Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.2 MEDIUM
CVE-2025-48587 — Apache ProfilingService Denial of Service Vulnerability

In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execut…

android | Denial of Service
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
6.2 MEDIUM
CVE-2025-48585 — Apache ProfilingService Denial of Service Vulnerability

In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execut…

android | Denial of Service
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
8.4 HIGH
CVE-2025-48582 — Google Android Intent Redirection Media Deletion Vulnerability

In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. This could lead to local escalation of privilege with no addit…

android | Authorization
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
8.4 HIGH
CVE-2025-48579 — "MediaProvider Java External Storage Write Permission Bypass"

In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional…

android | Authorization
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
7.8 HIGH
CVE-2025-48578 — Apache MediaProvider Permission Bypass vulnerability

In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission check. This could lead to local escalation of privileg…

android | Authorization
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
7.4 HIGH
CVE-2025-48577 — Android Keyguard Lockscreen Bypass Vulnerability

In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privil…

android | Race Condition
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
8.4 HIGH
CVE-2025-48574 — Google Chrome Drag-and-Drop Privilege Escalation

In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission check. This could lead to local escalation of privile…

android | Authorization
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
7.4 HIGH
CVE-2025-48568 — Samsung Galaxy Lockscreen Bypass Vulnerability

In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

android | Race Condition
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
7.8 HIGH
CVE-2025-48567 — Apache HTTP Server Unicode Normalization Privilege Escalation Vulnerability

In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalatio…

android | Path Traversal
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
8.4 HIGH
CVE-2025-32313 — Apache Software Java Out-of-Bounds Write Vulnerability

In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges …

android | Memory Corruption
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
6.5 MEDIUM
CVE-2024-43766 — "Bluetoothy Bluetooth Information Disclosure Vulnerability"

In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no addi…

android | Cryptography
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
8.8 HIGH
CVE-2024-31328 — Android BroadcastController arbitrary activity launch vulnerability

In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on the paired companion phone due to a logic error in the code. …

android | Authentication
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
7.5 HIGH
CVE-2026-3180 — Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in al…

Remote | Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-3132 — Master Addons for Elementor Premium <= 2.1.3 - Authenticated (Subscriber+) Remote Code Ex…

The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Admin::render_preview'. This is d…

Remote | Authentication
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2026-26707 — Sourcecodester Pharmacy Point of Sale System SQL Injection Vulnerability

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.

pharmacy_point_of_sale_system | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-26706 — Sourcecodester Pharmacy Point of Sale System SQL Injection Vulnerability

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.

pharmacy_point_of_sale_system | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-26705 — Sourcecodester Pharmacy Point of Sale System SQL Injection Vulnerability

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.

pharmacy_point_of_sale_system | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-26704 — Sourcecodester Pharmacy Point of Sale System SQL Injection

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.

pharmacy_point_of_sale_system | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
8.0 HIGH
CVE-2026-0655 — Path Traversal on TP-Link Deco BE25

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authenticated adjacent attacker to read arbitrary files or …

deco_be25_firmware deco_be25 | Path Traversal
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
8.5 HIGH
CVE-2026-0654 — Command injection on TP-Link Deco BE25

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arb…

Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
Showing 20 of 5067 Results