Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2026-14156 Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 HIGH 8.1 CVE-2026-11719 An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handle… Mcp Toolbox For Databases Patch available Fix from $1,9502026-06-18 MEDIUM 5.5 CVE-2026-28573 In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of servic… Android Mitigation only Fix from $1,6002026-06-18 HIGH 7.8 CVE-2026-28615 In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privi… Android Mitigation only Fix from $1,9502026-06-17 MEDIUM 5.5 CVE-2026-28587 In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lea… Android Mitigation only Fix from $1,6002026-06-17 CRITICAL 10.0 CVE-2026-0092 In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privi… Android Mitigation only Fix from $2,3002026-06-17 HIGH 7.8 CVE-2026-0071 In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,9502026-06-17 HIGH 7.8 CVE-2026-0081 In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no add… Android Mitigation only Fix from $1,9502026-06-17 HIGH 8.0 CVE-2025-48640 In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (pro… Android No fix yet Fix from $1,9502026-06-17 HIGH 7.8 CVE-2025-48617 In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local esca… Android Mitigation only Fix from $1,9502026-06-17 HIGH 7.8 CVE-2026-0133 In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check.… Android Mitigation only Fix from $1,9502026-06-16 HIGH 7.8 CVE-2025-26418 In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a manage… Android Mitigation only Fix from $1,9502026-06-01 HIGH 7.5 CVE-2026-8547 Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the re… Chrome 148.0.7778.168+ Fix from $1,9502026-05-14 HIGH 7.8 CVE-2026-0026 In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code… Android Mitigation only Fix from $1,9502026-03-02 HIGH 7.3 CVE-2025-48634 In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escala… Android Mitigation only Fix from $1,9502026-03-02 HIGH 8.4 CVE-2025-48574 In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission che… Android Mitigation only Fix from $1,9502026-03-02 HIGH 7.8 CVE-2025-48578 In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission chec… Android Mitigation only Fix from $1,9502026-03-02 HIGH 8.8 CVE-2026-0628EPSS 7% Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicio… Chrome 143.0.7499.192+ Fix from $1,9502026-01-07 MEDIUM 5.5 CVE-2025-48608 In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local in… Android Mitigation only Fix from $1,6002025-12-08 HIGH 7.8 CVE-2025-48599 In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check. … Android Patch available Fix from $1,9502025-12-08 MEDIUM 5.5 CVE-2025-48600 In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information… Android Mitigation only Fix from $1,6002025-12-08 MEDIUM 5.5 CVE-2025-48604 In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local informatio… Android Patch available Fix from $1,6002025-12-08 MEDIUM 5.5 CVE-2025-48591 In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local informatio… Android Mitigation only Fix from $1,6002025-12-08 HIGH 7.8 CVE-2025-48575 In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass. This could lead to local es… Android Patch available Fix from $1,9502025-12-08 MEDIUM 6.7 CVE-2025-32319 In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. T… Android Patch available Fix from $1,6002025-12-08 MEDIUM 5.5 CVE-2024-0028 In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permission check. This could lead to l… Android Mitigation only Fix from $1,6002025-09-05 HIGH 7.8 CVE-2025-22414 In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permission check. This could lead to… Android Mitigation only Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-48549 In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escal… Android Patch available Fix from $1,9502025-09-04 HIGH 7.3 CVE-2025-48547 In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead to local escalation of privil… Android No fix yet Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-48524 In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of … Android Mitigation only Fix from $1,6002025-09-04