Vulnerability index

Browse CVEs

28 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.7 CVE-2026-14538 An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1… Mcp Toolbox For Databases after 1.4.0 Fix from $1,9502026-07-31 HIGH 7.8 CVE-2026-0072 In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local … Android Xr Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-5283 Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML… Chrome 146.0.7680.177+ Fix from $1,6002026-04-01 HIGH 7.7 CVE-2026-0017 In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local… Android Mitigation only Fix from $1,9502026-03-02 MEDIUM 5.4 CVE-2025-12435 Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HT… Chrome 142.0.7444.59+ Fix from $1,6002025-11-10 HIGH 7.8 CVE-2025-26430 In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to loca… Android Patch available Fix from $1,9502025-09-04 HIGH 7.5 CVE-2024-3840 Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions… Chrome 124.0.6367.60+ Fix from $1,9502024-04-17 HIGH 7.8 CVE-2023-44123 The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary … Android Mitigation only Fix from $1,9502023-09-27 HIGH 7.8 CVE-2023-44125 The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbit… Android Mitigation only Fix from $1,9502023-09-27 MEDIUM 5.5 CVE-2022-39905 Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via im… Android Mitigation only Fix from $1,6002022-12-08 HIGH 7.8 CVE-2022-39883 Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API. Android Mitigation only Fix from $1,9502022-11-09 MEDIUM 5.5 CVE-2022-36848 Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of… Android Mitigation only Fix from $1,6002022-09-09 MEDIUM 5.5 CVE-2022-33702 Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock… Android Mitigation only Fix from $1,6002022-07-12 CRITICAL 9.8 CVE-2022-30722 Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Ac… Android Mitigation only Fix from $2,3002022-06-07 HIGH 7.5 CVE-2022-30717 Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink. Android Mitigation only Fix from $1,9502022-06-07 MEDIUM 6.1 CVE-2022-22268 Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via S… Android Mitigation only Fix from $1,6002022-01-10 MEDIUM 5.5 CVE-2021-25459 An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZSe… Android Mitigation only Fix from $1,6002021-09-09 MEDIUM 5.5 CVE-2021-25460 An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate Blockchain… Android Mitigation only Fix from $1,6002021-09-09 HIGH 7.5 CVE-2021-25417 Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage. Android Mitigation only Fix from $1,9502021-06-11 MEDIUM 5.5 CVE-2021-25382 An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secur… Android Mitigation only Fix from $1,6002021-04-23 MEDIUM 6.5 CVE-2018-16073 Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a cra… Chrome 69.0.3497.81+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-16074 Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a cra… Chrome 69.0.3497.81+ Fix from $1,6002019-06-27 MEDIUM 6.5 CVE-2018-16077 Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content security policy via a crafted HTML… Chrome 69.0.3497.81+ Fix from $1,6002019-06-27 MEDIUM 5.4 CVE-2018-16086 Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malici… Chrome 69.0.3497.81+ Fix from $1,6002019-06-27 HIGH 7.8 CVE-2014-9945 In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist. Android Patch available Fix from $1,9502017-06-06 HIGH 7.8 CVE-2014-9950 In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist. Android Patch available Fix from $1,9502017-06-06 HIGH 8.8 CVE-2016-1711 WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach o… Chrome after 51.0.2704.106 Fix from $1,9502016-07-23 HIGH 8.8 CVE-2016-1710 The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not … Chrome after 51.0.2704.106 Fix from $1,9502016-07-23