Vulnerabilities

Summary — last 7 days

New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
–

9,099 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (5.4)0.13%—Mozilla Firefox AndroidAI9/29/202610/1/2026
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
Awaiting AnalysisMedium (5.3)0.32%—Wikimedia Wikipedia Android APPAI9/25/20269/28/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main.
Awaiting AnalysisMedium (6.9)0.19%—Verizon Cloud FOR AndroidAI9/17/20269/22/2026
Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value containing path-traversal sequences through…
AnalyzedMedium (6.7)0.10%—Google Android9/15/20269/18/2026
In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.10%—Google Android9/15/20269/18/2026
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedHigh (7.8)0.10%—Google Android9/15/20269/18/2026
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.10%—Google Android9/15/20269/18/2026
In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.10%—Google Android9/15/20269/18/2026
In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.10%—Google Android9/15/20269/18/2026
In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.10%—Google Android9/15/20269/18/2026
In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedHigh (7.8)0.10%—Google Android9/15/20269/18/2026
In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.09%—Google Android9/15/20269/18/2026
In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedHigh (7)0.07%—Google Android9/15/20269/18/2026
In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.2)0.10%—Google Android9/15/20269/18/2026
In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalyzedHigh (7)0.07%—Google Android9/15/20269/18/2026
In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.10%—Google Android9/15/20269/18/2026
In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedHigh (7)0.07%—Google Android9/15/20269/18/2026
In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (4.4)0.09%—Google Android9/15/20269/18/2026
In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.10%—Google Android9/15/20269/18/2026
In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.08%—Google Android9/15/20269/18/2026
In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedHigh (8.8)0.37%—Google Android9/15/20269/18/2026
In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalyzedHigh (8.8)0.59%⚠ Active exploitationGoogle Android9/15/20269/17/2026
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalyzedHigh (7)0.07%—Google Android9/15/20269/18/2026
In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
AnalyzedHigh (8.4)0.10%—Google Android9/15/20269/18/2026
In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalyzedMedium (6.7)0.10%—Google Android9/15/20269/18/2026
In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.