CVE Database

45033+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82536
8.8 HIGH

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the …

Sep 8, 2026
CVE-2026-77774
8.6 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Sep 8, 2026
CVE-2026-77111
8.7 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this …

Sep 8, 2026
CVE-2026-77110
7.6 HIGH

Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature …

Sep 8, 2026
CVE-2026-77109
8.6 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access …

Sep 8, 2026
CVE-2026-77108
7.5 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access …

Sep 8, 2026
CVE-2026-76202
8.2 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access …

Sep 8, 2026
CVE-2026-69646
8.3 HIGH

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

Sep 8, 2026
CVE-2026-66307
7.5 HIGH

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-66305
7.1 HIGH

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-66304
7.5 HIGH

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-58941
7.8 HIGH

In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-58874
7.8 HIGH

In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-58848
7.0 HIGH

In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58846
7.8 HIGH

In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58839
7.8 HIGH

In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58823
7.8 HIGH

In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58820
7.8 HIGH

In multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege with no additional …

Sep 8, 2026
CVE-2026-55294
7.8 HIGH

In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-55285
7.8 HIGH

In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-55277
8.0 HIGH

In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code …

Sep 8, 2026
CVE-2026-55273
7.8 HIGH

In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with …

Sep 8, 2026
CVE-2026-49932
7.8 HIGH

In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-49927
7.8 HIGH

In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with …

Sep 8, 2026
CVE-2026-49919
7.8 HIGH

In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with …

Sep 8, 2026
CVE-2026-49918
7.8 HIGH

In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with …

Sep 8, 2026
CVE-2026-49887
7.8 HIGH

In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with …

Sep 8, 2026
CVE-2026-49884
7.8 HIGH

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-49882
8.8 HIGH

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with …

Sep 8, 2026
CVE-2026-49881
7.8 HIGH

In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation …

Sep 8, 2026
CVE-2026-49879
8.8 HIGH

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution …

Sep 8, 2026
CVE-2026-45531
7.8 HIGH

In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-45528
7.3 HIGH

In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no …

Sep 8, 2026
CVE-2026-45520
7.8 HIGH

In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no …

Sep 8, 2026
CVE-2026-45515
7.8 HIGH

In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-28668
7.8 HIGH

In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation …

Sep 8, 2026
CVE-2026-28666
8.8 HIGH

In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead …

Sep 8, 2026
CVE-2026-28664
7.8 HIGH

In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-28663
7.8 HIGH

In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local …

Sep 8, 2026
CVE-2026-28662
8.0 HIGH

In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code …

Sep 8, 2026
CVE-2026-28658
7.8 HIGH

In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-28657
7.8 HIGH

In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-28656
7.3 HIGH

In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-28655
7.8 HIGH

In multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This could lead to …

Sep 8, 2026
CVE-2026-28653
7.8 HIGH

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-28650
7.8 HIGH

In setHiddenWhileSuspended of WindowState.java, there is a possible overlay bypass due to a logic error in the code. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-28644
7.8 HIGH

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no …

Sep 8, 2026
CVE-2026-28642
7.8 HIGH

In executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation …

Sep 8, 2026
CVE-2026-28639
7.8 HIGH

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local …

Sep 8, 2026
CVE-2026-28636
7.8 HIGH

In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy. This could lead to …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.