Android
Vendor:
First CVE: Mar 4, 2021 · Active for 5 years
475
Total CVEs
More Total CVEs than 100% of tracked products
95.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Android over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2021
5 years ago
Most Recent CVE
Jun 5, 2026
49 days ago
CVE Severity & Scoring
Android475 CVEs
15%
48%
35%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local370 (77.9%)
Network40 (8.4%)
Unknown0 (0.0%)
Physical56 (11.8%)
Adjacent Network9 (1.9%)
Attack Complexity
Low469 (98.7%)
High6 (1.3%)
Unknown0 (0.0%)
User Interaction
None425 (89.5%)
Unknown0 (0.0%)
Required50 (10.5%)
Privileges Required
Low304 (64.0%)
High45 (9.5%)
None126 (26.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (475 CVEs).
475 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-21042CRITICAL Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | Sep 12, 2025 | 9.8 | 80 | YES | NO |
CVE-2025-21043CRITICAL Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. | Sep 12, 2025 | 9.8 | 75 | YES | NO |
CVE-2021-25487HIGH Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dere | Oct 6, 2021 | 7.8 | 63 | YES | NO |
CVE-2021-25372MEDIUM An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | Mar 26, 2021 | 6.7 | 60 | YES | NO |
CVE-2021-25337HIGH Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. | Mar 4, 2021 | 7.1 | 60 | YES | NO |
CVE-2021-25394MEDIUM A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised. | Jun 11, 2021 | 6.4 | 58 | YES | NO |
CVE-2021-25371MEDIUM A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. | Mar 26, 2021 | 6.7 | 58 | YES | NO |
CVE-2021-25395MEDIUM A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised. | Jun 11, 2021 | 6.4 | 57 | YES | NO |
CVE-2021-25369MEDIUM An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. | Mar 26, 2021 | 5.5 | 56 | YES | NO |
CVE-2023-21492MEDIUM Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. | May 4, 2023 | 4.4 | 55 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (475 CVEs).
CISA KEV
12 CVEs
2.5% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (475 CVEs).
Media Mentions
Signals from CVEs in this product scope (475 CVEs).
Top CNAs Publishing CVEs For Android
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0 | 7 | 5.9 | 1.4% | 7 | 0 |
| 8.1 | 6 | 6.0 | 0.7% | 6 | 0 |
| 8.0 | 2 | 5.0 | 1.0% | 2 | 0 |
| 16.0 | 70 | 6.1 | 0.1% | 1 | 0 |
| 15.0 | 112 | 6.0 | 0.2% | 2 | 0 |
| 14.0 | 265 | 6.0 | 0.2% | 2 | 0 |
| 13.0 | 356 | 6.1 | 0.3% | 3 | 0 |
| 12.0 | 267 | 6.2 | 0.2% | 1 | 0 |
| 11.0 | 149 | 6.3 | 0.2% | 9 | 0 |
| 10.0 | 18 | 5.8 | 0.3% | 9 | 0 |