CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,867 CVEs tracked 53,243 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,925 Nuclei templates 37,802 vendors 42,500 researchers
403 results Clear all
CVE-2025-54917 4.3 MEDIUM EPSS 0.00
Windows MapUrlToZone - Privilege Escalation
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
CWE-693 Sep 09, 2025
CVE-2025-59033 7.4 HIGH EPSS 0.00
Microsoft - Info Disclosure
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier (such as file name or version) may not be blocked, whether hypervisor-protected code integrity (HVCI) is enabled or not. NOTE: The vendor disputes this CVE ID assignment and states that the driver blocklist is intended for use with HVCI.
CWE-693 Sep 08, 2025
CVE-2025-26439 7.8 HIGH EPSS 0.00
Android - Privilege Escalation
In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead of the system component due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-26431 7.8 HIGH EPSS 0.00
Android - Privilege Escalation
In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-48554 6.1 MEDIUM EPSS 0.00
Android - DoS
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-48546 7.8 HIGH EPSS 0.00
Java - Privilege Escalation
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-48534 8.8 HIGH EPSS 0.00
Java - Privilege Escalation
In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-48531 7.8 HIGH EPSS 0.00
Android - Privilege Escalation
In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-48522 7.8 HIGH EPSS 0.00
Java - Privilege Escalation
In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-32331 7.8 HIGH EPSS 0.00
Android - Privilege Escalation
In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-26464 7.8 HIGH EPSS 0.00
AppSearchManagerService - Privilege Escalation
In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-0089 7.8 HIGH EPSS 0.00
Launcher App - Privilege Escalation
In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-26458 7.8 HIGH EPSS 0.00
Java - Privilege Escalation
In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-26444 7.8 HIGH EPSS 0.00
Android - Privilege Escalation
In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the default assistant application when a user-selected assistant is forcibly stopped due to a logic error in the code. This could lead to local escalation of privilege where the default assistant app is automatically granted ROLE_ASSISTANT with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-26443 7.3 HIGH 1 PoC Analysis EPSS 0.00
Android - Privilege Escalation
In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-36905 7.8 HIGH EPSS 0.00
Google Android - Privilege Escalation
In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-36898 7.8 HIGH EPSS 0.00
Unknown - Privilege Escalation
There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 04, 2025
CVE-2025-9866 8.8 HIGH EPSS 0.00
Google Chrome <140.0.7339.80 - Auth Bypass
Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
CWE-693 Sep 03, 2025
CVE-2025-22437 7.8 HIGH EPSS 0.00
Android - Privilege Escalation
In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 02, 2025
CVE-2025-22434 7.8 HIGH EPSS 0.00
Android - Privilege Escalation
In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE-693 Sep 02, 2025