8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 4651-4700 of 8341 CVEs Page 94 of 167
CVE-2025-48592
7.5
Unknown Multiple Products

In initDecoder of C2SoftDav1dDec

2025-12-09
CVE-2025-48589
7.8
Unknown Multiple Products

In multiple functions of HeaderPrivacyIconsController

2025-12-09
CVE-2025-48588
Analyzed
7.8
Unknown Multiple Products

In startAlwaysOnVpn of Vpn

2025-12-09
CVE-2025-48586
7.8
Unknown Multiple Products

In onActivityResult of EditFdnContactScreen

2025-12-09
CVE-2025-48583
7.8
Unknown Multiple Products

In multiple functions of BaseBundle

2025-12-09
CVE-2025-48581
Analyzed
9.8
Unknown Multiple Products

In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates through mainline installations due to a logic error in th...

2025-09-04
CVE-2025-48580
7.8
Unknown Multiple Products

In connectInternal of MediaBrowser

2025-12-09
CVE-2025-48575
7.8
Unknown Multiple Products

In multiple functions of CertInstaller

2025-12-09
CVE-2025-48573
7.8
Unknown Multiple Products

In sendCommand of MediaSessionRecord

2025-12-09
CVE-2025-48572
KEV Analyzed
9.5
Google Framework

Android Framework Privilege Escalation Vulnerability - Active in CISA KEV catalog.

2025-12-03
CVE-2025-48566
7.8
Unknown Multiple Products

In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation

2025-12-09
CVE-2025-48565
7.8
Unknown Multiple Products

In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code

2025-12-09
CVE-2025-48564
7
Unknown Multiple Products

In multiple locations, there is a possible intent filter bypass due to a race condition

2025-12-09
CVE-2025-48563
Analyzed
7.8
Unknown Multiple Products

In onNullBinding of RemoteFillService

2025-09-04
CVE-2025-48558
Analyzed
7.8
Unknown Multiple Products

In multiple functions of BatteryService

2025-09-04
CVE-2025-48556
7.3
Unknown Multiple Products

In multiple methods of NotificationChannel

2025-09-04
CVE-2025-48555
7.8
Unknown Multiple Products

In multiple functions of NotificationStation

2025-12-09
CVE-2025-48553
7.8
Unknown Multiple Products

In handlePackagesChanged of DevicePolicyManagerService

2025-09-05
CVE-2025-48552
7.8
Unknown Multiple Products

In saveGlobalProxyLocked of DevicePolicyManagerService

2025-09-05
CVE-2025-4855
9.8
WordPress Multiple Products

The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in t...

2025-07-10
CVE-2025-48549
Analyzed
7.8
Unknown Multiple Products

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check

2025-09-04
CVE-2025-48548
7.3
Unknown Multiple Products

In multiple functions of AppOpsControllerImpl

2025-09-04
CVE-2025-48546
7.8
Unknown Multiple Products

In checkPermissions of SafeActivityOptions

2025-09-05
CVE-2025-48544
7.8
Unknown Multiple Products

In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection

2025-09-05
CVE-2025-48543
KEV Analyzed
8.8
Google Multiple Products

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free

2025-09-04
CVE-2025-48541
Analyzed
7.8
Unknown Multiple Products

In onCreate of FaceSettings

2025-09-04
CVE-2025-48540
Analyzed
7.8
Unknown Multiple Products

In processTransactInternal of RpcState

2025-09-04
CVE-2025-48539
Analyzed
8
SendPacketToPeer Multiple Products

In SendPacketToPeer of acl_arbiter

2025-09-04
CVE-2025-48536
Analyzed
7.8
Unknown Multiple Products

In grantAllowlistedPackagePermissions of SettingsSliceProvider

2025-12-09
CVE-2025-48535
Analyzed
7.8
Unknown Multiple Products

In assertSafeToStartCustomActivity of AppRestrictionsFragment

2025-09-04
CVE-2025-48534
8.8
Unknown Multiple Products

In getDefaultCBRPackageName of CellBroadcastHandler

2025-09-05
CVE-2025-48532
7.3
Unknown Multiple Products

In markMediaAsFavorite of MediaProvider

2025-09-04
CVE-2025-48531
7.8
Unknown Multiple Products

In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code

2025-09-05
CVE-2025-48530
8.1
Unknown Multiple Products

In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check

2025-09-05
CVE-2025-48525
7.8
Unknown Multiple Products

In disassociate of DisassociationProcessor

2025-12-09
CVE-2025-48523
7.8
Unknown Multiple Products

In onCreate of SelectAccountActivity

2025-09-05
CVE-2025-48522
7.8
Unknown Multiple Products

In setDisplayName of AssociationRequest

2025-09-05
CVE-2025-48510
7.1
AMD Multiple Products

Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability

2025-11-25
CVE-2025-48498
7.5
Unknown Multiple Products

A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8

2025-07-23
CVE-2025-48429
7.4
Grassroot Multiple Products

An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3

2025-12-17
CVE-2025-48397
7.1
Unknown Multiple Products

The privileged user could log in without sufficient credentials after enabling an application protocol

2025-11-04
CVE-2025-48396
Analyzed
8.3
HP Multiple Products

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS

2025-11-04
CVE-2025-48392
7.5
Apache Multiple Products

A vulnerability in Apache IoTDB

2025-09-24
CVE-2025-48384
KEV
8
Git Multiple Products

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full acce...

2025-07-10
CVE-2025-48359
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in thaihavnn07 ATT YouTube Widget allows Stored XSS

2025-08-28
CVE-2025-48353
7.1
WordPress Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in dactum Clickbank WordPress Plugin (Niche Storefront) allows Stored XSS

2025-08-28
CVE-2025-48351
7.1
PluginsPoint Kento Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen allows Stored XSS

2025-08-28
CVE-2025-48345
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft Contact Form 7 Editor Button allows Refl...

2025-07-16
CVE-2025-48343
7.1
Aaron Axelsen WPMU Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Aaron Axelsen WPMU Ldap Authentication allows Stored XSS

2025-08-28
CVE-2025-48338
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp-...

2025-10-23