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalati… Android Mitigation only Fix from $1,9502024-09-13 HIGH 7.8 CVE-2024-44094 In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalati… Android Mitigation only Fix from $1,9502024-09-13 HIGH 7.8 CVE-2024-44095 In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation … Android Mitigation only Fix from $1,9502024-09-13 HIGH 8.8 CVE-2024-8638 Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML p… Chrome 128.0.6613.137+ Fix from $1,9502024-09-11 HIGH 8.8 CVE-2024-8639 Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a… Chrome 128.0.6613.137+ Fix from $1,9502024-09-11 HIGH 8.8 CVE-2024-8636 Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted … Chrome 128.0.6613.137+ Fix from $1,9502024-09-11 HIGH 8.8 CVE-2024-8637 Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption v… Chrome 128.0.6613.137+ Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-31336 In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper input validation. This could lea… Android Mitigation only Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40650 In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of p… Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40652 In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing pe… Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40654 In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit… Android Patch available Fix from $1,9502024-09-11