Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57048
Total
4535
Critical
16933
High
16775
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55302 | MEDIUM | 6.7 | In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege … | Sep 15, 2026 |
| CVE-2026-55301 | UNKNOWN | — | In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with … | Sep 15, 2026 |
| CVE-2026-19886 | HIGH | 7.8 | OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … | Sep 15, 2026 |
| CVE-2026-19885 | HIGH | 7.8 | OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … | Sep 15, 2026 |
| CVE-2026-19781 | HIGH | 7.8 | Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … | Sep 15, 2026 |
| CVE-2026-19774 | HIGH | 7.1 | BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker … | Sep 15, 2026 |
| CVE-2026-19773 | CRITICAL | 9.8 | libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … | Sep 15, 2026 |
| CVE-2026-19641 | MEDIUM | 5.3 | On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can … | Sep 15, 2026 |
| CVE-2026-19504 | MEDIUM | 4.0 | Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is … | Sep 15, 2026 |
| CVE-2026-18421 | UNKNOWN | — | Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), … | Sep 15, 2026 |
| CVE-2026-0200 | HIGH | 8.8 | In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no … | Sep 15, 2026 |
| CVE-2026-0199 | HIGH | 7.8 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no … | Sep 15, 2026 |
| CVE-2026-0197 | MEDIUM | 4.4 | In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local information disclosure with System … | Sep 15, 2026 |
| CVE-2026-0194 | UNKNOWN | — | In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with no additional … | Sep 15, 2026 |
| CVE-2026-0192 | UNKNOWN | — | In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System … | Sep 15, 2026 |
| CVE-2026-0189 | UNKNOWN | — | In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of … | Sep 15, 2026 |
| CVE-2026-0187 | UNKNOWN | — | In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … | Sep 15, 2026 |
| CVE-2026-0186 | UNKNOWN | — | In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … | Sep 15, 2026 |
| CVE-2026-0183 | MEDIUM | 4.4 | In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. … | Sep 15, 2026 |
| CVE-2026-0179 | UNKNOWN | — | In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution … | Sep 15, 2026 |
| CVE-2026-0177 | MEDIUM | 4.4 | In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System … | Sep 15, 2026 |
| CVE-2026-0171 | HIGH | 8.8 | In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with … | Sep 15, 2026 |
| CVE-2026-0170 | HIGH | 8.8 | In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with … | Sep 15, 2026 |
| CVE-2026-0159 | HIGH | 8.8 | In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional … | Sep 15, 2026 |
| CVE-2026-88765 | HIGH | 8.5 | GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions … | Sep 15, 2026 |