2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48537HIGH7.1In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This cou...
CVE-2025-48535HIGH7.8In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatc...
CVE-2025-48534HIGH8.8In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic err...
CVE-2025-48533HIGH7In multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race ...
CVE-2025-48532HIGH7.3In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission du...
CVE-2025-48531HIGH7.8In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. T...
CVE-2025-48530HIGH8.1In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This...
CVE-2025-48523HIGH7.8In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic err...
CVE-2025-48522HIGH7.8In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logi...
CVE-2025-32350HIGH7.8In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to...
CVE-2025-32349HIGH7.8In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to l...
CVE-2025-32347HIGH7.8In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an uns...
CVE-2025-32346HIGH7.8In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a con...
CVE-2025-32345HIGH7.8In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa...
CVE-2025-32333HIGH7.8In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in th...
CVE-2025-32332HIGH7.8In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalatio...
CVE-2025-32331HIGH7.8In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error i...
CVE-2025-32327HIGH7.8In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This co...
CVE-2025-32326HIGH7.8In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a...
CVE-2025-32325HIGH7.8In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to l...
CVE-2025-32324HIGH7.8In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy...
CVE-2025-32323HIGH7.8In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text...
CVE-2025-32321HIGH7.8In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a con...
CVE-2025-26464HIGH7.8In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic err...
CVE-2025-26454HIGH7.8In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another us...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now