4.3

CVSS3.1

CVE-2025-21030 -

Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background.

๐Ÿ“… Published: Sept. 3, 2025, 6:05 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-21029 -

Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.

๐Ÿ“… Published: Sept. 3, 2025, 6:05 a.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 9:22 p.m.

5.5

CVSS3.1

CVE-2025-21028 -

Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.

๐Ÿ“… Published: Sept. 3, 2025, 6:05 a.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 9:22 p.m.

5.1

CVSS3.1

CVE-2025-21027 -

Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.

๐Ÿ“… Published: Sept. 3, 2025, 6:05 a.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 9:21 p.m.

4

CVSS3.1

CVE-2025-21026 -

Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.

๐Ÿ“… Published: Sept. 3, 2025, 6:05 a.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 9:21 p.m.

5.1

CVSS3.1

CVE-2025-21025 -

Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.

๐Ÿ“… Published: Sept. 3, 2025, 6:05 a.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 9:20 p.m.

6.3

CVSS3.1

CVE-2023-21474 -

Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.

๐Ÿ“… Published: Sept. 3, 2025, 6:01 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

3.3

CVSS3.1

CVE-2023-3666 - Sticky Side Buttons < 2.0.0 - Admin+ Stored XSS

The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

๐Ÿ“… Published: Sept. 3, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Jan. 16, 2026, 4:38 p.m.

2

CVSS4.0

CVE-2025-58272 -

Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by an attacker, the settings of the product may be unintentionally changed.

๐Ÿ“… Published: Sept. 3, 2025, 5:28 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2023-21483 -

Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.

๐Ÿ“… Published: Sept. 3, 2025, 5:17 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 4:23 p.m.
Total resulsts: 349182
Page 4041 of 34,919
ยซ previous page ยป next page
Filters