Vulnerabilities

Summary — last 7 days

New vulnerabilities2,625▼ 312 vs. last week
Critical / high1,347▲ 72 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)61▼ 466 vs. last week
–

9 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (5.3)0.19%—Mediatek Mt2716 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 Firmware+539/7/20269/9/2026
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue…
AnalyzedMedium (6)0.17%—Mediatek Mt6991 FirmwareMediatek Mt8768 FirmwareMediatek Mt8791t FirmwareMediatek Mt8792 Firmware+68/3/20268/19/2026
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
AnalyzedMedium (6)0.17%—Mediatek Mt6989 FirmwareMediatek Mt8755 FirmwareMediatek Mt8768 FirmwareMediatek Mt8771 Firmware+78/3/20268/19/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
AnalyzedMedium (4.4)0.15%—Mediatek Mt6983 FirmwareMediatek Mt8676 FirmwareMediatek Mt8678 FirmwareMediatek Mt8755 Firmware+138/3/20268/19/2026
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.
AnalyzedHigh (7.7)0.17%—Mediatek Mt8893 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 Firmware+318/3/20268/19/2026
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.
AnalyzedMedium (6)0.17%—Mediatek Mt6989 FirmwareMediatek Mt8755 FirmwareMediatek Mt8768 FirmwareMediatek Mt8771 Firmware+108/3/20268/19/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.
AnalyzedMedium (6.7)0.15%—Mediatek Mt8115 FirmwareMediatek Mt8186 FirmwareMediatek Mt8188 FirmwareMediatek Mt8196 Firmware+285/4/20266/17/2026
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504.
AnalyzedMedium (6.7)0.15%—Mediatek Mt6765 FirmwareMediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 Firmware+185/4/20266/17/2026
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281.
ModifiedMedium (6.5)0.36%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+814/7/20256/17/2026
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01519028;…