CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2026-79721

    Last Modified: 11 Sept 2026

    Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

    Published: 8 Sept 2026
    9.3
    Critical

    CVE-2026-76200

    Last Modified: 11 Sept 2026

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

    Published: 8 Sept 2026
    9.3
    Critical

    CVE-2026-76201

    Last Modified: 9 Sept 2026

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-77109

    Last Modified: 9 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    7.6
    High

    CVE-2026-77110

    Last Modified: 10 Sept 2026

    Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-77108

    Last Modified: 11 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

    Published: 8 Sept 2026
    8.2
    High

    CVE-2026-76202

    Last Modified: 10 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-77774

    Last Modified: 9 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    8.7
    High

    CVE-2026-77111

    Last Modified: 11 Sept 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58941

    Last Modified: 11 Sept 2026

    In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58874

    Last Modified: 11 Sept 2026

    In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7
    High

    CVE-2026-58848

    Last Modified: 11 Sept 2026

    In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58846

    Last Modified: 11 Sept 2026

    In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58839

    Last Modified: 11 Sept 2026

    In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58823

    Last Modified: 11 Sept 2026

    In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    9.8
    Critical

    CVE-2026-58822

    Last Modified: 11 Sept 2026

    In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-58820

    Last Modified: 10 Sept 2026

    In multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege with no additional execution privileges required.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-55294

    Last Modified: 11 Sept 2026

    In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.3
    Low

    CVE-2026-55290

    Last Modified: 11 Sept 2026

    In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-55285

    Last Modified: 11 Sept 2026

    In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    8
    High

    CVE-2026-55277

    Last Modified: 11 Sept 2026

    In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-55273

    Last Modified: 11 Sept 2026

    In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-55256

    Last Modified: 11 Sept 2026

    In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49932

    Last Modified: 11 Sept 2026

    In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49927

    Last Modified: 11 Sept 2026

    In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    9.8
    Critical

    CVE-2026-49921

    Last Modified: 11 Sept 2026

    In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49919

    Last Modified: 10 Sept 2026

    In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49918

    Last Modified: 11 Sept 2026

    In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.5
    Low

    CVE-2026-49895

    Last Modified: 11 Sept 2026

    In get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49887

    Last Modified: 11 Sept 2026

    In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49884

    Last Modified: 11 Sept 2026

    In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-49882

    Last Modified: 10 Sept 2026

    In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-49881

    Last Modified: 11 Sept 2026

    In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-49879

    Last Modified: 11 Sept 2026

    In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-45531

    Last Modified: 10 Sept 2026

    In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.3
    High

    CVE-2026-45528

    Last Modified: 11 Sept 2026

    In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 8 Sept 2026
    4.3
    Medium

    CVE-2026-45527

    Last Modified: 11 Sept 2026

    In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.3
    Low

    CVE-2026-45525

    Last Modified: 11 Sept 2026

    In multiple locations, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.3
    Low

    CVE-2026-45521

    Last Modified: 11 Sept 2026

    In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-45520

    Last Modified: 10 Sept 2026

    In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.3
    Low

    CVE-2026-45519

    Last Modified: 11 Sept 2026

    In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-45515

    Last Modified: 10 Sept 2026

    In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.3
    Low

    CVE-2026-28671

    Last Modified: 11 Sept 2026

    In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-28668

    Last Modified: 11 Sept 2026

    In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    8.8
    High

    CVE-2026-28666

    Last Modified: 11 Sept 2026

    In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-28664

    Last Modified: 11 Sept 2026

    In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-28663

    Last Modified: 11 Sept 2026

    In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    8
    High

    CVE-2026-28662

    Last Modified: 10 Sept 2026

    In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    3.3
    Low

    CVE-2026-28660

    Last Modified: 11 Sept 2026

    In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-28658

    Last Modified: 10 Sept 2026

    In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    Items Per Page