VYPR

CVEs

378,267 total · page 67 of 7,566

  • CVE-2026-68529LowSep 15, 2026
    risk 0.14cvss epss 0.00

    Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express entity directly from a user-supplied entity ID and rendered…

  • CVE-2026-66790Sep 15, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerability. Please use CVE-2026-70496 instead.

  • CVE-2026-66789Sep 15, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70495, which describes the same vulnerability. Please use CVE-2026-70495 instead.

  • CVE-2026-58773MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58767MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58766HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58765MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58755MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58751MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58747MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58744HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58739MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58734HigSep 15, 2026
    risk 0.46cvss 7.0epss 0.00

    In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58731MedSep 15, 2026
    risk 0.40cvss 6.2epss 0.00

    In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58728HigSep 15, 2026
    risk 0.46cvss 7.0epss 0.00

    In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58726MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58724HigSep 15, 2026
    risk 0.46cvss 7.0epss 0.00

    In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58721MedSep 15, 2026
    risk 0.29cvss 4.4epss 0.00

    In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58718MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58716MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58710HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58704HigKEVSep 15, 2026
    risk 0.69cvss 8.8epss 0.00

    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58701HigSep 15, 2026
    risk 0.46cvss 7.0epss 0.00

    In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58699HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58698MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58695HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58691HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58683HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58679HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-58678HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-57042MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-57035MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-57014HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-57012HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-57008HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-57006MedSep 15, 2026
    risk 0.29cvss 4.4epss 0.00

    In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56997HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56992MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56989MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56988MedSep 15, 2026
    risk 0.42cvss 6.4epss 0.00

    In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56986HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56985HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56982HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56979MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56978HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56975MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56974HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2026-56973MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56972MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56970HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.