CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2026-26892

    Last Modified: 16 Apr 2026

    Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.

    Published: 3 Mar 2026
    8.8
    High

    CVE-2026-1566

    Last Modified: 22 Apr 2026

    The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 5.2.7. This is due to the plugin allowing users with a LatePoint Agent role, who are creating new customers to set the 'wordpress_user_id' field. This makes it possible for authenticated attackers, with Agent-level access and above, to gain elevated privileges by linking a customer to the arbitrary user ID, including administrators, and then resetting the password.

    Published: 2 Mar 2026
    5.3
    Medium

    CVE-2026-1336

    Last Modified: 22 Apr 2026

    The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the store_data() and get_chatgpt_api_key() functions in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to view, modify or delete the plugin's ChatGPT API key. The vulnerability was partially fixed in version 2.7.5 and fully fixed in version 2.7.6

    Published: 2 Mar 2026
    6.4
    Medium

    CVE-2026-2583

    Last Modified: 22 Apr 2026

    The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in all versions up to, and including, 2.1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Mar 2026
    8.7
    High

    CVE-2026-3338

    Last Modified: 17 Apr 2026

    Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

    Published: 2 Mar 2026
    8.2
    High

    CVE-2026-3337

    Last Modified: 17 Apr 2026

    Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

    Published: 2 Mar 2026
    8.7
    High

    CVE-2026-3336

    Last Modified: 17 Apr 2026

    Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

    Published: 2 Mar 2026
    6.5
    Medium

    CVE-2026-2256

    Last Modified: 21 Apr 2026

    A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

    Published: 2 Mar 2026
    2.7
    Low

    CVE-2026-25884

    Last Modified: 18 Apr 2026

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

    Published: 2 Mar 2026
    2.7
    Low

    CVE-2026-27596

    Last Modified: 16 Apr 2026

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. The out-of-bounds read is at a 4GB offset, which usually causes Exiv2 to crash. This issue has been patched in version 0.28.8.

    Published: 2 Mar 2026
    2.7
    Low

    CVE-2026-27631

    Last Modified: 16 Apr 2026

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. Due to an integer overflow, the code attempts to create a huge std::vector, which causes Exiv2 to crash with an uncaught exception. This issue has been patched in version 0.28.8.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-21882

    Last Modified: 16 Apr 2026

    theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege dropping allows local privilege escalation via command re-execution. This issue has been patched in version 0.2.0.

    Published: 2 Mar 2026
    6.9
    Medium

    CVE-2026-25477

    Last Modified: 16 Apr 2026

    AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an improperly anchored Regular Expression allows an attacker to bypass the whitelist by using malicious domains that end with a trusted string. This issue has been patched in version 0.26.0.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2025-48636

    Last Modified: 6 Mar 2026

    In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.8
    High

    CVE-2024-31328

    Last Modified: 6 Mar 2026

    In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on the paired companion phone due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.8
    High

    CVE-2026-21853

    Last Modified: 20 Apr 2026

    AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This vulnerability can be exploited by embedding a specially crafted affine: URL on a website. An attacker can trigger the vulnerability in two common scenarios: 1/ A victim visits a malicious website controlled by the attacker and the website redirect to the URL automatically, or 2/ A victim clicks on a crafted link embedded on a legitimate website (e.g., in user-generated content). In both cases, the browser invokes AFFiNE custom URL handler, which launches the AFFiNE app and processes the crafted URL. This results in arbitrary code execution on the victim’s machine, without further interaction. This issue has been patched in version 0.25.4.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0047

    Last Modified: 16 Apr 2026

    In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0038

    Last Modified: 17 Apr 2026

    In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0037

    Last Modified: 17 Apr 2026

    In multiple functions of ffa.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0035

    Last Modified: 17 Apr 2026

    In createRequest of MediaProvider.java, there is a possible way for an app to gain read/write access to non-existing files due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0034

    Last Modified: 16 Apr 2026

    In setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    7.8
    High

    CVE-2026-0032

    Last Modified: 16 Apr 2026

    In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0031

    Last Modified: 16 Apr 2026

    In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0030

    Last Modified: 16 Apr 2026

    In __host_check_page_state_range of mem_protect.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0029

    Last Modified: 16 Apr 2026

    In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0028

    Last Modified: 17 Apr 2026

    In __pkvm_host_share_guest of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    6.7
    Medium

    CVE-2026-0027

    Last Modified: 18 Apr 2026

    In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    7.8
    High

    CVE-2026-0026

    Last Modified: 16 Apr 2026

    In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0025

    Last Modified: 18 Apr 2026

    In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    4
    Medium

    CVE-2026-0024

    Last Modified: 16 Apr 2026

    In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    7.8
    High

    CVE-2026-0023

    Last Modified: 16 Apr 2026

    In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0021

    Last Modified: 16 Apr 2026

    In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0020

    Last Modified: 16 Apr 2026

    In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    7.7
    High

    CVE-2026-0017

    Last Modified: 18 Apr 2026

    In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    6.2
    Medium

    CVE-2026-0015

    Last Modified: 16 Apr 2026

    In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    6.2
    Medium

    CVE-2026-0014

    Last Modified: 16 Apr 2026

    In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0013

    Last Modified: 26 Aug 2026

    In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    6.2
    Medium

    CVE-2026-0012

    Last Modified: 26 Aug 2026

    In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0011

    Last Modified: 26 Aug 2026

    In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0010

    Last Modified: 8 Sept 2026

    In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2026-0008

    Last Modified: 10 Sept 2026

    In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.6
    High

    CVE-2026-0007

    Last Modified: 16 Apr 2026

    In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    9.8
    Critical

    CVE-2026-0006

    Last Modified: 16 Apr 2026

    In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    6.2
    Medium

    CVE-2026-0005

    Last Modified: 16 Apr 2026

    In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other apps without knowing the LSKF due to a missing permission check. This could lead to local information disclosure where the extent of interaction and impact is app-dependent with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    7.8
    High

    CVE-2025-48654

    Last Modified: 6 Mar 2026

    In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    7.8
    High

    CVE-2025-48653

    Last Modified: 6 Mar 2026

    In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    8.4
    High

    CVE-2025-48650

    Last Modified: 6 Mar 2026

    In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    7.8
    High

    CVE-2025-48646

    Last Modified: 6 Mar 2026

    In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 2 Mar 2026
    7.8
    High

    CVE-2025-48645

    Last Modified: 22 Apr 2026

    In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026
    5.5
    Medium

    CVE-2025-48644

    Last Modified: 6 Mar 2026

    In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Mar 2026