Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.7 MEDIUM
CVE-2026-20511 — SurfaceFlinger Use-After-Free Vulnerability

In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User i…

Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
6.7 MEDIUM
CVE-2026-20510 — Camera Middleware Double Free Privilege Escalation

In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. …

Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
6.7 MEDIUM
CVE-2026-20509 — Power HAL Out-of-Bounds Write Vulnerability

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. U…

Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
6.7 MEDIUM
CVE-2026-20508 — Power HAL Type Confusion Vulnerability

In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User …

Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
6.7 MEDIUM
CVE-2026-20507 — Audio HAL Use-After-Free Privilege Escalation

In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User …

Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
6.7 MEDIUM
CVE-2026-20506 — Audio HAL Use-After-Free Privilege Escalation

In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User …

Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-20504 — Modem System Denial of Service Vulnerability

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with n…

mt2735 mt6833 mt6853 mt6855 mt6873 mt6875 +32 more | Denial of Service
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-20503 — Modem System Denial of Service Vulnerability

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with n…

mt2735 mt6813 mt6833 mt6835 mt6853 mt6855 +108 more | Denial of Service
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
8.4 HIGH
CVE-2026-20502 — Vdec Out-of-Bounds Write Vulnerability

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…

mt8696_firmware mt6779 mt6781 mt6785 mt6789 mt6833 +100 more | Memory Corruption
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
8.4 HIGH
CVE-2026-20501 — MediaTek VDEC Heap Buffer Overflow

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…

mt8696_firmware mt6779 mt6781 mt6785 mt6789 mt6833 +100 more | Memory Corruption
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
5.5 MEDIUM
CVE-2026-20500 — Modem Improper Input Validation Denial of Service

In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitat…

mt6835 mt6878 mt6897 mt8676 mt8678 mt8755 +38 more | Denial of Service
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
9.3 CRITICAL
CVE-2026-16876 — NEC UNIVERGE IX-R/IX-V Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and s…

Remote | Authentication
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
Showing 20 of 15452 Results