Export limit exceeded: 402607 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402607 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402607 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103335 | 2026-10-05 | N/A | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Retrieve Embedded Sensitive Data.This issue affects Video Conferencing with Zoom: from n/a through 4.6.10. | ||||
| CVE-2026-103084 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeapWorx Premium Addons for Elementor premium-addons-for-elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.11.109. | ||||
| CVE-2026-63045 | 2 Apache, Redhat | 3 Apache Http Server, Http Server, Hummingbird | 2026-10-05 | 7.5 High |
| Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue. | ||||
| CVE-2026-20526 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 7.5 High |
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01898195; Issue ID: MSV-8906. | ||||
| CVE-2026-20527 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 / MOLY01210562; Issue ID: MSV-8303. | ||||
| CVE-2026-20579 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9800. | ||||
| CVE-2026-20587 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In mtee, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9608. | ||||
| CVE-2026-20588 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In mtee, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9607. | ||||
| CVE-2026-20529 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11276677; Issue ID: MSV-9217. | ||||
| CVE-2026-20530 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11292777; Issue ID: MSV-9195. | ||||
| CVE-2026-20534 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01797547; Issue ID: MSV-9155. | ||||
| CVE-2026-20535 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In aidl, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185216; Issue ID: MSV-9039. | ||||
| CVE-2026-20537 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185225; Issue ID: MSV-9024. | ||||
| CVE-2026-20539 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8913. | ||||
| CVE-2026-20542 | 1 Mediatek | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11076799; Issue ID: MSV-8143. | ||||
| CVE-2026-78371 | 2026-10-05 | 5.9 Medium | ||
| The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files. | ||||
| CVE-2026-104404 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0. | ||||
| CVE-2026-20519 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 7.5 High |
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898. | ||||
| CVE-2026-20589 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9606. | ||||
| CVE-2026-20521 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 8.4 High |
| In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11375674; Issue ID: MSV-9571. | ||||