Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Android MEDIUM 5.5
CVE-2026-28576

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure w…

Mitigation only
Fix from $1,600 2026-06-17
Android MEDIUM 5.9
CVE-2026-0075

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privile…

Mitigation only
Fix from $1,600 2026-06-01
Android HIGH 8.4
CVE-2025-48650

In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege with no addi…

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 7.8
CVE-2025-48544

In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could lead to local escalation of pri…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32327

In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This could lead to local escalation …

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2023-35683

In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injection. This could lead to loca…

Patch available
Fix from $1,600 2023-09-11
Android MEDIUM 5.5
CVE-2022-42535

In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclos…

Patch available
Fix from $1,600 2022-12-16
Android MEDIUM 5.5
CVE-2022-20517

In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local in…

Patch available
Fix from $1,600 2022-12-16
Android MEDIUM 5.5
CVE-2022-20518

In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosur…

Patch available
Fix from $1,600 2022-12-16
Android MEDIUM 5.5
CVE-2022-20351

In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local informat…

Patch available
Fix from $1,600 2022-10-11
Android MEDIUM 6.5
CVE-2021-25427

SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information

Mitigation only
Fix from $1,600 2021-07-08
Android MEDIUM 5.5
CVE-2020-0344

In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional exe…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 5.5
CVE-2020-0352

In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional exe…

Mitigation only
Fix from $1,600 2020-09-17
Android HIGH 8.1
CVE-2019-20613

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-based SQL injection in Contacts. The Samsung ID is S…

Mitigation only
Fix from $1,950 2020-03-24
Android HIGH 7.8
CVE-2019-20591

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Gear VR Service Conte…

Mitigation only
Fix from $1,950 2020-03-24
Android HIGH 7.8
CVE-2019-20592

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Story Video Editor Co…

Mitigation only
Fix from $1,950 2020-03-24
Android CRITICAL 9.8
CVE-2019-20576

An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-…

Mitigation only
Fix from $2,300 2020-03-24
Android HIGH 7.8
CVE-2019-20574

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Wi-Fi history Content…

Mitigation only
Fix from $1,950 2020-03-24
Android HIGH 7.8
CVE-2019-20573

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the RCS Content Provider.…

Mitigation only
Fix from $1,950 2020-03-24
Android HIGH 7.5
CVE-2019-2211

In createProjectionMapForQuery of TvProvider.java, there is possible SQL injection. This could lead to local information disclosure with no additiona…

Mitigation only
Fix from $1,950 2019-11-13
Android HIGH 7.8
CVE-2019-2195

In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to loc…

Mitigation only
Fix from $1,950 2019-11-13
Android MEDIUM 5.5
CVE-2019-2196

In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed…

Mitigation only
Fix from $1,600 2019-11-13
Android MEDIUM 5.5
CVE-2019-2198

In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution p…

Mitigation only
Fix from $1,600 2019-11-13
Android MEDIUM 5.5
CVE-2018-9493

In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local informa…

Patch available
Fix from $1,600 2018-10-02
Android CRITICAL 9.8
CVE-2018-14066

The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One …

No fix yet
Fix from $2,300 2018-07-15
Android CRITICAL 9.8
CVE-2014-4959

**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands …

No fix yet
Fix from $2,300 2018-03-27
Android HIGH 7.5
CVE-2014-8507

Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPu…

Fix: after 4.4.4
Fix from $1,950 2014-12-15