Skip to main content

CWE archive

CWE-693 CVEs

Programmatic archive

639 CVEs tagged with CWE-69393 Critical, 224 High, 280 Medium, 42 Low, 0 Unrated.

CVE-2025-36898

Published Sep 4, 2025

There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9866

Published Sep 3, 2025

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22437

Published Sep 2, 2025

In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in the code. This could lead to local esca…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22434

Published Sep 2, 2025

In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22433

Published Sep 2, 2025

In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work Profile scenarios due to a logic error in t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22431

Published Sep 2, 2025

In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error in the code. This coul…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22429

Published Sep 2, 2025

In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional exec…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-22427

Published Sep 2, 2025

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due to a logic error in the code. This could…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49720

Published Sep 2, 2025

In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic error in the code. This could lead to lo…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-20347

Published Aug 27, 2025

A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54143

Published Aug 19, 2025

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-50897

Published Aug 19, 2025

A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24835

Published Aug 12, 2025

Protection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 32.0.101.6737 may allow an authenticated user to potentially…

CVSS 4.1 · Medium

CVE-2025-24523

Published Aug 12, 2025

Protection mechanism failure for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable…

CVSS 5.1 · Medium

CVE-2025-3770

Published Aug 7, 2025

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitr…

CVSS 7.0 · High

CVE-2025-43273

Published Jul 30, 2025

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.8. A sandboxed process may be able to circumvent…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-43261

Published Jul 30, 2025

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sand…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-8032

Published Jul 22, 2025

XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, T…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52951

Published Jul 11, 2025

A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic destined to the device to effectively…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46358

Published Jul 11, 2025

Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

CVSS 8.5 · High

CVE-2025-48003

Published Jul 8, 2025

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVSS 6.8 · Medium
Showing 326-350 of 639 CVEsPage 14 of 26