CVE Database

130945+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-56889
6.7 MEDIUM

In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with System execution …

Sep 15, 2026
CVE-2026-56888
6.2 MEDIUM

In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no …

Sep 15, 2026
CVE-2026-56882
8.8 HIGH

In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remote code execution with …

Sep 15, 2026
CVE-2026-56881
8.4 HIGH

In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of …

Sep 15, 2026
CVE-2026-56879
6.7 MEDIUM

In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-55366
9.8 CRITICAL

In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalation of …

Sep 15, 2026
CVE-2026-55365
6.7 MEDIUM

In multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Sep 15, 2026
CVE-2026-55359
7.8 HIGH

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege …

Sep 15, 2026
CVE-2026-55351
7.8 HIGH

In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution …

Sep 15, 2026
CVE-2026-55343
8.0 HIGH

In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no …

Sep 15, 2026
CVE-2026-55332
6.7 MEDIUM

In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution …

Sep 15, 2026
CVE-2026-55331
8.8 HIGH

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no …

Sep 15, 2026
CVE-2026-55323
7.8 HIGH

In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with …

Sep 15, 2026
CVE-2026-55318
8.8 HIGH

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges …

Sep 15, 2026
CVE-2026-55317
6.7 MEDIUM

In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-55306
7.5 HIGH

In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote denial of service with no …

Sep 15, 2026
CVE-2026-55304
6.7 MEDIUM

In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation …

Sep 15, 2026
CVE-2026-55302
6.7 MEDIUM

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege …

Sep 15, 2026
CVE-2026-55301
8.4 HIGH

In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 15, 2026
CVE-2026-19886
7.8 HIGH

OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Sep 15, 2026
CVE-2026-19885
7.8 HIGH

OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Sep 15, 2026
CVE-2026-19781
7.8 HIGH

Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Sep 15, 2026
CVE-2026-19774
7.1 HIGH

BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker …

Sep 15, 2026
CVE-2026-19773
9.8 CRITICAL

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Sep 15, 2026
CVE-2026-19641
5.3 MEDIUM

On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can …

Sep 15, 2026
CVE-2026-19504
4.0 MEDIUM

Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is …

Sep 15, 2026
CVE-2026-18421

Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), …

Sep 15, 2026
CVE-2026-0200
8.8 HIGH

In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no …

Sep 15, 2026
CVE-2026-0199
7.8 HIGH

In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no …

Sep 15, 2026
CVE-2026-0197
4.4 MEDIUM

In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local information disclosure with System …

Sep 15, 2026
CVE-2026-0194
8.4 HIGH

In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with no additional …

Sep 15, 2026
CVE-2026-0192
6.7 MEDIUM

In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-0189
8.4 HIGH

In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of …

Sep 15, 2026
CVE-2026-0187
6.7 MEDIUM

In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation …

Sep 15, 2026
CVE-2026-0186
6.7 MEDIUM

In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation …

Sep 15, 2026
CVE-2026-0183
4.4 MEDIUM

In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. …

Sep 15, 2026
CVE-2026-0179
6.7 MEDIUM

In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution …

Sep 15, 2026
CVE-2026-0177
4.4 MEDIUM

In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 15, 2026
CVE-2026-0171
8.8 HIGH

In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with …

Sep 15, 2026
CVE-2026-0170
8.8 HIGH

In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with …

Sep 15, 2026
CVE-2026-0159
8.8 HIGH

In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional …

Sep 15, 2026
CVE-2026-88765
8.5 HIGH

GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions …

Sep 15, 2026
CVE-2026-85234
7.5 HIGH

A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, …

Sep 15, 2026
CVE-2026-82837
5.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions …

Sep 15, 2026
CVE-2026-81899

Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored …

Sep 15, 2026
CVE-2026-81898

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to …

Sep 15, 2026
CVE-2026-81240
8.6 HIGH

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could …

Sep 15, 2026
CVE-2026-81239
8.6 HIGH

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could …

Sep 15, 2026
CVE-2026-81238
7.5 HIGH

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit …

Sep 15, 2026
CVE-2026-81237
6.5 MEDIUM

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.