Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25301
Total
1888
Critical
7733
High
7926
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-59611 | MEDIUM | 6.7 | Memory corruption in diagnostic services due to absence of input validation | Jun 01, 2026 |
| CVE-2025-59610 | MEDIUM | 6.4 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | Jun 01, 2026 |
| CVE-2025-59609 | MEDIUM | 5.5 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | Jun 01, 2026 |
| CVE-2025-59606 | HIGH | 7.8 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. | Jun 01, 2026 |
| CVE-2025-59605 | HIGH | 7.8 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. | Jun 01, 2026 |
| CVE-2025-59604 | HIGH | 7.8 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. | Jun 01, 2026 |
| CVE-2025-59601 | MEDIUM | 6.5 | Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration. | Jun 01, 2026 |
| CVE-2019-25718 | HIGH | 8.4 | Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through … | Jun 01, 2026 |
| CVE-2026-49491 | HIGH | 8.2 | Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers … | Jun 01, 2026 |
| CVE-2026-40965 | CRITICAL | 10.0 | Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys … | Jun 01, 2026 |
| CVE-2026-40964 | HIGH | 7.5 | Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for … | Jun 01, 2026 |
| CVE-2026-28586 | LOW | 3.3 | In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with … | Jun 01, 2026 |
| CVE-2026-28581 | MEDIUM | 4.0 | In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead … | Jun 01, 2026 |
| CVE-2026-28580 | HIGH | 7.8 | In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with … | Jun 01, 2026 |
| CVE-2026-28578 | MEDIUM | 5.5 | In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service … | Jun 01, 2026 |
| CVE-2026-28577 | HIGH | 7.8 | In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no … | Jun 01, 2026 |
| CVE-2026-10294 | MEDIUM | 4.3 | A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation … | Jun 01, 2026 |
| CVE-2026-10293 | HIGH | 8.8 | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formFireWall. This manipulation of the … | Jun 01, 2026 |
| CVE-2026-10292 | HIGH | 8.8 | A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based … | Jun 01, 2026 |
| CVE-2026-10291 | MEDIUM | 4.3 | A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the … | Jun 01, 2026 |
| CVE-2026-10290 | HIGH | 7.3 | A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of … | Jun 01, 2026 |
| CVE-2026-0100 | HIGH | 7.8 | In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of … | Jun 01, 2026 |
| CVE-2026-0099 | HIGH | 7.8 | In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This … | Jun 01, 2026 |
| CVE-2026-0098 | HIGH | 7.8 | In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation … | Jun 01, 2026 |
| CVE-2026-0097 | HIGH | 8.0 | In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead … | Jun 01, 2026 |