Export limit exceeded: 372692 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372692 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18590 | 1 Wavlink | 2 Wl-nu516u1, Wl-nu516u1 Firmware | 2026-08-03 | 6.3 Medium |
| A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | ||||
| CVE-2026-12259 | 1 Nltk | 1 Nltk/nltk | 2026-08-03 | N/A |
| In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for `info.url` through a compromised mirror, malicious proxy, or other source-substitution condition, leading to the installation of attacker-controlled package bytes. The vulnerability can result in malicious corpus or model content being trusted by downstream users or applications. | ||||
| CVE-2026-28147 | 2 Unlimited-elements, Wordpress | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress | 2026-08-03 | 5.4 Medium |
| Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15. | ||||
| CVE-2026-3245 | 2026-08-03 | 7.5 High | ||
| A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. | ||||
| CVE-2026-65875 | 2026-08-03 | 7.1 High | ||
| BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed. | ||||
| CVE-2026-20464 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11104718; Issue ID: MSV-8297. | ||||
| CVE-2026-20467 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767. | ||||
| CVE-2026-20468 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741. | ||||
| CVE-2026-20469 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533. | ||||
| CVE-2026-20472 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764. | ||||
| CVE-2026-16563 | 2 Academylms, Wordpress | 2 Academy Lms, Wordpress | 2026-08-03 | N/A |
| The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons. | ||||
| CVE-2026-20474 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758. | ||||
| CVE-2026-20475 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748. | ||||
| CVE-2026-20476 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660. | ||||
| CVE-2026-20478 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638. | ||||
| CVE-2026-20483 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243. | ||||
| CVE-2026-20484 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004. | ||||
| CVE-2026-20485 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931. | ||||
| CVE-2026-20486 | 2026-08-03 | N/A | ||
| In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833. | ||||
| CVE-2026-20488 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-08-03 | N/A |
| In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757. | ||||