Export limit exceeded: 393090 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 393090 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (393090 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-90451 | 1 Cisagov | 1 Malcolm | 2026-09-15 | N/A |
| An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component. | ||||
| CVE-2026-90453 | 1 Cisagov | 1 Malcolm | 2026-09-15 | N/A |
| A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload. | ||||
| CVE-2026-56889 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56907 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56914 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56915 | 1 Google | 1 Android | 2026-09-15 | 6.4 Medium |
| In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56923 | 1 Google | 1 Android | 2026-09-15 | 6.4 Medium |
| In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56932 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In Trusted Execution Environment, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56960 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56970 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56978 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56979 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56982 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56986 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-57012 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-58678 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-58695 | 1 Google | 1 Android | 2026-09-15 | N/A |
| In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-68070 | 2026-09-15 | 8.8 High | ||
| The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command. | ||||
| CVE-2026-54544 | 2026-09-15 | 7.2 High | ||
| Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-discord-webhook or POST /api/test-webhook and cause the Fireshare server to issue an arbitrary HTTP POST to any URL the attacker supplies, including internal network addresses and cloud metadata services. No credentials, session cookies, or prior access are required. Version 1.6.16 contains a patch. | ||||
| CVE-2026-66890 | 2026-09-15 | 9.6 Critical | ||
| The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable. | ||||