Vulnerability index

Browse CVEs

83 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Mcp Toolbox For Databases HIGH 7.7
CVE-2026-14538

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1…

Fix: after 1.4.0
Fix from $1,950 2026-07-31
Mcp Toolbox For Databases CRITICAL 9.8
CVE-2026-14537

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated at…

No fix yet
Fix from $2,300 2026-07-31
Chrome HIGH 8.8
CVE-2026-15125

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox v…

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Android HIGH 7.8
CVE-2025-32348

In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privi…

Mitigation only
Fix from $1,950 2026-06-01
Gerrit MEDIUM 5.3
CVE-2026-2725

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permis…

Patch available
Fix from $1,600 2026-05-13
Cloud Build CRITICAL 9.8
CVE-2026-3136

An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execut…

Fix: 2026-1-26+
Fix from $2,300 2026-03-03
Android HIGH 7.8
CVE-2025-48523

In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could le…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32333

In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to lo…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-26442

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2025-26436

In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due t…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-22428

In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the pr…

Mitigation only
Fix from $1,950 2025-09-02
Android HIGH 7.8
CVE-2018-9374

In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User…

Patch available
Fix from $1,950 2024-11-28
Android HIGH 7.8
CVE-2023-21270

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to …

Patch available
Fix from $1,950 2024-11-19
Android MEDIUM 5.5
CVE-2024-47025

In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information di…

Mitigation only
Fix from $1,600 2024-10-25
Android MEDIUM 5.5
CVE-2024-44099

There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additi…

No fix yet
Fix from $1,600 2024-10-25
Android HIGH 7.8
CVE-2024-0043

In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. This c…

Patch available
Fix from $1,950 2024-05-07
Android MEDIUM 5.5
CVE-2024-0017

In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local informatio…

Patch available
Fix from $1,600 2024-02-16
Android HIGH 7.8
CVE-2023-21390

In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege …

Fix: 14.0+
Fix from $1,950 2023-10-30
Android MEDIUM 5.5
CVE-2023-21311

In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local info…

Fix: 14.0+
Fix from $1,600 2023-10-30
Android HIGH 7.8
CVE-2023-40117

In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalati…

Patch available
Fix from $1,950 2023-10-27
Android HIGH 7.8
CVE-2023-21254

In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a …

Patch available
Fix from $1,950 2023-07-13
Android HIGH 7.8
CVE-2023-21256

In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could le…

Patch available
Fix from $1,950 2023-07-13
Android HIGH 7.8
CVE-2023-21245

In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup …

Patch available
Fix from $1,950 2023-07-13
Android HIGH 7.8
CVE-2023-21225

there is a possible way to bypass the protected confirmation screen due to Failure to lock display power. This could lead to local escalation of priv…

Mitigation only
Fix from $1,950 2023-06-28
Android HIGH 7.8
CVE-2023-21117

In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to…

Patch available
Fix from $1,950 2023-05-15
Android MEDIUM 6.7
CVE-2023-21116

In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logi…

Patch available
Fix from $1,600 2023-05-15
Web Stories MEDIUM 6.5
CVE-2023-1979

The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password. The content is then only ac…

Fix: 1.32.0+
Fix from $1,600 2023-05-08
Android HIGH 7.8
CVE-2023-20950

In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. …

Patch available
Fix from $1,950 2023-04-19
Android HIGH 7.8
CVE-2023-21034

In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local …

Patch available
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-21035

In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same pac…

Patch available
Fix from $1,950 2023-03-24