Export limit exceeded: 383241 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (383241 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-20521 | 2026-10-05 | N/A | ||
| In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11375674; Issue ID: MSV-9571. | ||||
| CVE-2026-20524 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: MSV-9170. | ||||
| CVE-2026-20528 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, memory corruption, crashes, or privilege escalation if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS11428950 (Note: For MT6880, MT6890) / ALPS10563453 (Note: For MT6980D, MT6990, MT6986, MT6986D, MT6813, MT6988) / AUTO00858766 (Note: For MT2735, MT2737); Issue ID: MSV-9893. | ||||
| CVE-2026-20534 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01797547; Issue ID: MSV-9155. | ||||
| CVE-2026-20532 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In apu, there is a possible application crash due to double free. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249024; Issue ID: MSV-9168. | ||||
| CVE-2026-20535 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In aidl, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185216; Issue ID: MSV-9039. | ||||
| CVE-2026-20536 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11242428; Issue ID: MSV-9038. | ||||
| CVE-2026-93495 | 1 Asus | 13 Motherboard Prime Z390-a , Motherboard Prime Z390-a H10 , Motherboard Pro Ws C246-ace and 10 more | 2026-10-05 | N/A |
| Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device. Refer to the ' Security Update for Multiple ASUS Motherboards ' section on the ASUS Security Advisory for more information. | ||||
| CVE-2026-20586 | 2026-10-05 | N/A | ||
| In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9614. | ||||
| CVE-2026-20537 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185225; Issue ID: MSV-9024. | ||||
| CVE-2026-20522 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issue ID: MSV-9172. | ||||
| CVE-2026-20523 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171. | ||||
| CVE-2026-20526 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01898195; Issue ID: MSV-8906. | ||||
| CVE-2026-105225 | 1 Oscommerce | 1 Oscommerce2 | 2026-10-05 | 4.3 Medium |
| A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1. This affects the function include of the file includes/classes/payment.php of the component Payment Page. Such manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-20527 | 2026-10-05 | N/A | ||
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 / MOLY01210562; Issue ID: MSV-8303. | ||||
| CVE-2026-20530 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11292777; Issue ID: MSV-9195. | ||||
| CVE-2026-20531 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | N/A |
| In apu, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249016; Issue ID: MSV-9169. | ||||
| CVE-2026-105188 | 1 Code-projects | 1 Human Resource Management System | 2026-10-05 | 3.5 Low |
| A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. | ||||
| CVE-2026-20519 | 2026-10-05 | N/A | ||
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898. | ||||
| CVE-2026-20579 | 2026-10-05 | N/A | ||
| In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9800. | ||||