VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

28998 CVEsRSS

CVE-2026-68530Low· 2.1
2w ago

Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard

Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details single-page controller resolved a board instance directly from an attacker-su…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.47%via NVD
CVE-2026-68529Low· 2.1
2w ago

Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action

Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express entity directly fro…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.44%via NVD
CVE-2026-66790None
2w ago

Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerability

Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerability. Please use CVE-2026-70496 instead.

▾ Sunlitvia NVD
CVE-2026-66789None
2w ago

Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70495, which describes the same vulnerability

Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70495, which describes the same vulnerability. Please use CVE-2026-70495 instead.

▾ Sunlitvia NVD
CVE-2026-58773Medium· 6.7
2w ago

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58767Medium· 6.7
2w ago

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58766High· 7.8
2w ago

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58765Medium· 6.7
2w ago

In GPU, there is a possible permission bypass due to a logic error in the code

In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58755Medium· 6.7
2w ago

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not …

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58751Medium· 6.7
2w ago

In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code

In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exp…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58747Medium· 6.7
2w ago

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exp…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58744High· 7.8
2w ago

In multiple locations, there is a possible escalation of privilege due to improper input validation

In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58739Medium· 6.7
2w ago

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede…

▾ Sunlitgoogle · androidEPSS 0.09%via NVD
CVE-2026-58734High· 7.0
2w ago

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-58731Medium· 6.2
2w ago

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58728High· 7.0
2w ago

In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition

In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-58726Medium· 6.7
2w ago

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58724High· 7.0
2w ago

In multiple locations, there is a possible use-after-free due to a race condition

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-18421Low· 2.1
2w ago

Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), which resolve a ConfiguredDataSource directly from…

Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), which resolve a ConfiguredDataSource directly from…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.27%via NVD
CVE-2026-19774High· 7.10day
2w ago

BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability

BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to p…

▾ AbyssalBlueZ · BlueZEPSS 0.27%via NVD
CVE-2026-19773Critical· 9.80day
2w ago

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is no…

▾ Hadallibwebsockets · libwebsocketsEPSS 0.65%via NVD
CVE-2026-19504Medium· 4.00day
2w ago

Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability

Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is required to exploit t…

▾ MidnightFabric.js · Fabric.jsEPSS 0.12%via NVD
CVE-2026-19886High· 7.80day
2w ago

OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability

OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction i…

▾ AbyssalOriginLab · Origin ViewerEPSS 0.17%via NVD
CVE-2026-19885High· 7.80day
2w ago

OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interactio…

▾ AbyssalOriginLab · Origin ViewerEPSS 0.17%via NVD
CVE-2026-19781High· 7.80day
2w ago

Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction…

▾ AbyssalAshlar-Vellum · CobaltEPSS 0.17%via NVD
CVE-2026-92180High· 7.80day
2w ago

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PD…

▾ Abyssalpdfforge · PDF ArchitectEPSS 0.19%via NVD
CVE-2026-92179High· 7.80day
2w ago

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction i…

▾ Abyssalpdfforge · PDF ArchitectEPSS 0.23%via NVD
CVE-2026-92178High· 7.80day
2w ago

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is …

▾ Abyssalpdfforge · PDF ArchitectEPSS 0.23%via NVD
CVE-2026-92177High· 7.80day
2w ago

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction i…

▾ Abyssalpdfforge · PDF ArchitectEPSS 0.23%via NVD
CVE-2026-92176High· 7.80day
2w ago

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is requi…

▾ Abyssalpdfforge · PDF ArchitectEPSS 0.23%via NVD
CVEs tagged “nvd” — page 272 · VulnSea