Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 8.4
CVE-2026-0034

In setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. This could …

Mitigation only
Fix from $1,950 2026-03-02
Android MEDIUM 6.2
CVE-2026-0015

In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to lo…

Mitigation only
Fix from $1,600 2026-03-02
Android MEDIUM 6.2
CVE-2026-0014

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to…

Mitigation only
Fix from $1,600 2026-03-02
Android MEDIUM 5.5
CVE-2025-48644

In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service …

No fix yet
Fix from $1,600 2026-03-02
Android MEDIUM 6.2
CVE-2025-48585

In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to…

Mitigation only
Fix from $1,600 2026-03-02
Android MEDIUM 6.2
CVE-2025-48587

In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to…

Mitigation only
Fix from $1,600 2026-03-02
Chrome MEDIUM 5.4
CVE-2026-0903

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type …

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $1,600 2026-01-20
Android HIGH 7.8
CVE-2025-48647

In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This coul…

Mitigation only
Fix from $1,950 2026-01-16
Android HIGH 7.8
CVE-2025-36932

In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This …

Mitigation only
Fix from $1,950 2025-12-11
Android MEDIUM 5.5
CVE-2025-36929

In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to local infor…

Mitigation only
Fix from $1,600 2025-12-11
Security Operations Soar HIGH 7.2
CVE-2025-13428

A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote …

Fix: 6.3.64+
Fix from $1,950 2025-12-09
Android HIGH 7.8
CVE-2025-48632

In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due …

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48638

In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48623

In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48624

In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48612

In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to…

Mitigation only
Fix from $1,950 2025-12-08
Android MEDIUM 5.5
CVE-2025-48601

In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalation of privi…

Mitigation only
Fix from $1,600 2025-12-08
Android HIGH 7.3
CVE-2025-48594

In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to im…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48525

In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a compan…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48566

In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead …

Patch available
Fix from $1,950 2025-12-08
Android MEDIUM 6.7
CVE-2025-22432

In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to loc…

Patch available
Fix from $1,600 2025-12-08
Chrome HIGH 8.8
CVE-2025-12907

Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code vi…

Fix: 140.0.7339.80+
Fix from $1,950 2025-11-08
Chrome MEDIUM 5.4
CVE-2025-12908

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domai…

Fix: 140.0.7339.80+
Fix from $1,600 2025-11-08
Android HIGH 7.8
CVE-2025-32322

In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recordi…

Mitigation only
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-48559

In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could lead to l…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.3
CVE-2025-48556

In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper input validation. This could …

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-48541

In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. This coul…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-48538

In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input v…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.1
CVE-2025-48537

In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This could lead to local information …

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32323

In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to…

Patch available
Fix from $1,950 2025-09-04