CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-26450
7.8 HIGH

In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motion events to the default IME due to …

Sep 4, 2025
CVE-2025-26449
5.5 MEDIUM

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no …

Sep 4, 2025
CVE-2025-26448
5.5 MEDIUM

In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no …

Sep 4, 2025
CVE-2025-26445
5.5 MEDIUM

In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local information disclosure …

Sep 4, 2025
CVE-2025-26444
7.8 HIGH

In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the default assistant application when a user-selected assistant …

Sep 4, 2025
CVE-2025-26443
7.3 HIGH

In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the …

Sep 4, 2025
CVE-2025-26442
5.5 MEDIUM

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic error in the code. This …

Sep 4, 2025
CVE-2025-26441
6.5 MEDIUM

In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Sep 4, 2025
CVE-2025-26440
7.8 HIGH

In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lead …

Sep 4, 2025
CVE-2025-26438
8.8 HIGH

In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. This could lead to remote …

Sep 4, 2025
CVE-2025-26437
5.5 MEDIUM

In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permission check. This could lead to local information …

Sep 4, 2025
CVE-2025-26436
7.8 HIGH

In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could …

Sep 4, 2025
CVE-2025-26435
7.8 HIGH

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a …

Sep 4, 2025
CVE-2025-26432
5.5 MEDIUM

In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denial …

Sep 4, 2025
CVE-2025-26430
7.8 HIGH

In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation …

Sep 4, 2025
CVE-2025-26429
5.5 MEDIUM

In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of …

Sep 4, 2025
CVE-2025-26428
3.2 LOW

In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation …

Sep 4, 2025
CVE-2025-26427
4.4 MEDIUM

In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no …

Sep 4, 2025
CVE-2025-26426
5.1 MEDIUM

In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead …

Sep 4, 2025
CVE-2025-26425
4.0 MEDIUM

In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local …

Sep 4, 2025
CVE-2025-26424
4.0 MEDIUM

In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local …

Sep 4, 2025
CVE-2025-26423
6.2 MEDIUM

In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. This could lead to local …

Sep 4, 2025
CVE-2025-26422
4.0 MEDIUM

In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead …

Sep 4, 2025
CVE-2025-26421
4.0 MEDIUM

In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-26420
4.4 MEDIUM

In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This …

Sep 4, 2025
CVE-2025-22425
5.1 MEDIUM

In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no …

Sep 4, 2025
CVE-2025-0087
5.1 MEDIUM

In onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app due to a missing permission check. This could lead to …

Sep 4, 2025
CVE-2025-0077
4.0 MEDIUM

In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege …

Sep 4, 2025
CVE-2024-49739
4.0 MEDIUM

In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Sep 4, 2025
CVE-2023-35657
4.0 MEDIUM

In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no …

Sep 4, 2025
CVE-2025-9636
7.9 HIGH

pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to …

Sep 4, 2025
CVE-2025-57576
5.4 MEDIUM

PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.

Sep 4, 2025
CVE-2025-38730
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring/net: commit partial buffers on retry Ring provided buffers are potentially only valid within the …

Sep 4, 2025
CVE-2025-38729
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be …

Sep 4, 2025
CVE-2025-38728
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb3: fix for slab out of bounds on mount to ksmbd With KASAN enabled, it …

Sep 4, 2025
CVE-2025-38727
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netlink: avoid infinite retry looping in netlink_unicast() netlink_attachskb() checks for the socket's read memory allocation …

Sep 4, 2025
CVE-2025-38726
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ftgmac100: fix potential NULL pointer access in ftgmac100_phy_disconnect After the call to phy_disconnect() netdev->phydev …

Sep 4, 2025
CVE-2025-38725
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio …

Sep 4, 2025
CVE-2025-38724
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check …

Sep 4, 2025
CVE-2025-38723
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix jump offset calculation in tailcall The extra pass of bpf_int_jit_compile() skips JIT …

Sep 4, 2025
CVE-2025-38722
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: habanalabs: fix UAF in export_dmabuf() As soon as we'd inserted a file reference into descriptor …

Sep 4, 2025
CVE-2025-38721
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix refcount leak on table dump There is a reference count leak in …

Sep 4, 2025
CVE-2025-38720
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hibmcge: fix rtnl deadlock issue Currently, the hibmcge netdev acquires the rtnl_lock in pci_error_handlers.reset_prepare() …

Sep 4, 2025
CVE-2025-38719
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hibmcge: fix the division by zero issue When the network port is down, the …

Sep 4, 2025
CVE-2025-38718
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso packets in sctp_rcv A cloned head skb still shares these frag …

Sep 4, 2025
CVE-2025-38717
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: kcm: Fix race condition in kcm_unattach() syzbot found a race condition when kcm_unattach(psock) and …

Sep 4, 2025
CVE-2025-38716
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hfs: fix general protection fault in hfs_find_init() The hfs_find_init() method can trigger the crash if …

Sep 4, 2025
CVE-2025-38715
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: hfs: fix slab-out-of-bounds in hfs_bnode_read() This patch introduces is_bnode_offset_valid() method that checks the requested offset …

Sep 4, 2025
CVE-2025-38714
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() The hfsplus_bnode_read() method can trigger the issue: [ 174.852007][ T9784] …

Sep 4, 2025
CVE-2025-38713
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() The hfsplus_readdir() method is capable to crash by calling …

Sep 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.