Skip to main content

CWE archive

CWE-693 CVEs

Programmatic archive

639 CVEs tagged with CWE-69393 Critical, 224 High, 280 Medium, 42 Low, 0 Unrated.

CVE-2025-52615

Published Oct 12, 2025

HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-43296

Published Oct 9, 2025

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55886

Published Sep 22, 2025

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated att…

CVSS 6.5 · Medium

CVE-2025-10157

Published Sep 17, 2025

A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is poss…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-37124

Published Sep 16, 2025

A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitation could allow an a…

CVSS 8.6 · High

CVE-2025-10528

Published Sep 16, 2025

Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and…

CVSS 7.3 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-43330

Published Sep 15, 2025

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to break out of its sandbox.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59033

Published Sep 8, 2025

The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code…

CVSS 7.4 · High

CVE-2025-26439

Published Sep 4, 2025

In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead of the system component due to a logic er…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26431

Published Sep 4, 2025

In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48554

Published Sep 4, 2025

In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the code. This could lead to local denial of…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48546

Published Sep 4, 2025

In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48534

Published Sep 4, 2025

In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local denial of service…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48531

Published Sep 4, 2025

In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no add…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48522

Published Sep 4, 2025

In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code. This could lead to local escalation of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32331

Published Sep 4, 2025

In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This could lead to local escalation of privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26464

Published Sep 4, 2025

In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of priv…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0089

Published Sep 4, 2025

In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalation of privilege with no additional exe…

CVSS 7.8 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-26458

Published Sep 4, 2025

In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of priv…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26444

Published Sep 4, 2025

In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the default assistant application when a user-sele…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26443

Published Sep 4, 2025

In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the code. This could l…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36905

Published Sep 4, 2025

In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local escalation of privilege with no additio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 301-325 of 639 CVEsPage 13 of 26