Export limit exceeded: 372114 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372114 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-20464 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11104718; Issue ID: MSV-8297. | ||||
| CVE-2026-20467 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767. | ||||
| CVE-2026-20468 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741. | ||||
| CVE-2026-20469 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533. | ||||
| CVE-2026-20472 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764. | ||||
| CVE-2026-16563 | 2 Academylms, Wordpress | 2 Academy Lms, Wordpress | 2026-08-03 | N/A |
| The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons. | ||||
| CVE-2026-65526 | 2 Themeisle, Wordpress | 2 Visualizer, Wordpress | 2026-08-03 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1. | ||||
| CVE-2026-20475 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748. | ||||
| CVE-2026-20483 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243. | ||||
| CVE-2026-20488 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757. | ||||
| CVE-2026-20490 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669. | ||||
| CVE-2026-20491 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652. | ||||
| CVE-2026-20494 | 1 Mediatek | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570. | ||||
| CVE-2026-20495 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296. | ||||
| CVE-2026-20496 | 1 Mediatek | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132. | ||||
| CVE-2026-16274 | 2026-08-03 | N/A | ||
| The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership. | ||||
| CVE-2026-16534 | 2026-08-03 | N/A | ||
| The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email. | ||||
| CVE-2025-15672 | 2026-08-03 | N/A | ||
| The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code. | ||||
| CVE-2026-12872 | 2026-08-03 | N/A | ||
| The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path. | ||||
| CVE-2026-15231 | 2026-08-03 | N/A | ||
| The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own. | ||||