VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29023 CVEsRSS

CVE-2026-57014High· 7.8
2w ago

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User i…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-57012High· 8.4
2w ago

In the Setup Wizard, there is a possible remote package install due to a missing permission check

In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo…

▾ Twilightgoogle · androidEPSS 0.14%via NVD
CVE-2026-57008High· 7.5
2w ago

In Modem, there is a possible information disclosure due to improper input validation

In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.33%via NVD
CVE-2026-58679High· 8.4
2w ago

In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code

In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

▾ Twilightgoogle · androidEPSS 0.11%via NVD
CVE-2026-58678High· 7.8
2w ago

In Bootloader, there is a possible permission bypass due to a logic error in the code

In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-57042Medium· 6.7
2w ago

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58701High· 7.0
2w ago

In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition

In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl…

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-58699High· 8.4
2w ago

In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check

In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58683High· 8.8
2w ago

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.37%via NVD
CVE-2026-58710High· 8.8
2w ago

In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check

In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed…

▾ Twilightgoogle · androidEPSS 0.37%via NVD
CVE-2026-58704High· 8.8CISA KEV0dayPoC
2w ago

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…

▾ Abyssalgoogle · androidEPSS 0.59%via NVD
CVE-2026-58691High· 8.4
2w ago

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58718Medium· 6.7
2w ago

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not n…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58716Medium· 6.7
2w ago

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-58695High· 7.8
2w ago

In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check

In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction i…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-85234High· 7.5
2w ago

A flaw was found in tftp-hpa

A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to ou…

▾ TwilightRed Hat · tftpEPSS 0.78%via NVD
CVE-2026-82837Medium· 5.3
2w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials …

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials …

▾ Sunlitgitlab · gitlabEPSS 0.23%via NVD
CVE-2026-58721Medium· 4.4
2w ago

In multiple locations, there is a possible information disclosure due to uninitialized memory use

In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.09%via NVD
CVE-2026-81899High· 7.3
2w ago

Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored cross-site scripting

Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored cross-site scripting. The add and edit group-folder handlers stored the sub…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.48%via NVD
CVE-2026-81240High· 8.6
2w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

▾ Twilightdell · wyse_management_suiteEPSS 0.40%via NVD
CVE-2026-81239High· 8.6
2w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

▾ Twilightdell · wyse_management_suiteEPSS 0.40%via NVD
CVE-2026-81238High· 7.5
2w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Una…

▾ Twilightdell · wyse_management_suiteEPSS 0.27%via NVD
CVE-2026-81237Medium· 6.5
2w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

▾ Sunlitdell · wyse_management_suiteEPSS 0.34%via NVD
CVE-2026-81236High· 8.6
2w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

▾ Twilightdell · wyse_management_suiteEPSS 0.41%via NVD
CVE-2026-81235High· 8.0
2w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.

▾ Twilightdell · wyse_management_suiteEPSS 0.24%via NVD
CVE-2026-58502High· 7.1PoC
2w ago

githubtoplanguages generates a user's top GitHub languages as an SVG

githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for…

▾ Midnightgouef · githubtoplanguagesEPSS 0.53%via NVD
CVE-2026-58485High· 7.1PoC
2w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read receives its caller-controlled URL through src/index.ts and validates only the …

▾ Midnightihor-sokoliuk · mcp-searxngEPSS 0.19%via NVD
CVE-2026-58483High· 7.5PoC
2w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in src/index.ts passes a caller-supplied URL to readUrlContent() in src/url-rea…

▾ Midnightihor-sokoliuk · mcp-searxngEPSS 0.67%via NVD
CVE-2026-57442Medium· 6.9PoC
2w ago

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules pa…

▾ Twilightbitbonsai · mcpvaultEPSS 0.19%via NVD
CVE-2026-57441High· 8.4
2w ago

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without ca…

▾ Twilightbitbonsai · mcpvaultEPSS 0.20%via NVD
CVEs tagged “nvd” — page 276 · VulnSea