Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2025-32349

In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of privilege …

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32350

In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to a tapjacking/overlay attack.…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-48522

In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code. This cou…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32325

In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege …

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32326

In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a confused deputy. This could …

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32327

In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This could lead to local escalation …

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32331

In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This could lead t…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32332

In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additi…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32333

In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to lo…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.7
CVE-2025-32330

In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure defaul…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2025-26454

In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. …

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-26464

In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. This could le…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32321

In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32323

In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32324

In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local es…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-0089

In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.3
CVE-2025-22441

In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary java code in a privileged conte…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2024-49714

In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-26462

In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to local esc…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32312

In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-26463

In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a local persiste…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2025-26452

In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a confused deputy. This could l…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-26455

In multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalatio…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-26458

In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic error in the code. This could le…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-26453

In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. This could l…

Patch available
Fix from $1,600 2025-09-04
Android MEDIUM 5.5
CVE-2025-26456

In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server due to a logic error in the code. This could lead to…

Mitigation only
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2025-26450

In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motion events to the default IME d…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-26445

In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local i…

Patch available
Fix from $1,600 2025-09-04
Android MEDIUM 5.5
CVE-2025-26448

In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosu…

Patch available
Fix from $1,600 2025-09-04
Android MEDIUM 5.5
CVE-2025-26449

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no…

Patch available
Fix from $1,600 2025-09-04