Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.8 CVE-2025-26450 In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motion events to the default IME d… Android Patch available Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-26445 In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local i… Android Patch available Fix from $1,6002025-09-04 HIGH 7.8 CVE-2025-26440 In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lea… Android Patch available Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-26437 In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permissi… Android Patch available Fix from $1,6002025-09-04 HIGH 7.3 CVE-2025-22439 In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission c… Android Mitigation only Fix from $1,9502025-09-02 MEDIUM 6.2 CVE-2025-0086 In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to loca… Android Mitigation only Fix from $1,6002025-08-26 HIGH 8.4 CVE-2024-40677 In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission … Android Mitigation only Fix from $1,9502025-01-28 MEDIUM 5.5 CVE-2018-9406 In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privi… Android Mitigation only Fix from $1,6002025-01-18 HIGH 7.8 CVE-2018-9382 In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission… Android Mitigation only Fix from $1,9502025-01-17 HIGH 7.8 CVE-2017-13316 In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local es… Android Patch available Fix from $1,9502024-11-27 HIGH 7.8 CVE-2018-9477 In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead … Android Patch available Fix from $1,9502024-11-20 HIGH 7.8 CVE-2018-9469 In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead … Android Patch available Fix from $1,9502024-11-20 HIGH 7.8 CVE-2017-13314 In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul… Android Patch available Fix from $1,9502024-11-15 HIGH 7.8 CVE-2024-43087 In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the access… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43088 In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due … Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43089 In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc… Android Patch available Fix from $1,9502024-11-13 MEDIUM 5.0 CVE-2024-43090 In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure w… Android No fix yet Fix from $1,6002024-11-13 HIGH 7.8 CVE-2024-34719 In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no a… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-40661 In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission chec… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-40671 In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This … Android Mitigation only Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-40650 In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of p… Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40652 In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing pe… Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-31318 In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. … Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31332 In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could … Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-23704 In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check.… Android Patch available Fix from $1,9502024-05-07 MEDIUM 5.5 CVE-2023-52352 In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution pri… Android Mitigation only Fix from $1,6002024-04-08 MEDIUM 6.7 CVE-2024-20032 In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System executi… Android Mitigation only Fix from $1,6002024-03-04 HIGH 7.8 CVE-2024-0038 In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission… Android Patch available Fix from $1,9502024-02-16 MEDIUM 5.5 CVE-2023-40105 In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could le… Android Patch available Fix from $1,6002024-02-15 MEDIUM 5.5 CVE-2023-40113 In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local… Android Patch available Fix from $1,6002024-02-15