133011+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, …
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a …
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a …
In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User …
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a …
In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if …
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User …
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with …
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if …
In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has …
In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor …
In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor …
In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor …
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no …
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no …
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service …
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if …
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service …
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with …
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious …
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …
In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if …
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if …
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution …
In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious …
In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious …
In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a …
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if …
In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation …
In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if …
A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component …
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java …
BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected …
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java …
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java …
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before …
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and …
In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS …
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for …
In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips …
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java …
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before …
Free website and port scanning — find vulnerabilities before attackers do.