Vulnerabilities
Summary — last 7 days
New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
9,099 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (5.4) | 0.13% | — | Mozilla Firefox AndroidAI | 9/29/2026 | 10/1/2026 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157. | |
| Awaiting Analysis | Medium (5.3) | 0.32% | — | Wikimedia Wikipedia Android APPAI | 9/25/2026 | 9/28/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main. | |
| Awaiting Analysis | Medium (6.9) | 0.19% | — | Verizon Cloud FOR AndroidAI | 9/17/2026 | 9/22/2026 | Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value containing path-traversal sequences through… | |
| Analyzed | Medium (6.7) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | High (7.8) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | High (7.8) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.09% | — | Google Android | 9/15/2026 | 9/18/2026 | In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | High (7) | 0.07% | — | Google Android | 9/15/2026 | 9/18/2026 | In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.2) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | High (7) | 0.07% | — | Google Android | 9/15/2026 | 9/18/2026 | In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | High (7) | 0.07% | — | Google Android | 9/15/2026 | 9/18/2026 | In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (4.4) | 0.09% | — | Google Android | 9/15/2026 | 9/18/2026 | In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.08% | — | Google Android | 9/15/2026 | 9/18/2026 | In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | High (8.8) | 0.37% | — | Google Android | 9/15/2026 | 9/18/2026 | In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | High (8.8) | 0.59% | ⚠ Active exploitation | Google Android | 9/15/2026 | 9/17/2026 | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | High (7) | 0.07% | — | Google Android | 9/15/2026 | 9/18/2026 | In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | High (8.4) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analyzed | Medium (6.7) | 0.10% | — | Google Android | 9/15/2026 | 9/18/2026 | In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |