Export limit exceeded: 402951 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402951 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104809 | 2026-10-05 | N/A | ||
| DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine. | ||||
| CVE-2026-104675 | 2026-10-05 | 4.3 Medium | ||
| Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. | ||||
| CVE-2026-104401 | 2026-10-05 | 4.3 Medium | ||
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2. | ||||
| CVE-2026-104388 | 2026-10-05 | 5.3 Medium | ||
| Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9. | ||||
| CVE-2026-103351 | 2026-10-05 | 5.3 Medium | ||
| Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1. | ||||
| CVE-2026-103335 | 2026-10-05 | N/A | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Retrieve Embedded Sensitive Data.This issue affects Video Conferencing with Zoom: from n/a through 4.6.10. | ||||
| CVE-2026-103084 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeapWorx Premium Addons for Elementor premium-addons-for-elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.11.109. | ||||
| CVE-2026-63045 | 2 Apache, Redhat | 3 Apache Http Server, Http Server, Hummingbird | 2026-10-05 | 7.5 High |
| Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue. | ||||
| CVE-2026-20526 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 7.5 High |
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01898195; Issue ID: MSV-8906. | ||||
| CVE-2026-20527 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 / MOLY01210562; Issue ID: MSV-8303. | ||||
| CVE-2026-20579 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9800. | ||||
| CVE-2026-20587 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In mtee, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9608. | ||||
| CVE-2026-20588 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In mtee, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9607. | ||||
| CVE-2026-20529 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11276677; Issue ID: MSV-9217. | ||||
| CVE-2026-20530 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11292777; Issue ID: MSV-9195. | ||||
| CVE-2026-20534 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01797547; Issue ID: MSV-9155. | ||||
| CVE-2026-20535 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In aidl, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185216; Issue ID: MSV-9039. | ||||
| CVE-2026-20537 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185225; Issue ID: MSV-9024. | ||||
| CVE-2026-20539 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8913. | ||||
| CVE-2026-20542 | 1 Mediatek | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11076799; Issue ID: MSV-8143. | ||||