CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 1mo ago | 7.8 | In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| Exploit 1mo ago | 7.8 | In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| Exploit 1mo ago | 7.8 | In createSessionInternal of PackageInstallerService.java, there is a possible method to remove a DPC app from a managed device without DO consent due to desync from persistence. This could lead to local escalation of privilege if a user can install a malicious app with no additional execution privileges needed. User interaction is needed for exploitation. |
| Exploit 1mo ago | 5.5 | In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. |
| Exploit 1mo ago | 7.8 | In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| Exploit 1mo ago | 3.3 | In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. |
| Exploit 1mo ago | 7.8 | In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| 1mo ago | 9.8 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Truemag <= 4.3.14.2 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Roneous <= 2.1.5 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in ITactics <= 1.0 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Tipsy <= 1.1 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Resurs <= 1.3 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Orpheus <= 1.3 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Spike <= 1.2 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Eros <= 1.3 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Choreo <= 1.6 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in WineShop <= 3.17 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Grecko <= 5.17 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Snowy <= 1.13 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Gita <= 1.11 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Printo <= 1.11 versions. |
| 1mo ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <= 3.7 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Medeus <= 1.14 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Top Dog <= 1.0.5 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Quirky <= 1.23 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Putter <= 1.17 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Dom <= 1.24 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Gat <= 1.16 versions. |
| 1mo ago | 8.1 | Unauthenticated Local File Inclusion in Mission <= 1.22 versions. |