Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Chrome MEDIUM 6.5
CVE-2026-14156

Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Mcp Toolbox For Databases HIGH 8.1
CVE-2026-11719

An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handle…

Patch available
Fix from $1,950 2026-06-18
Android MEDIUM 5.5
CVE-2026-28573

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of servic…

Mitigation only
Fix from $1,600 2026-06-18
Android HIGH 7.8
CVE-2026-28615

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privi…

Mitigation only
Fix from $1,950 2026-06-17
Android MEDIUM 5.5
CVE-2026-28587

In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lea…

Mitigation only
Fix from $1,600 2026-06-17
Android CRITICAL 10.0
CVE-2026-0092

In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privi…

Mitigation only
Fix from $2,300 2026-06-17
Android HIGH 7.8
CVE-2026-0071

In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2026-06-17
Android HIGH 7.8
CVE-2026-0081

In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no add…

Mitigation only
Fix from $1,950 2026-06-17
Android HIGH 8.0
CVE-2025-48640

In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (pro…

No fix yet
Fix from $1,950 2026-06-17
Android HIGH 7.8
CVE-2025-48617

In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local esca…

Mitigation only
Fix from $1,950 2026-06-17
Android HIGH 7.8
CVE-2026-0133

In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check.…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.8
CVE-2025-26418

In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a manage…

Mitigation only
Fix from $1,950 2026-06-01
Chrome HIGH 7.5
CVE-2026-8547

Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the re…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Android HIGH 7.8
CVE-2026-0026

In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code…

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 7.3
CVE-2025-48634

In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escala…

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 8.4
CVE-2025-48574

In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission che…

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 7.8
CVE-2025-48578

In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission chec…

Mitigation only
Fix from $1,950 2026-03-02
Chrome HIGH 8.8
CVE-2026-0628EPSS 7%

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicio…

Fix: 143.0.7499.192+
Fix from $1,950 2026-01-07
Android MEDIUM 5.5
CVE-2025-48608

In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local in…

Mitigation only
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48599

In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check. …

Patch available
Fix from $1,950 2025-12-08
Android MEDIUM 5.5
CVE-2025-48600

In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information…

Mitigation only
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48604

In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local informatio…

Patch available
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48591

In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local informatio…

Mitigation only
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48575

In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass. This could lead to local es…

Patch available
Fix from $1,950 2025-12-08
Android MEDIUM 6.7
CVE-2025-32319

In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. T…

Patch available
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2024-0028

In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permission check. This could lead to l…

Mitigation only
Fix from $1,600 2025-09-05
Android HIGH 7.8
CVE-2025-22414

In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permission check. This could lead to…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-48549

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escal…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.3
CVE-2025-48547

In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead to local escalation of privil…

No fix yet
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-48524

In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of …

Mitigation only
Fix from $1,600 2025-09-04