Vulnerability index

Browse CVEs

28 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Mcp Toolbox For Databases HIGH 7.7
CVE-2026-14538

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1…

Fix: after 1.4.0
Fix from $1,950 2026-07-31
Android Xr HIGH 7.8
CVE-2026-0072

In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local …

Mitigation only
Fix from $1,950 2026-06-01
Chrome MEDIUM 6.5
CVE-2026-5283

Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML…

Fix: 146.0.7680.177+
Fix from $1,600 2026-04-01
Android HIGH 7.7
CVE-2026-0017

In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local…

Mitigation only
Fix from $1,950 2026-03-02
Chrome MEDIUM 5.4
CVE-2025-12435

Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HT…

Fix: 142.0.7444.59+
Fix from $1,600 2025-11-10
Android HIGH 7.8
CVE-2025-26430

In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to loca…

Patch available
Fix from $1,950 2025-09-04
Chrome HIGH 7.5
CVE-2024-3840

Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions…

Fix: 124.0.6367.60+
Fix from $1,950 2024-04-17
Android HIGH 7.8
CVE-2023-44123

The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary …

Mitigation only
Fix from $1,950 2023-09-27
Android HIGH 7.8
CVE-2023-44125

The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbit…

Mitigation only
Fix from $1,950 2023-09-27
Android MEDIUM 5.5
CVE-2022-39905

Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via im…

Mitigation only
Fix from $1,600 2022-12-08
Android HIGH 7.8
CVE-2022-39883

Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.

Mitigation only
Fix from $1,950 2022-11-09
Android MEDIUM 5.5
CVE-2022-36848

Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of…

Mitigation only
Fix from $1,600 2022-09-09
Android MEDIUM 5.5
CVE-2022-33702

Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock…

Mitigation only
Fix from $1,600 2022-07-12
Android CRITICAL 9.8
CVE-2022-30722

Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Ac…

Mitigation only
Fix from $2,300 2022-06-07
Android HIGH 7.5
CVE-2022-30717

Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.

Mitigation only
Fix from $1,950 2022-06-07
Android MEDIUM 6.1
CVE-2022-22268

Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via S…

Mitigation only
Fix from $1,600 2022-01-10
Android MEDIUM 5.5
CVE-2021-25459

An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZSe…

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25460

An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate Blockchain…

Mitigation only
Fix from $1,600 2021-09-09
Android HIGH 7.5
CVE-2021-25417

Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.

Mitigation only
Fix from $1,950 2021-06-11
Android MEDIUM 5.5
CVE-2021-25382

An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secur…

Mitigation only
Fix from $1,600 2021-04-23
Chrome MEDIUM 6.5
CVE-2018-16073

Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a cra…

Fix: 69.0.3497.81+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-16074

Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a cra…

Fix: 69.0.3497.81+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-16077

Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content security policy via a crafted HTML…

Fix: 69.0.3497.81+
Fix from $1,600 2019-06-27
Chrome MEDIUM 5.4
CVE-2018-16086

Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malici…

Fix: 69.0.3497.81+
Fix from $1,600 2019-06-27
Android HIGH 7.8
CVE-2014-9945

In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Android HIGH 7.8
CVE-2014-9950

In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Chrome HIGH 8.8
CVE-2016-1711

WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach o…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Chrome HIGH 8.8
CVE-2016-1710

The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not …

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23