Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.4
CVE-2025-22406
In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to local esca…
Android
Mitigation only
HIGH 7.5
CVE-2025-0093
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to re…
Android
Mitigation only
MEDIUM 6.5
CVE-2025-0092
In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remo…
Android
Mitigation only
MEDIUM 6.2
CVE-2025-0086
In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to loca…
Android
Mitigation only
CRITICAL 9.8
CVE-2025-0074
In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote…
Android
Mitigation only
CRITICAL 9.8
CVE-2025-0075
In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to re…
Android
Mitigation only
HIGH 8.8
CVE-2025-0078
In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to local escalation of privilege wit…
Android
Mitigation only
HIGH 7.8
CVE-2025-0079
In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error in the code. This could lead t…
Android
Mitigation only
HIGH 7.8
CVE-2025-0080
In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack. This could lead to…
Android
Mitigation only
HIGH 7.5
CVE-2025-0081
In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitialized data. This could lead to …
Android
Mitigation only
MEDIUM 5.5
CVE-2025-0082
In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confused deputy.…
Android
Mitigation only
MEDIUM 5.5
CVE-2024-49740
In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execu…
Android
No fix yet
HIGH 8.0
CVE-2023-21125
In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of…
Android
Mitigation only
MEDIUM 6.7
CVE-2025-20698
In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious …
Android
Mitigation only
MEDIUM 6.7
CVE-2025-20697
In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious …
Android
Mitigation only
MEDIUM 6.1
CVE-2025-6044
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a p…
Chrome Os
Mitigation only
CRITICAL 9.8
CVE-2025-6179
Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensi…
Chrome Os
Mitigation only
HIGH 7.4
CVE-2025-6177
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code e…
Chrome Os
Mitigation only
HIGH 8.4
CVE-2025-31710
In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege wit…
Android
Mitigation only
MEDIUM 6.2
CVE-2025-31711
In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional exe…
Android
Mitigation only
MEDIUM 6.2
CVE-2025-31712
In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additiona…
Android
Mitigation only
HIGH 8.4
CVE-2025-27700
There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional …
Android
No fix yet
MEDIUM 5.5
CVE-2025-27701
In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Late…
Android
Mitigation only
MEDIUM 5.1
CVE-2024-56193
There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no addi…
Android
Mitigation only
HIGH 7.8
CVE-2025-2509
Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandbox…
Chrome Os
No fix yet
HIGH 7.8
CVE-2025-20668
In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor …
Android
Mitigation only
HIGH 7.0
CVE-2025-20671
In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor ha…
Android
Mitigation only
MEDIUM 5.5
CVE-2025-20665
In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device ide…
Android
Mitigation only
HIGH 8.1
CVE-2025-1290
A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allo…
Chrome Os
No fix yet
HIGH 8.8
CVE-2025-2073
Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an…
Chrome Os
No fix yet