7.8

CVSS3.1

CVE-2025-48555 -

In multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Dec. 8, 2025, 4:57 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.8

CVSS3.1

CVE-2025-48536 -

In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settings due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for …

πŸ“… Published: Dec. 8, 2025, 4:57 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.8

CVSS3.1

CVE-2025-48525 -

In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a companion device due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User int…

πŸ“… Published: Dec. 8, 2025, 4:57 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.8

CVSS3.1

CVE-2025-32329 -

In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…

πŸ“… Published: Dec. 8, 2025, 4:56 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.8

CVSS3.1

CVE-2025-32328 -

In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…

πŸ“… Published: Dec. 8, 2025, 4:56 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

6.7

CVSS3.1

CVE-2025-32319 -

In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. This could lead to local escalation of privilege with user execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Dec. 8, 2025, 4:56 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

6.7

CVSS3.1

CVE-2025-22432 -

In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Dec. 8, 2025, 4:56 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.8

CVSS3.1

CVE-2025-22420 -

In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Dec. 8, 2025, 4:56 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

6.9

CVSS4.0

CVE-2025-14256 - itsourcecode Student Management System newcurriculm.php sql injection

A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

πŸ“… Published: Dec. 8, 2025, 4:32 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 4:13 p.m.

6.9

CVSS4.0

CVE-2025-14251 - code-projects Online Ordering System Admin Login admin sql injection

A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the component Admin Login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has…

πŸ“… Published: Dec. 8, 2025, 4:02 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 5:48 p.m.
Total resulsts: 343919
Page 2250 of 34,392
Β« previous page Β» next page
Filters