cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 91 of 339
CVE-2023-21089P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21089 [HIGH] CVE-2023-21089: In startInstrumentation of ActivityManagerService.java, there is a possible way to keep the foregrou In startInstrumentation of ActivityManagerService.java, there is a possible way to keep the foreground service alive while the app is in the background. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L And
nvd
CVE-2022-42777P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-42777 [HIGH] CWE-862 CVE-2022-42777: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-42776P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-42776 [HIGH] CWE-862 CVE-2022-42776: In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine s In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.
nvd
CVE-2022-48247P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48247 [HIGH] CWE-862 CVE-2022-48247: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48368P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48368 [HIGH] CWE-862 CVE-2022-48368: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-44433P3HIGHCVSS 7.8v10.02023-05-09
CVE-2022-44433 [HIGH] CWE-862 CVE-2022-44433: In phoneEx service, there is a possible missing permission check. This could lead to local escalatio In phoneEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48249P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48249 [HIGH] CWE-862 CVE-2022-48249: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48244P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48244 [HIGH] CWE-862 CVE-2022-48244: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48248P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48248 [HIGH] CWE-862 CVE-2022-48248: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48388P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48388 [HIGH] CWE-862 CVE-2022-48388: In powerEx service, there is a possible missing permission check. This could lead to local escalatio In powerEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48250P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48250 [HIGH] CWE-862 CVE-2022-48250: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48369P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48369 [HIGH] CWE-862 CVE-2022-48369: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48243P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48243 [HIGH] CWE-862 CVE-2022-48243: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48246P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48246 [HIGH] CWE-862 CVE-2022-48246: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48245P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48245 [HIGH] CWE-862 CVE-2022-48245: In audio service, there is a possible missing permission check. This could lead to local escalation In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2023-21004P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21004 [HIGH] CWE-862 CVE-2023-21004: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261193664
nvd
CVE-2023-21003P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21003 [HIGH] CWE-862 CVE-2023-21003: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261193711
nvd
CVE-2023-21015P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21015 [HIGH] CWE-862 CVE-2023-21015: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244569778
nvd
CVE-2023-21005P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21005 [HIGH] CWE-862 CVE-2023-21005: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261193946
nvd
CVE-2022-20611P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20611 [HIGH] CWE-276 CVE-2022-20611: In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass car In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 An
nvd
Google Android vulnerabilities | cvebase