CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-73451
4.8 MEDIUM

On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting …

Sep 15, 2026
CVE-2026-69216
5.4 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or …

Sep 15, 2026
CVE-2026-69214
6.8 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking …

Sep 15, 2026
CVE-2026-69212
5.9 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a …

Sep 15, 2026
CVE-2026-69211
4.8 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing …

Sep 15, 2026
CVE-2026-69201
5.9 MEDIUM

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments …

Sep 15, 2026
CVE-2026-58773
6.7 MEDIUM

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 15, 2026
CVE-2026-58767
6.7 MEDIUM

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local …

Sep 15, 2026
CVE-2026-58765
6.7 MEDIUM

In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with …

Sep 15, 2026
CVE-2026-58755
6.7 MEDIUM

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation …

Sep 15, 2026
CVE-2026-58751
6.7 MEDIUM

In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of …

Sep 15, 2026
CVE-2026-58747
6.7 MEDIUM

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of …

Sep 15, 2026
CVE-2026-58739
6.7 MEDIUM

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-58731
6.2 MEDIUM

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional …

Sep 15, 2026
CVE-2026-58726
6.7 MEDIUM

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with …

Sep 15, 2026
CVE-2026-58721
4.4 MEDIUM

In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges …

Sep 15, 2026
CVE-2026-58718
6.7 MEDIUM

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with …

Sep 15, 2026
CVE-2026-58716
6.7 MEDIUM

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-58698
6.7 MEDIUM

In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-57042
6.7 MEDIUM

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with …

Sep 15, 2026
CVE-2026-57035
6.7 MEDIUM

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-57006
4.4 MEDIUM

In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information disclosure with System …

Sep 15, 2026
CVE-2026-56992
6.7 MEDIUM

In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution …

Sep 15, 2026
CVE-2026-56989
6.7 MEDIUM

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-56988
6.4 MEDIUM

In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-56979
6.7 MEDIUM

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege …

Sep 15, 2026
CVE-2026-56975
6.5 MEDIUM

In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with …

Sep 15, 2026
CVE-2026-56973
6.7 MEDIUM

In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of …

Sep 15, 2026
CVE-2026-56972
6.7 MEDIUM

In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-56964
6.4 MEDIUM

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges …

Sep 15, 2026
CVE-2026-56958
5.5 MEDIUM

In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Sep 15, 2026
CVE-2026-56950
4.4 MEDIUM

In validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution …

Sep 15, 2026
CVE-2026-56932
6.7 MEDIUM

In Trusted Execution Environment, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-56923
6.4 MEDIUM

In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no …

Sep 15, 2026
CVE-2026-56922
6.7 MEDIUM

In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges …

Sep 15, 2026
CVE-2026-56915
6.4 MEDIUM

In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege with …

Sep 15, 2026
CVE-2026-56907
6.7 MEDIUM

In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with System execution …

Sep 15, 2026
CVE-2026-56892
6.2 MEDIUM

In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no …

Sep 15, 2026
CVE-2026-56889
6.7 MEDIUM

In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with System execution …

Sep 15, 2026
CVE-2026-56888
6.2 MEDIUM

In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no …

Sep 15, 2026
CVE-2026-56879
6.7 MEDIUM

In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-55365
6.7 MEDIUM

In multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Sep 15, 2026
CVE-2026-55332
6.7 MEDIUM

In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution …

Sep 15, 2026
CVE-2026-55317
6.7 MEDIUM

In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System …

Sep 15, 2026
CVE-2026-55304
6.7 MEDIUM

In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation …

Sep 15, 2026
CVE-2026-55302
6.7 MEDIUM

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege …

Sep 15, 2026
CVE-2026-19641
5.3 MEDIUM

On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can …

Sep 15, 2026
CVE-2026-19504
4.0 MEDIUM

Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is …

Sep 15, 2026
CVE-2026-0197
4.4 MEDIUM

In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local information disclosure with System …

Sep 15, 2026
CVE-2026-0192
6.7 MEDIUM

In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System …

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.