Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2025-36918

In aoc_service_read_message of aoc_ipc_core.c, there is a possible out of bounds read due to improper input validation. This could lead to local esca…

Mitigation only
Fix from $1,950 2025-12-11
Android HIGH 7.8
CVE-2025-36919

In aocc_read of aoc_channel_dev.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege with no …

Mitigation only
Fix from $1,950 2025-12-11
Android HIGH 7.0
CVE-2025-36916

In PrepareWorkloadBuffers of gxp_main_actor.cc, there is a possible double fetch due to a race condition. This could lead to local escalation of priv…

Mitigation only
Fix from $1,950 2025-12-11
Android MEDIUM 6.7
CVE-2025-36922

In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege in…

Mitigation only
Fix from $1,600 2025-12-11
Android MEDIUM 6.5
CVE-2025-36912

In cellular modem, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additi…

Mitigation only
Fix from $1,600 2025-12-11
Android MEDIUM 6.5
CVE-2025-36917

In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrect bounds check. This could lead to remote denial …

No fix yet
Fix from $1,600 2025-12-11
Android MEDIUM 5.5
CVE-2025-36921

In ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local…

Mitigation only
Fix from $1,600 2025-12-11
Android MEDIUM 5.5
CVE-2025-36889

In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclos…

Mitigation only
Fix from $1,600 2025-12-11
Security Operations Soar HIGH 7.2
CVE-2025-13428

A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote …

Fix: 6.3.64+
Fix from $1,950 2025-12-09
Android HIGH 7.8
CVE-2025-48606

In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation without a mechanism to uninstal…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.0
CVE-2025-48625

In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen is off due to a race conditio…

Mitigation only
Fix from $1,950 2025-12-08
Android MEDIUM 5.5
CVE-2025-48569

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no…

No fix yet
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48608

In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local in…

Mitigation only
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48627

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch an activity from the background due to a logic err…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48628

In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused deputy. This could lead to local…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48629

In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48632

In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due …

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48637

In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48638

In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.3
CVE-2025-48639

In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. This could l…

Mitigation only
Fix from $1,950 2025-12-08
Android MEDIUM 6.5
CVE-2025-48631

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote…

Mitigation only
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48633 KEV

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in …

Patch available
Fix from $1,600 2025-12-08
Android CRITICAL 9.8
CVE-2025-48626

In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to r…

Patch available
Fix from $2,300 2025-12-08
Android HIGH 7.8
CVE-2025-48615

In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48620

In onSomePackagesChanged of VoiceInteractionManagerService.java, there is a possible way for a third party application's component name to persist ev…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48623

In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2025-12-08
Android HIGH 7.8
CVE-2025-48624

In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.3
CVE-2025-48621

In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalatio…

Patch available
Fix from $1,950 2025-12-08
Android MEDIUM 6.8
CVE-2025-48618

In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. This could…

Patch available
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48622

In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclos…

Patch available
Fix from $1,600 2025-12-08