VYPR

CVEs

378,267 total · page 68 of 7,566

  • CVE-2026-56967HigSep 15, 2026
    risk 0.52cvss 8.0epss 0.00

    In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56964MedSep 15, 2026
    risk 0.42cvss 6.4epss 0.00

    In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56960CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56958MedSep 15, 2026
    risk 0.36cvss 5.5epss 0.00

    In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56950MedSep 15, 2026
    risk 0.29cvss 4.4epss 0.00

    In validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56945HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56942HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56941HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56932MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In Trusted Execution Environment, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56923MedSep 15, 2026
    risk 0.42cvss 6.4epss 0.00

    In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56922MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56920HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56915MedSep 15, 2026
    risk 0.42cvss 6.4epss 0.00

    In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56914HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56907MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56892MedSep 15, 2026
    risk 0.40cvss 6.2epss 0.00

    In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56889MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56888MedSep 15, 2026
    risk 0.40cvss 6.2epss 0.00

    In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56882HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56881HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-56879MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55366CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55365MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55359HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55351HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55343HigSep 15, 2026
    risk 0.52cvss 8.0epss 0.00

    In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2026-55332MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55331HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55323HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55318HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55317MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55306HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55304MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55302MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-55301HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-19886HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability…

  • CVE-2026-19885HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this…

  • CVE-2026-19781HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability…

  • CVE-2026-19774HigSep 15, 2026
    risk 0.39cvss 7.1epss 0.00

    BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the…

  • CVE-2026-19773CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. …

  • CVE-2026-19641MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being…

  • CVE-2026-19504MedSep 15, 2026
    risk 0.19cvss 4.0epss 0.00

    Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Fabric.js. Interaction with this library is required to exploit this vulnerability but attack vectors may…

  • CVE-2026-18421LowSep 15, 2026
    risk 0.14cvss epss 0.00

    Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboard controller (update, update_data_source, and delete_data_source), which resolve a ConfiguredDataSource directly from an attacker-supplied identifier without…

  • CVE-2026-0200HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0199HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0197MedSep 15, 2026
    risk 0.29cvss 4.4epss 0.00

    In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0194HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0192MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0189HigSep 15, 2026
    risk 0.55cvss 8.4epss 0.00

    In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0187MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.