Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android HIGH 7.8
CVE-2025-26450

In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motion events to the default IME d…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-26445

In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local i…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2025-26440

In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lea…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-26437

In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permissi…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.3
CVE-2025-22439

In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission c…

Mitigation only
Fix from $1,950 2025-09-02
Android MEDIUM 6.2
CVE-2025-0086

In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to loca…

Mitigation only
Fix from $1,600 2025-08-26
Android HIGH 8.4
CVE-2024-40677

In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission …

Mitigation only
Fix from $1,950 2025-01-28
Android MEDIUM 5.5
CVE-2018-9406

In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privi…

Mitigation only
Fix from $1,600 2025-01-18
Android HIGH 7.8
CVE-2018-9382

In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission…

Mitigation only
Fix from $1,950 2025-01-17
Android HIGH 7.8
CVE-2017-13316

In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local es…

Patch available
Fix from $1,950 2024-11-27
Android HIGH 7.8
CVE-2018-9477

In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead …

Patch available
Fix from $1,950 2024-11-20
Android HIGH 7.8
CVE-2018-9469

In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead …

Patch available
Fix from $1,950 2024-11-20
Android HIGH 7.8
CVE-2017-13314

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul…

Patch available
Fix from $1,950 2024-11-15
Android HIGH 7.8
CVE-2024-43087

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the access…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43088

In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due …

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43089

In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc…

Patch available
Fix from $1,950 2024-11-13
Android MEDIUM 5.0
CVE-2024-43090

In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure w…

No fix yet
Fix from $1,600 2024-11-13
Android HIGH 7.8
CVE-2024-34719

In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no a…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-40661

In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission chec…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-40671

In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This …

Mitigation only
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-40650

In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of p…

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40652

In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing pe…

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-31318

In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. …

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31332

In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could …

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-23704

In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check.…

Patch available
Fix from $1,950 2024-05-07
Android MEDIUM 5.5
CVE-2023-52352

In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution pri…

Mitigation only
Fix from $1,600 2024-04-08
Android MEDIUM 6.7
CVE-2024-20032

In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System executi…

Mitigation only
Fix from $1,600 2024-03-04
Android HIGH 7.8
CVE-2024-0038

In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission…

Patch available
Fix from $1,950 2024-02-16
Android MEDIUM 5.5
CVE-2023-40105

In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could le…

Patch available
Fix from $1,600 2024-02-15
Android MEDIUM 5.5
CVE-2023-40113

In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local…

Patch available
Fix from $1,600 2024-02-15