Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57048
Total
4535
Critical
16933
High
16775
Medium
CVE ID Severity Score Description Published
CVE-2026-55302 MEDIUM 6.7 In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege … Sep 15, 2026
CVE-2026-55301 UNKNOWN — In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with … Sep 15, 2026
CVE-2026-19886 HIGH 7.8 OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … Sep 15, 2026
CVE-2026-19885 HIGH 7.8 OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … Sep 15, 2026
CVE-2026-19781 HIGH 7.8 Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … Sep 15, 2026
CVE-2026-19774 HIGH 7.1 BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker … Sep 15, 2026
CVE-2026-19773 CRITICAL 9.8 libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … Sep 15, 2026
CVE-2026-19641 MEDIUM 5.3 On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can … Sep 15, 2026
CVE-2026-19504 MEDIUM 4.0 Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is … Sep 15, 2026
CVE-2026-18421 UNKNOWN — Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), … Sep 15, 2026
CVE-2026-0200 HIGH 8.8 In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no … Sep 15, 2026
CVE-2026-0199 HIGH 7.8 In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no … Sep 15, 2026
CVE-2026-0197 MEDIUM 4.4 In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local information disclosure with System … Sep 15, 2026
CVE-2026-0194 UNKNOWN — In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with no additional … Sep 15, 2026
CVE-2026-0192 UNKNOWN — In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System … Sep 15, 2026
CVE-2026-0189 UNKNOWN — In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of … Sep 15, 2026
CVE-2026-0187 UNKNOWN — In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … Sep 15, 2026
CVE-2026-0186 UNKNOWN — In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … Sep 15, 2026
CVE-2026-0183 MEDIUM 4.4 In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. … Sep 15, 2026
CVE-2026-0179 UNKNOWN — In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution … Sep 15, 2026
CVE-2026-0177 MEDIUM 4.4 In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System … Sep 15, 2026
CVE-2026-0171 HIGH 8.8 In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with … Sep 15, 2026
CVE-2026-0170 HIGH 8.8 In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with … Sep 15, 2026
CVE-2026-0159 HIGH 8.8 In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional … Sep 15, 2026
CVE-2026-88765 HIGH 8.5 GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions … Sep 15, 2026