Vulnerabilities
Summary — last 7 days
New vulnerabilities3,037▲ 502 vs. last week
Critical / high1,448▲ 249 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)365▲ 158 vs. last week
15 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (5.3) | 0.19% | — | Mediatek Mt2735 FirmwareMediatek Mt6833 FirmwareMediatek Mt6853 FirmwareMediatek Mt6855 Firmware+15 | 9/7/2026 | 9/9/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue… | |
| Analyzed | Medium (5.3) | 0.19% | — | Mediatek Mt2716 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 Firmware+53 | 9/7/2026 | 9/9/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue… | |
| Analyzed | High (8.4) | 0.13% | — | Mediatek Mt2718 FirmwareMediatek Mt6580 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+49 | 9/7/2026 | 9/9/2026 | In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196. | |
| Analyzed | High (8.4) | 0.13% | — | Mediatek Mt2718 FirmwareMediatek Mt6580 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+49 | 9/7/2026 | 9/9/2026 | In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197. | |
| Analyzed | Medium (4.4) | 0.16% | — | Mediatek Mt8799 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 Firmware+35 | 8/3/2026 | 8/19/2026 | In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004. | |
| Analyzed | High (7.7) | 0.17% | — | Mediatek Mt8893 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 Firmware+31 | 8/3/2026 | 8/19/2026 | In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243. | |
| Analyzed | High (7.5) | 0.71% | — | Mediatek Mt2735 FirmwareMediatek Mt6833 FirmwareMediatek Mt6853 FirmwareMediatek Mt6855 Firmware+15 | 8/3/2026 | 8/19/2026 | In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071;… | |
| Analyzed | High (7.8) | 0.11% | — | Mediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 FirmwareMediatek Mt6768 Firmware+32 | 6/1/2026 | 7/22/2026 | In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784. | |
| Analyzed | Medium (6.4) | 0.08% | — | Mediatek Mt8673 FirmwareMediatek Mt8765 FirmwareMediatek Mt8766 FirmwareMediatek Mt8768 Firmware+32 | 6/1/2026 | 7/22/2026 | In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786. | |
| Analyzed | Medium (6.7) | 0.11% | — | Mediatek Mt8673 FirmwareMediatek Mt8765 FirmwareMediatek Mt8766 FirmwareMediatek Mt8768 Firmware+32 | 6/1/2026 | 7/22/2026 | In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791. | |
| Analyzed | Medium (6.5) | 0.29% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6833 FirmwareMediatek Mt6835 Firmware+47 | 5/4/2026 | 6/17/2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620;… | |
| Analyzed | Medium (6.5) | 0.22% | — | Mediatek Mt6763 FirmwareMediatek Mt6765 FirmwareMediatek Mt6767 FirmwareMediatek Mt6768 Firmware+64 | 5/4/2026 | 6/17/2026 | In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue… | |
| Analyzed | High (8.8) | 0.34% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 FirmwareMediatek Mt6833 Firmware+58 | 4/7/2026 | 6/17/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:… | |
| Analyzed | High (8) | 0.29% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6779 FirmwareMediatek Mt6781 Firmware+54 | 4/7/2026 | 7/24/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:… | |
| Modified | Medium (6.5) | 0.36% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+81 | 4/7/2025 | 6/17/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01519028;… |