2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48650HIGH8.4In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalat...
CVE-2025-48646HIGH7.8In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead...
CVE-2025-48645HIGH7.8In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. Thi...
CVE-2025-48644MEDIUM5.5In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lea...
CVE-2025-48642MEDIUM5.5In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This coul...
CVE-2025-48641HIGH7In multiple functions of Nfc.h, there is a possible use after free due to a race condition. This could lead to local esc...
CVE-2025-48636HIGH8.4In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path...
CVE-2025-48635HIGH7.7In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic er...
CVE-2025-48634HIGH7.3In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. Th...
CVE-2025-48630HIGH7.4In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel infor...
CVE-2025-48619HIGH8.4In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate file...
CVE-2025-48613HIGH7.8In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previou...
CVE-2025-48609CRITICAL9.1In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, S...
CVE-2025-48605HIGH8.4In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the co...
CVE-2025-48602HIGH8.4In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass...
CVE-2025-48587MEDIUM6.2In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input v...
CVE-2025-48585MEDIUM6.2In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input v...
CVE-2025-48582HIGH8.4In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an ...
CVE-2025-48579HIGH8.4In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confu...
CVE-2025-48578HIGH7.8In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due...
CVE-2025-48577HIGH7.4In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This ...
CVE-2025-48574HIGH8.4In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events du...
CVE-2025-48568HIGH7.4In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalatio...
CVE-2025-48567HIGH7.8In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive director...
CVE-2025-32313HIGH8.4In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now