2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48531HIGH7.8In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. T...
CVE-2025-48530HIGH8.1In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This...
CVE-2025-48523HIGH7.8In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic err...
CVE-2025-48522HIGH7.8In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logi...
CVE-2025-32350HIGH7.8In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to...
CVE-2025-32349HIGH7.8In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to l...
CVE-2025-32347HIGH7.8In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an uns...
CVE-2025-32346HIGH7.8In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a con...
CVE-2025-32345HIGH7.8In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa...
CVE-2025-32333HIGH7.8In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in th...
CVE-2025-32332HIGH7.8In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalatio...
CVE-2025-32331HIGH7.8In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error i...
CVE-2025-32327HIGH7.8In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This co...
CVE-2025-32326HIGH7.8In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a...
CVE-2025-32325HIGH7.8In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to l...
CVE-2025-32324HIGH7.8In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy...
CVE-2025-32323HIGH7.8In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text...
CVE-2025-32321HIGH7.8In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a con...
CVE-2025-26464HIGH7.8In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic err...
CVE-2025-26454HIGH7.8In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another us...
CVE-2025-22441HIGH7.3In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary ja...
CVE-2025-0089HIGH7.8In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could l...
CVE-2025-32312HIGH7.8In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified ...
CVE-2025-26462HIGH7.8In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code....
CVE-2025-26458HIGH7.8In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic err...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now