Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-55270 — Android DialInternal Confused Deputy Privilege Escalation

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed.…

android | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.8 HIGH
CVE-2026-55269 — Snoop Logger Memory Safety Vulnerability

In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution pri…

android | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.8 HIGH
CVE-2026-55266 — Libufdt Out-of-Bounds Write Privilege Escalation

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges need…

android | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-55265 — Android PduParser Out-of-Bounds Read Vulnerability

In multiple functions of PduParser.java, there is a possible out of bounds read due to a missing bounds check. This could lead to a remote denial of service with no additional execution privileges ne…

android | Remote | Denial of Service
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.8 HIGH
CVE-2026-49937 — MessageQueueBase Out-of-Bounds Read Vulnerability

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution pri…

android | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.8 HIGH
CVE-2026-49933 — Android Bluetooth Uninitialized Pointer Dereference

In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalat…

android | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.8 HIGH
CVE-2026-49885 — Android rw_t4t Integer Overflow Out-of-Bounds Write

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed…

android | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-49880 — NXP NCI Stack Out-of-Bounds Write Vulnerability

In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privile…

android | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.2 HIGH
CVE-2026-49878 — WPA Supplicant Out-of-Bounds Write Vulnerability

In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privi…

android | Remote | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
8.8 HIGH
CVE-2026-45524 — Android WifiPermissionsUtil Sandbox Escape Local Privilege Escalation

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges…

android | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.5 MEDIUM
CVE-2026-28667 — Android NXP NFC Stack Out-of-Bounds Read

In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges neede…

android | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-28648 — Android Settings Local Privilege Escalation

In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…

android | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-28647 — Android DeviceAdminAppsPreferenceController Permission Bypass

In updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional…

android | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-28641 — Android ApplicationActionButtonsPreferenceController Permission Bypass Vulnerability

In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of pr…

android | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-28640 — Android CredentialStorageActivity Permission Bypass Local Privilege Escalation

In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privileg…

android | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-28625 — [Product/Vendor Name] Permission Bypass via Logic Error

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User in…

android | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
3.6 LOW
CVE-2026-105712 — GnuPG gpgtar Arbitrary File Overwrite Vulnerability

gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-exist…

gnupg | Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.9 MEDIUM
CVE-2026-105646 — Ghost: Regular Expression Denial of Service in Content Import

Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Ad…

ghost | Remote | Denial of Service
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.9 MEDIUM
CVE-2026-105645 — Ghost: Regular Expression Denial of Service in External Media Inliner

Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause excessive CPU usage, making the Ghost server unresponsive. Exploiti…

ghost | Remote | Denial of Service
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.8 MEDIUM
CVE-2026-105644 — Ghost: Stored XSS via SVG Files in Content Imports

Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a …

ghost | Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
Showing 20 of 14519 Results