CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
80 vulnerabilities with CWE-441
CVE-2025-36889
MEDIUM
Google Android - Information Disclosure
CVSS 5.5
CVE-2025-48628
HIGH
PrintManagerService - Privilege Escalation
CVSS 7.8
CVE-2025-48598
MEDIUM
Face Unlock Settings - Privilege Escalation
CVSS 6.6
CVE-2025-48586
HIGH
EditFdnContactScreen - Info Disclosure
CVSS 7.8
CVE-2025-48555
HIGH
NotificationStation - Info Disclosure
CVSS 7.8
CVE-2025-48536
HIGH
SettingsSliceProvider - Privilege Escalation
CVSS 7.8
CVE-2025-22420
HIGH
Multiple Locations - Info Disclosure
CVSS 7.8
CVE-2025-66415
MEDIUM
Fastify-reply-from <12.5.0 - SSRF
CVSS 5.4
CVE-2025-61780
MEDIUM
Rack < 2.2.20 - Information Disclosure
CVSS 5.8
CVE-2025-32320
HIGH
System UI - Privilege Escalation
CVSS 7.8
CVE-2025-32317
MEDIUM
Google Android - Information Disclosure
CVSS 5.5
CVE-2025-48560
MEDIUM
AndroidManifest.xml - Info Disclosure
CVSS 5.5
CVE-2025-48551
MEDIUM
Android - Info Disclosure
CVSS 5.0
CVE-2025-48545
HIGH
Android - Privilege Escalation
CVSS 7.1
CVE-2025-48532
HIGH
markMediaAsFavorite - Privilege Escalation
CVSS 7.3
CVE-2025-48529
MEDIUM
VoicemailNotificationSettingsUtil - Info Disclosure
CVSS 5.5
CVE-2025-32346
HIGH
VoicemailSettingsActivity - Privilege Escalation
CVSS 7.8
CVE-2025-32326
HIGH
AppRestrictionsFragment - Privilege Escalation
CVSS 7.8
CVE-2025-32324
HIGH
Java - Privilege Escalation
CVSS 7.8
CVE-2025-32321
HIGH
Android - Privilege Escalation
CVSS 7.8
CVE-2025-26454
HIGH
Java - Privilege Escalation
CVSS 7.8
CVE-2025-22441
HIGH
Java - Privilege Escalation
CVSS 7.3
CVE-2025-26452
HIGH
Android - Privilege Escalation
CVSS 7.8
CVE-2025-22418
HIGH
Multiple Locations - Privilege Escalation
CVSS 7.8
CVE-2025-22416
HIGH
ChooserActivity - Info Disclosure
CVSS 7.8
Details
Vulnerabilities
80