Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
–

9126 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.28%—Google Android4/9/202517/6/2026
In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.09%—Google Android4/9/202517/6/2026
In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (8.8)0.33%—Google Android4/9/202517/6/2026
In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (5.5)0.08%—Google Android4/9/202517/6/2026
In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.09%—Google Android4/9/202517/6/2026
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.08%—Google Android4/9/202517/6/2026
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…
AnalizadaMedia (5.5)0.08%—Google Android4/9/202517/6/2026
In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.08%—Google Android4/9/202517/6/2026
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (5.5)0.08%—Google Android4/9/202517/6/2026
In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaBaja (3.2)0.10%—Google Android4/9/202517/6/2026
In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
AnalizadaMedia (4.4)0.11%—Google Android4/9/202517/6/2026
In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
AnalizadaMedia (5.1)0.10%—Google Android4/9/202517/6/2026
In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
AnalizadaMedia (4)0.09%—Google Android4/9/202517/6/2026
In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local escalation of privilege on versions of Android where android.permission.MANAGE_DEFAULT_APPLICATIONS was not defined with no additional execution privileges…
AnalizadaMedia (4)0.10%—Google Android4/9/202517/6/2026
In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (4)0.09%—Google Android4/9/202517/6/2026
In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (4)0.10%—Google Android4/9/202517/6/2026
In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (4.4)0.09%—Google Android4/9/202517/6/2026
In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (5.1)0.10%—Google Android4/9/202517/6/2026
In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
AnalizadaMedia (5.1)0.22%💥 PoCGoogle Android4/9/202517/6/2026
In onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (4)0.10%—Google Android4/9/202517/6/2026
In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (4)0.11%—Google Android4/9/202517/6/2026
In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaMedia (4)0.09%—Google Android4/9/202517/6/2026
In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.08%—Google Android4/9/202530/9/2026
En onCreate de MediaProjectionPermissionActivity.java, existe una posible forma de otorgar a una aplicación maliciosa un token que permite capacidades de grabación de pantalla no autorizadas debido a una validación de entrada incorrecta. Esto podría conducir a una escalada de privilegios local sin necesidad de…
AnalizadaAlta (7.8)0.09%—Google Android4/9/202530/9/2026
En setupAccessibilityServices de AccessibilityFragment.java, existe una posible forma de ocultar un servicio de accesibilidad habilitado debido a un error de lógica en el código. Esto podría conducir a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción…
AnalizadaMedia (5.5)0.07%—Google Android4/9/202530/9/2026
En AndroidManifest.xml, existe una posible forma para que una aplicación monitoree eventos de movimiento debido a un delegado confundido. Esto podría llevar a la revelación de información local sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación.