VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18336 CVEsRSS

CVE-2026-56975Medium· 6.5
2w ago

In Cellular Modem, there is a possible denial of service due to improper input validation

In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for…

▾ Sunlitgoogle · androidEPSS 0.15%via NVD
CVE-2026-56974High· 8.8
2w ago

In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation

In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for…

▾ Twilightgoogle · androidEPSS 0.37%via NVD
CVE-2026-56986High· 8.4
2w ago

In multiple files, there is a possible out-of-bounds read due to type confusion

In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-56982High· 7.8
2w ago

In VPU, there is a possible permission bypass due to a missing permission check

In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-56979Medium· 6.7
2w ago

In multiple locations, there is a possible permission bypass due to a logic error in the code

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-56988Medium· 6.4
2w ago

In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition

In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat…

▾ Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-56985High· 8.4
2w ago

In multiple files, there is a possible way to obtain signatures due to type confusion

In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58698Medium· 6.7
2w ago

In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy

In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-56992Medium· 6.7
2w ago

In multiple files, there is a possible permission bypass due to a confused deputy

In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-56989Medium· 6.7
2w ago

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-57006Medium· 4.4
2w ago

In acfw_ffa.c, there is a possible secret read due to a logic error in the code

In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-56997High· 8.8
2w ago

In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check

In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not n…

▾ Twilightgoogle · androidEPSS 0.37%via NVD
CVE-2026-57035Medium· 6.7
2w ago

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-57014High· 7.8
2w ago

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User i…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-57012High· 8.4
2w ago

In the Setup Wizard, there is a possible remote package install due to a missing permission check

In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo…

▾ Twilightgoogle · androidEPSS 0.14%via NVD
CVE-2026-57008High· 7.5
2w ago

In Modem, there is a possible information disclosure due to improper input validation

In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.33%via NVD
CVE-2026-58679High· 8.4
2w ago

In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code

In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

▾ Twilightgoogle · androidEPSS 0.11%via NVD
CVE-2026-58678High· 7.8
2w ago

In Bootloader, there is a possible permission bypass due to a logic error in the code

In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-57042Medium· 6.7
2w ago

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58701High· 7.0
2w ago

In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition

In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl…

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-58699High· 8.4
2w ago

In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check

In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58683High· 8.8
2w ago

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.37%via NVD
CVE-2026-58710High· 8.8
2w ago

In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check

In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed…

▾ Twilightgoogle · androidEPSS 0.37%via NVD
CVE-2026-58704High· 8.8CISA KEV0dayPoC
2w ago

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…

▾ Abyssalgoogle · androidEPSS 0.59%via NVD
CVE-2026-58691High· 8.4
2w ago

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58718Medium· 6.7
2w ago

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not n…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58716Medium· 6.7
2w ago

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-58695High· 7.8
2w ago

In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check

In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction i…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-85234High· 7.5
2w ago

A flaw was found in tftp-hpa

A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to ou…

▾ TwilightRed Hat · tftpEPSS 0.78%via NVD
CVE-2026-82837Medium· 5.3
2w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials …

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials …

▾ Sunlitgitlab · gitlabEPSS 0.23%via NVD
CVEs tagged “cve.org” — page 293 · VulnSea