CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-26462

    Last Modified: 26 Feb 2026

    In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-26458

    Last Modified: 8 Sept 2025

    In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-26456

    Last Modified: 26 Feb 2026

    In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server due to a logic error in the code. This could lead to local permanent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-26455

    Last Modified: 26 Feb 2026

    In multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-26453

    Last Modified: 8 Sept 2025

    In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-26452

    Last Modified: 26 Feb 2026

    In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-26450

    Last Modified: 26 Feb 2026

    In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motion events to the default IME due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-26449

    Last Modified: 8 Sept 2025

    In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-26448

    Last Modified: 8 Sept 2025

    In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-26445

    Last Modified: 8 Sept 2025

    In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.3
    High

    CVE-2025-26443

    Last Modified: 26 Feb 2026

    In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 4 Sept 2025
    6.5
    Medium

    CVE-2025-26441

    Last Modified: 8 Sept 2025

    In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-26437

    Last Modified: 8 Sept 2025

    In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-26432

    Last Modified: 5 Sept 2025

    In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-26444

    Last Modified: 26 Feb 2026

    In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the default assistant application when a user-selected assistant is forcibly stopped due to a logic error in the code. This could lead to local escalation of privilege where the default assistant app is automatically granted ROLE_ASSISTANT with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-26442

    Last Modified: 29 Sept 2025

    In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-26440

    Last Modified: 26 Feb 2026

    In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    8.8
    High

    CVE-2025-26438

    Last Modified: 26 Feb 2026

    In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-26436

    Last Modified: 26 Feb 2026

    In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-26435

    Last Modified: 26 Feb 2026

    In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-26430

    Last Modified: 26 Feb 2026

    In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-26429

    Last Modified: 5 Sept 2025

    In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    3.2
    Low

    CVE-2025-26428

    Last Modified: 5 Sept 2025

    In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 4 Sept 2025
    4.4
    Medium

    CVE-2025-26427

    Last Modified: 26 Feb 2026

    In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 4 Sept 2025
    5.1
    Medium

    CVE-2025-26426

    Last Modified: 26 Feb 2026

    In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    4
    Medium

    CVE-2025-26425

    Last Modified: 26 Feb 2026

    In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local escalation of privilege on versions of Android where android.permission.MANAGE_DEFAULT_APPLICATIONS was not defined with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    4
    Medium

    CVE-2025-26424

    Last Modified: 5 Sept 2025

    In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    6.2
    Medium

    CVE-2025-26423

    Last Modified: 26 Feb 2026

    In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    4
    Medium

    CVE-2025-26422

    Last Modified: 26 Feb 2026

    In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    4
    Medium

    CVE-2025-26421

    Last Modified: 26 Feb 2026

    In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    4.4
    Medium

    CVE-2025-26420

    Last Modified: 26 Feb 2026

    In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    5.1
    Medium

    CVE-2025-22425

    Last Modified: 26 Feb 2026

    In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 4 Sept 2025
    5.1
    Medium

    CVE-2025-0087

    Last Modified: 5 Sept 2025

    In onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    4
    Medium

    CVE-2025-0077

    Last Modified: 26 Feb 2026

    In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    4
    Medium

    CVE-2024-49739

    Last Modified: 26 Feb 2026

    In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    4
    Medium

    CVE-2023-35657

    Last Modified: 5 Sept 2025

    In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Sept 2025
    7.9
    High

    CVE-2025-9636

    Last Modified: 26 Feb 2026

    pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.

    Published: 4 Sept 2025
    6.3
    Medium

    CVE-2025-23262

    Last Modified: 15 Apr 2026

    NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-23261

    Last Modified: 15 Apr 2026

    NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disclosing information to unauthorized users.

    Published: 4 Sept 2025
    6.5
    Medium

    CVE-2025-23259

    Last Modified: 15 Apr 2026

    NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause information disclosure and denial of service on the network interface.

    Published: 4 Sept 2025
    7.3
    High

    CVE-2025-23258

    Last Modified: 15 Apr 2026

    NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker with low privileges to escalate privileges. A successful exploit of this vulnerability might lead to escalation of privileges.

    Published: 4 Sept 2025
    7.3
    High

    CVE-2025-23257

    Last Modified: 15 Apr 2026

    NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privileges to escalate privileges. A successful exploit of this vulnerability might lead to escalation of privileges.

    Published: 4 Sept 2025
    8.7
    High

    CVE-2025-23256

    Last Modified: 15 Apr 2026

    NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 4 Sept 2025
    4.2
    Medium

    CVE-2025-23302

    Last Modified: 15 Apr 2026

    NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsafe debug access level. A successful exploit of this vulnerability might lead to denial of service.

    Published: 4 Sept 2025
    4.2
    Medium

    CVE-2025-23301

    Last Modified: 15 Apr 2026

    NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsafe debug access level. A successful exploit of this vulnerability might lead to denial of service.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-38725

    Last Modified: 12 May 2026

    In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is such a device. However, only one main phy device will bind to net phy driver. This is creating issue during system suspend/resume since phy_polling_mode() in phy_state_machine() will directly deference member of phydev->drv for non-main phy devices. Then NULL pointer dereference issue will occur. Due to only external phy or internal phy is necessary, add phy_mask for ax88772 mdio bus to workarnoud the issue.

    Published: 4 Sept 2025
    7.8
    High

    CVE-2025-38715

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: hfs: fix slab-out-of-bounds in hfs_bnode_read() This patch introduces is_bnode_offset_valid() method that checks the requested offset value. Also, it introduces check_and_correct_requested_length() method that checks and correct the requested length (if it is necessary). These methods are used in hfs_bnode_read(), hfs_bnode_write(), hfs_bnode_clear(), hfs_bnode_copy(), and hfs_bnode_move() with the goal to prevent the access out of allocated memory and triggering the crash.

    Published: 4 Sept 2025
    9.8
    Critical

    CVE-2025-38708

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in handle_write_conflicts With `two-primaries` enabled, DRBD tries to detect "concurrent" writes and handle write conflicts, so that even if you write to the same sector simultaneously on both nodes, they end up with the identical data once the writes are completed. In handling "superseeded" writes, we forgot a kref_get, resulting in a premature drbd_destroy_device and use after free, and further to kernel crashes with symptoms. Relevance: No one should use DRBD as a random data generator, and apparently all users of "two-primaries" handle concurrent writes correctly on layer up. That is cluster file systems use some distributed lock manager, and live migration in virtualization environments stops writes on one node before starting writes on the other node. Which means that other than for "test cases", this code path is never taken in real life. FYI, in DRBD 9, things are handled differently nowadays. We still detect "write conflicts", but no longer try to be smart about them. We decided to disconnect hard instead: upper layers must not submit concurrent writes. If they do, that's their fault.

    Published: 4 Sept 2025
    5.5
    Medium

    CVE-2025-38693

    Last Modified: 12 May 2026

    In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar In w7090p_tuner_write_serpar, msg is controlled by user. When msg[0].buf is null and msg[0].len is zero, former checks on msg[0].buf would be passed. If accessing msg[0].buf[2] without sanity check, null pointer deref would happen. We add check on msg[0].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")

    Published: 4 Sept 2025
    6.5
    Medium

    CVE-2025-25048

    Last Modified: 9 Jan 2026

    IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.

    Published: 4 Sept 2025