CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48637
7.8 HIGH

In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of …

Dec 8, 2025
CVE-2025-48632
7.8 HIGH

In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input …

Dec 8, 2025
CVE-2025-48629
7.8 HIGH

In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure default value. This could lead …

Dec 8, 2025
CVE-2025-48628
7.8 HIGH

In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused deputy. This could lead to local escalation of privilege with …

Dec 8, 2025
CVE-2025-48627
7.8 HIGH

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch an activity from the background due to a logic error in the code. This …

Dec 8, 2025
CVE-2025-48624
7.8 HIGH

In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with …

Dec 8, 2025
CVE-2025-48623
7.8 HIGH

In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Dec 8, 2025
CVE-2025-48621
7.3 HIGH

In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalation of privilege …

Dec 8, 2025
CVE-2025-48620
7.8 HIGH

In onSomePackagesChanged of VoiceInteractionManagerService.java, there is a possible way for a third party application's component name to persist even after uninstalling due to a logic …

Dec 8, 2025
CVE-2025-48615
7.8 HIGH

In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalation of privilege with no …

Dec 8, 2025
CVE-2025-48612
7.8 HIGH

In multiple locations, there is a possible way for an application on a work profile to set the main user's default NFC payment setting due …

Dec 8, 2025
CVE-2025-48599
7.8 HIGH

In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check. This could lead …

Dec 8, 2025
CVE-2025-48597
7.8 HIGH

In multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to …

Dec 8, 2025
CVE-2025-48596
7.8 HIGH

In appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of …

Dec 8, 2025
CVE-2025-48594
7.3 HIGH

In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to …

Dec 8, 2025
CVE-2025-48592
7.5 HIGH

In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure …

Dec 8, 2025
CVE-2025-48589
7.8 HIGH

In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due to a logic error in the code. This could …

Dec 8, 2025
CVE-2025-48588
7.8 HIGH

In startAlwaysOnVpn of Vpn.java, there is a possible way to disable always-on VPN due to a logic error in the code. This could lead to …

Dec 8, 2025
CVE-2025-48586
7.8 HIGH

In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to a confused deputy. This could lead to …

Dec 8, 2025
CVE-2025-48583
7.8 HIGH

In multiple functions of BaseBundle.java, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead …

Dec 8, 2025
CVE-2025-48580
7.8 HIGH

In connectInternal of MediaBrowser.java, there is a possible way to access while in use permission while the app is in background due to a logic …

Dec 8, 2025
CVE-2025-48575
7.8 HIGH

In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass. This could lead to local escalation of …

Dec 8, 2025
CVE-2025-48573
7.8 HIGH

In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in the background due to FGS while-in-use …

Dec 8, 2025
CVE-2025-48572
7.8 HIGH KEV

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation …

Dec 8, 2025
CVE-2025-48566
7.8 HIGH

In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead to …

Dec 8, 2025
CVE-2025-48565
7.8 HIGH

In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could …

Dec 8, 2025
CVE-2025-48564
7.0 HIGH

In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no …

Dec 8, 2025
CVE-2025-48555
7.8 HIGH

In multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a confused deputy. This could lead to local escalation of privilege …

Dec 8, 2025
CVE-2025-48536
7.8 HIGH

In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settings due to a confused deputy. This could …

Dec 8, 2025
CVE-2025-48525
7.8 HIGH

In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a companion device due to …

Dec 8, 2025
CVE-2025-32329
7.8 HIGH

In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic …

Dec 8, 2025
CVE-2025-32328
7.8 HIGH

In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic …

Dec 8, 2025
CVE-2025-22420
7.8 HIGH

In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This could lead to local …

Dec 8, 2025
CVE-2025-14257
7.3 HIGH

A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /newrecord.php. Executing manipulation of the argument …

Dec 8, 2025
CVE-2025-14256
7.3 HIGH

A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performing manipulation of the argument ID …

Dec 8, 2025
CVE-2025-14251
7.3 HIGH

A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the component Admin …

Dec 8, 2025
CVE-2025-14250
7.3 HIGH

A weakness has been identified in code-projects Online Ordering System 1.0. The impacted element is an unknown function of the file /user_contact.php. This manipulation of …

Dec 8, 2025
CVE-2025-14249
7.3 HIGH

A security flaw has been discovered in code-projects Online Ordering System 1.0. The affected element is an unknown function of the file /user_school.php. The manipulation …

Dec 8, 2025
CVE-2025-14248
7.3 HIGH

A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /adminlogin.php. The manipulation of the argument admin_username …

Dec 8, 2025
CVE-2025-14245
7.3 HIGH

A vulnerability has been found in IdeaCMS up to 1.8. This affects the function whereRaw of the file app/common/logic/index/Coupon.php. Such manipulation of the argument params …

Dec 8, 2025
CVE-2025-14226
7.3 HIGH

A vulnerability was identified in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The manipulation of the argument fname …

Dec 8, 2025
CVE-2025-66328
8.4 HIGH

Multi-thread race condition vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66327
7.1 HIGH

Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 8, 2025
CVE-2025-26488
7.5 HIGH

Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the appliance, thus causing a …

Dec 8, 2025
CVE-2025-26487
8.6 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources using HTTPS requests through the …

Dec 8, 2025
CVE-2025-12956
8.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary …

Dec 8, 2025
CVE-2025-66324
8.4 HIGH

Input verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affect app data integrity.

Dec 8, 2025
CVE-2025-14223
7.3 HIGH

A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /request.php. Such manipulation …

Dec 8, 2025
CVE-2025-14218
7.3 HIGH

A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editotheraccount.php. Performing manipulation …

Dec 8, 2025
CVE-2025-14217
7.3 HIGH

A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the file /edittrns.php. Such manipulation of the argument ID …

Dec 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.