Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.4 CVE-2026-0034 In setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. This could … Android Mitigation only Fix from $1,9502026-03-02 MEDIUM 6.2 CVE-2026-0015 In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to lo… Android Mitigation only Fix from $1,6002026-03-02 MEDIUM 6.2 CVE-2026-0014 In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to… Android Mitigation only Fix from $1,6002026-03-02 MEDIUM 5.5 CVE-2025-48644 In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service … Android No fix yet Fix from $1,6002026-03-02 MEDIUM 6.2 CVE-2025-48585 In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to… Android Mitigation only Fix from $1,6002026-03-02 MEDIUM 6.2 CVE-2025-48587 In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to… Android Mitigation only Fix from $1,6002026-03-02 MEDIUM 5.4 CVE-2026-0903 Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type … Chrome 144.0.7559.59 / 144.0.7559.60+ Fix from $1,6002026-01-20 HIGH 7.8 CVE-2025-48647 In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This coul… Android Mitigation only Fix from $1,9502026-01-16 HIGH 7.8 CVE-2025-36932 In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This … Android Mitigation only Fix from $1,9502025-12-11 MEDIUM 5.5 CVE-2025-36929 In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to local infor… Android Mitigation only Fix from $1,6002025-12-11 HIGH 7.2 CVE-2025-13428 A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote … Security Operations Soar 6.3.64+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-48632 In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due … Android Patch available Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48638 In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of p… Android Mitigation only Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48623 In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of pri… Android Patch available Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48624 In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation… Android Mitigation only Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48612 In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to… Android Mitigation only Fix from $1,9502025-12-08 MEDIUM 5.5 CVE-2025-48601 In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalation of privi… Android Mitigation only Fix from $1,6002025-12-08 HIGH 7.3 CVE-2025-48594 In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to im… Android Patch available Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48525 In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a compan… Android Patch available Fix from $1,9502025-12-08 HIGH 7.8 CVE-2025-48566 In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead … Android Patch available Fix from $1,9502025-12-08 MEDIUM 6.7 CVE-2025-22432 In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to loc… Android Patch available Fix from $1,6002025-12-08 HIGH 8.8 CVE-2025-12907 Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code vi… Chrome 140.0.7339.80+ Fix from $1,9502025-11-08 MEDIUM 5.4 CVE-2025-12908 Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domai… Chrome 140.0.7339.80+ Fix from $1,6002025-11-08 HIGH 7.8 CVE-2025-32322 In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recordi… Android Mitigation only Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-48559 In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could lead to l… Android Patch available Fix from $1,6002025-09-04 HIGH 7.3 CVE-2025-48556 In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper input validation. This could … Android Patch available Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-48541 In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. This coul… Android Patch available Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-48538 In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input v… Android Patch available Fix from $1,6002025-09-04 HIGH 7.1 CVE-2025-48537 In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This could lead to local information … Android Patch available Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-32323 In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to… Android Patch available Fix from $1,9502025-09-04