Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 565/1469
7.3
CVE-2025-48556

In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper

7.8
CVE-2025-48553

In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic er

7.8
CVE-2025-48552

In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a

7.8
CVE-2025-48549

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. T

7.3
CVE-2025-48548

In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the priva

7.3
CVE-2025-48547

In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead

7.8
CVE-2025-48546

In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in

7.1
CVE-2025-48545

In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a conf

7.8
CVE-2025-48544

In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could le

8.8
CVE-2025-48543 KEV

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft

7.8
CVE-2025-48541

In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope

7.8
CVE-2025-48540

In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the co

8.0
CVE-2025-48539

In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead t

7.1
CVE-2025-48537

In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This cou

7.8
CVE-2025-48535

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatc

8.8
CVE-2025-48534

In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic err

7.0
CVE-2025-48533

In multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race

7.3
CVE-2025-48532

In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission du

7.8
CVE-2025-48531

In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. T

8.1
CVE-2025-48530

In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This

7.8
CVE-2025-48523

In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic err

7.8
CVE-2025-48522

In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logi

7.8
CVE-2025-32350

In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to

7.8
CVE-2025-32349

In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to l

7.8
CVE-2025-32347

In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an uns

7.8
CVE-2025-32346

In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a con

7.8
CVE-2025-32345

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa

7.8
CVE-2025-32333

In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in th

7.8
CVE-2025-32332

In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalatio

7.8
CVE-2025-32331

In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error i

7.8
CVE-2025-32327

In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This co

7.8
CVE-2025-32326

In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a

7.8
CVE-2025-32325

In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to l

7.8
CVE-2025-32324

In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy

7.8
CVE-2025-32323

In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text

7.8
CVE-2025-32321

In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a con

7.8
CVE-2025-26464

In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic err

7.8
CVE-2025-26454

In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another us

7.3
CVE-2025-22441

In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary ja

7.8
CVE-2025-0089

In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could l

7.8
CVE-2024-49714

In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lea

7.8
CVE-2025-32312

In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified

7.8
CVE-2025-26462

In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code.

7.8
CVE-2025-26458

In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic err

7.8
CVE-2025-26455

In multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This

7.8
CVE-2025-26452

In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a

7.8
CVE-2025-26450

In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motio

7.8
CVE-2025-26444

In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly r

7.3
CVE-2025-26443

In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unk

7.8
CVE-2025-26440

In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permi

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started