Export limit exceeded: 372706 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372706 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28147 | 2 Unlimited-elements, Wordpress | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress | 2026-08-03 | 5.4 Medium |
| Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15. | ||||
| CVE-2026-68580 | 1 Freerdp | 1 Freerdp | 2026-08-03 | 7.5 High |
| FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms. | ||||
| CVE-2026-3245 | 2026-08-03 | 7.5 High | ||
| A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. | ||||
| CVE-2026-65875 | 2026-08-03 | 7.1 High | ||
| BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed. | ||||
| CVE-2026-20464 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11104718; Issue ID: MSV-8297. | ||||
| CVE-2026-20467 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767. | ||||
| CVE-2026-20468 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741. | ||||
| CVE-2026-20469 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533. | ||||
| CVE-2026-20472 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764. | ||||
| CVE-2026-16563 | 2 Academylms, Wordpress | 2 Academy Lms, Wordpress | 2026-08-03 | N/A |
| The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons. | ||||
| CVE-2026-65526 | 2 Themeisle, Wordpress | 2 Visualizer, Wordpress | 2026-08-03 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1. | ||||
| CVE-2026-20474 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758. | ||||
| CVE-2026-20475 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748. | ||||
| CVE-2026-20476 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660. | ||||
| CVE-2026-20478 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638. | ||||
| CVE-2026-20483 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243. | ||||
| CVE-2026-20484 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004. | ||||
| CVE-2026-20485 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931. | ||||
| CVE-2026-20486 | 2026-08-03 | N/A | ||
| In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833. | ||||
| CVE-2026-20488 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757. | ||||