Vulnerability index

Browse CVEs

90 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.8
CVE-2026-11645 KEV

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Android HIGH 8.4
CVE-2025-48595 KEV

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege…

Mitigation only
Fix from $1,950 2026-06-01
Chrome HIGH 8.8
CVE-2026-5281 KEV

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitra…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome HIGH 8.8
CVE-2026-3909 KEV

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HT…

Fix: 146.0.7680.80+
Fix from $1,950 2026-03-13
Chrome HIGH 8.8
CVE-2026-3910 KEV

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 146.0.7680.75+
Fix from $1,950 2026-03-13
Chrome HIGH 8.8
CVE-2026-2441 KEVEPSS 22%

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 145.0.7632.75 / 145.0.7632.76+
Fix from $1,950 2026-02-13
Chrome HIGH 8.8
CVE-2025-14174 KEVEPSS 23%

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access…

Fix: 18.7.3 / 26.2+
Fix from $1,950 2025-12-12
Android MEDIUM 5.5
CVE-2025-48633 KEV

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in …

Patch available
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48572 KEV

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalat…

Mitigation only
Fix from $1,950 2025-12-08
Chrome HIGH 8.8
CVE-2025-13223 KEVEPSS 5%

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 142.0.7444.175+
Fix from $1,950 2025-11-17
Chrome CRITICAL 9.8
CVE-2025-10585 KEVEPSS 5%

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 140.0.7339.185+
Fix from $2,300 2025-09-24
Android HIGH 8.8
CVE-2025-48543 KEV

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to l…

Patch available
Fix from $1,950 2025-09-04
Chrome HIGH 8.8
CVE-2025-6558 KEVEPSS 9%

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform…

Fix: 2.6 / 11.6+
Fix from $1,950 2025-07-15
Chrome HIGH 8.1
CVE-2025-6554 KEVEPSS 13%

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chro…

Fix: 138.0.7204.92 / 138.0.7204.96+
Fix from $1,950 2025-06-30
Chrome HIGH 8.8
CVE-2025-5419 KEVEPSS 8%

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 137.0.3296.62 / 137.0.7151.68+
Fix from $1,950 2025-06-03
Chrome HIGH 8.3
CVE-2025-2783 KEVEPSS 8%

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perfo…

Fix: 134.0.6998.177+
Fix from $1,950 2025-03-26
Android HIGH 7.3
CVE-2024-43093 KEV

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive direc…

Patch available
Fix from $1,950 2024-11-13
Chrome CRITICAL 9.6
CVE-2024-7971 KEVEPSS 21%

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium …

Fix: 128.0.2739.42 / 128.0.6613.84+
Fix from $2,300 2024-08-21
Chrome HIGH 8.8
CVE-2024-7965 KEVEPSS 19%

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 128.0.2739.42 / 128.0.6613.84+
Fix from $1,950 2024-08-21
Android HIGH 7.8
CVE-2024-32896 KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr…

No fix yet
Fix from $1,950 2024-06-13
Chrome CRITICAL 9.6
CVE-2024-5274 KEVEPSS 7%

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 125.0.6422.112+
Fix from $2,300 2024-05-28
Chrome CRITICAL 9.6
CVE-2024-4947 KEVEPSS 15%

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 125.0.6422.60+
Fix from $2,300 2024-05-15
Chrome HIGH 8.8
CVE-2024-4761 KEVEPSS 11%

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted H…

Fix: 124.0.6367.207+
Fix from $1,950 2024-05-14
Chrome CRITICAL 9.6
CVE-2024-4671 KEVEPSS 8%

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 124.0.6367.201+
Fix from $2,300 2024-05-14
Android HIGH 7.8
CVE-2024-29748 KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr…

Fix: 2024-04-05+
Fix from $1,950 2024-04-05
Android MEDIUM 5.5
CVE-2024-29745 KEV

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution pr…

Mitigation only
Fix from $1,600 2024-04-05
Chrome HIGH 8.8
CVE-2024-0519 KEV

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 7.2.5 / 120.0.6099.224+
Fix from $1,950 2024-01-16
Chrome HIGH 8.8
CVE-2023-7024 KEVEPSS 7%

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 120.0.6099.129+
Fix from $1,950 2023-12-21
Chrome CRITICAL 9.6
CVE-2023-6345 KEVEPSS 16%

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially p…

Fix: 119.0.2151.97 / 119.0.6045.199+
Fix from $2,300 2023-11-29
Chrome HIGH 8.8
CVE-2023-4863 KEVEPSS 100%

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memo…

Fix: 1.0.62681.0 / 1.6.00.26463+
Fix from $1,950 2023-09-12