cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 262 of 339
CVE-2022-20294P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20294 [MEDIUM] CWE-862 CVE-2022-20294: In Content, there is a possible way to learn about an account present on the device due to a missing In Content, there is a possible way to learn about an account present on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-202160705
nvd
CVE-2022-20300P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20300 [MEDIUM] CWE-862 CVE-2022-20300: In Content, there is a possible way to check if the given account exists on the device due to a miss In Content, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-200956588
nvd
CVE-2022-20295P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20295 [MEDIUM] CWE-862 CVE-2022-20295: In ContentService, there is a possible way to check if an account exists on the device due to a miss In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-202160584
nvd
CVE-2022-33702P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-07-12
CVE-2022-33702 [MEDIUM] CWE-285 CVE-2022-33702: Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attac Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.
nvd
CVE-2023-21016P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-21016 [MEDIUM] CVE-2023-21016: In AccountTypePreference of AccountTypePreference.java, there is a possible way to mislead the user In AccountTypePreference of AccountTypePreference.java, there is a possible way to mislead the user about accounts installed on the device due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:
nvd
CVE-2022-47333P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47333 [MEDIUM] CWE-862 CVE-2022-47333: In wlan driver, there is a possible missing permission check. This could lead to local information d In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2022-47330P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47330 [MEDIUM] CWE-862 CVE-2022-47330: In wlan driver, there is a possible missing permission check. This could lead to local information d In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2022-47327P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47327 [MEDIUM] CWE-862 CVE-2022-47327: In wlan driver, there is a possible missing permission check. This could lead to local information d In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2022-47332P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47332 [MEDIUM] CWE-862 CVE-2022-47332: In wlan driver, there is a possible missing permission check. This could lead to local information d In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2022-47450P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47450 [MEDIUM] CWE-862 CVE-2022-47450: In wlan driver, there is a possible missing permission check. This could lead to local information d In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2023-21111P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21111 [MEDIUM] CWE-20 CVE-2023-21111: In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L A
nvd
CVE-2025-48644P4MEDIUMCVSS 5.5v14.0v15.0+5 more2026-03-02
CVE-2025-48644 [MEDIUM] CWE-20 CVE-2025-48644: In multiple locations, there is a possible persistent denial of service due to improper input valida In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0948P4MEDIUMCVSS 5.5vAndroid SoC2023-07-13
CVE-2021-0948 [MEDIUM] CWE-908 CVE-2021-0948: The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space. The contents of this memory could contain sensitive information.
nvd
CVE-2023-21325P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21325 [MEDIUM] CWE-203 CVE-2023-21325: In Settings, there is a possible way to determine whether an app is installed, without query permiss In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21327P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21327 [MEDIUM] CWE-203 CVE-2023-21327: In Permission Manager, there is a possible way to determine whether an app is installed, without que In Permission Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21319P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21319 [MEDIUM] CWE-203 CVE-2023-21319: In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel i In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21323P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21323 [MEDIUM] CWE-203 CVE-2023-21323: In Activity Manager, there is a possible way to determine whether an app is installed, without query In Activity Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21369P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21369 [MEDIUM] CVE-2023-21369: In Usage Access, there is a possible way to display a Settings usage access restriction toggle scree In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissions bypass. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-21029P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-21029 [MEDIUM] CWE-862 CVE-2023-21029: In register of UidObserverController.java, there is a missing permission check. This could lead to l In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-217934898
nvd
CVE-2021-0735P4MEDIUMCVSS 5.5v13.0.0vAndroid-132022-08-11
CVE-2021-0735 [MEDIUM] CWE-862 CVE-2021-0735: In PackageManager, there is a possible way to get information about installed packages ignoring limi In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Andro
nvd
Google Android vulnerabilities | cvebase