2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26449 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo... |
| CVE-2025-26448 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead ... |
| CVE-2025-26445 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission chec... |
| CVE-2025-26444 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly r... |
| CVE-2025-26443 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unk... |
| CVE-2025-26442 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent ... |
| CVE-2025-26441 | MEDIUM | 6.5 | 0.3% | Sep 4, 2025 | In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead t... |
| CVE-2025-26440 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permi... |
| CVE-2025-26438 | HIGH | 8.8 | 0.3% | Sep 4, 2025 | In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Inc... |
| CVE-2025-26437 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credenti... |
| CVE-2025-26436 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activ... |
| CVE-2025-26435 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa... |
| CVE-2025-26432 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could ... |
| CVE-2025-26430 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the ... |
| CVE-2025-26429 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. Th... |
| CVE-2025-26428 | LOW | 3.2 | 0.1% | Sep 4, 2025 | In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code... |
| CVE-2025-26427 | MEDIUM | 4.4 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local e... |
| CVE-2025-26426 | MEDIUM | 5.1 | 0.1% | Sep 4, 2025 | In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant fo... |
| CVE-2025-26425 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error i... |
| CVE-2025-26424 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. Thi... |
| CVE-2025-26423 | MEDIUM | 6.2 | 0.1% | Sep 4, 2025 | In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a mi... |
| CVE-2025-26422 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to ... |
| CVE-2025-26421 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local... |
| CVE-2025-26420 | MEDIUM | 4.4 | 0.1% | Sep 4, 2025 | In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the inc... |
| CVE-2025-22425 | MEDIUM | 5.1 | 0.1% | Sep 4, 2025 | In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could le... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now