In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic er
In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a
In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. T
In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the priva
In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in
In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a conf
In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could le
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft
In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope
In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the co
In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead t
In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This cou
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatc
In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic err
In multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race
In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission du
In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. T
In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This
In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic err
In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logi
In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to
In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to l
In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an uns
In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a con
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in th
In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalatio
In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error i
In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This co
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a
In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to l
In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy
In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text
In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a con
In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic err
In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another us
In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary ja
In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could l
In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lea
In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified
In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code.
In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic err
In multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This
In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a
In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motio
In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly r
In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unk
In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permi
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started