Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2022-0609 | Chromium Animation | Google Chromium Animation Use-After-Free Vulnerability Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2022-02-15 | 2022-03-01 | Unknown | |
| CVE-2020-6572 | Chrome Media | Google Chrome Media Use-After-Free Vulnerability Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. | 8.8 CISA | 2022-01-10 | 2022-07-10 | Unknown | |
| CVE-2021-4102 | Chromium V8 | Google Chromium V8 Use-After-Free Vulnerability Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-12-15 | 2021-12-29 | Unknown | |
| CVE-2021-30563 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-21220 | Chromium V8 | Google Chromium V8 Improper Input Validation Vulnerability Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-21193 | Chromium Blink | Google Chromium Blink Use-After-Free Vulnerability Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-21224 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-38003 | Chromium V8 | Google Chromium V8 Memory Corruption Vulnerability Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-38000 | Chromium Intents | Google Chromium Intents Improper Input Validation Vulnerability Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 6.1 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-21206 | Chromium Blink | Google Chromium Blink Use-After-Free Vulnerability Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-30554 | Chromium WebGL | Google Chromium WebGL Use-After-Free Vulnerability Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2020-6418 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown | |
| CVE-2021-37975 | Chromium V8 | Google Chromium V8 Use-After-Free Vulnerability Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-30551 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-37973 | Chromium Portals | Google Chromium Portals Use-After-Free Vulnerability Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge. | 9.6 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-21148 | Chromium V8 | Google Chromium V8 Heap Buffer Overflow Vulnerability Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-30633 | Chromium Indexed DB API | Google Chromium Indexed DB API Use-After-Free Vulnerability Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 9.6 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2020-16013 | Chromium V8 | Google Chromium V8 Incorrect Implementation Vulnerabililty Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown | |
| CVE-2021-30632 | Chromium V8 | Google Chromium V8 Out-of-Bounds Write Vulnerability Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2020-16009 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown | |
| CVE-2021-37976 | Chromium | Google Chromium Information Disclosure Vulnerability Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 6.5 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2020-16017 | Chrome | Google Chrome Use-After-Free Vulnerability Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. | 9.6 CISA | 2021-11-03 | 2022-05-03 | Unknown | |
| CVE-2021-21166 | Chromium | Google Chromium Race Condition Vulnerability Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2020-15999 | Chrome FreeType | Google Chrome FreeType Heap Buffer Overflow Vulnerability Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. | 9.6 CISA | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2020-16010 | Chrome for Android UI | Google Chrome for Android UI Heap Buffer Overflow Vulnerability Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. | 9.6 CISA | 2021-11-03 | 2022-05-03 | Unknown |