Vulnerabilities (CVE)

Total 398833 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-45203 3 Google, Imaginationtech, Linux 3 Android, Ddk, Linux Kernel 2026-08-12 N/A 7.8 HIGH
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in memory after firmware validation but before use.
CVE-2026-7639 3 Google, Imaginationtech, Linux 3 Android, Ddk, Linux Kernel 2026-08-12 N/A 7.8 HIGH
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a malicious code could lead to incomplete cleanup of an internal driver state, allowing for future unauthorized access to the contents of the physical memory.
CVE-2026-72746 2026-08-12 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.
CVE-2026-72745 2026-08-12 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73242.
CVE-2026-50656 1 Microsoft 1 Malware Protection Engine 2026-08-12 N/A 7.8 HIGH
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
CVE-2026-6851 2 Bitdefender, Microsoft 3 Internet Security, Total Security, Windows 2026-08-12 N/A 7.0 HIGH
An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race conditions via Symbolic Links. This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315.
CVE-2026-62422 1 Jetbrains 1 Youtrack 2026-08-12 N/A 10.0 CRITICAL
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
CVE-2026-59126 1 Microsoft 8 Windows 10 21h2, Windows 10 22h2, Windows 11 23h2 and 5 more 2026-08-12 N/A 7.0 HIGH
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CVE-2026-45804 1 Huggingface 1 Diffusers 2026-08-12 N/A 7.5 HIGH
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub repository with custom .py pipeline code to execute through the custom pipeline flow without passing custom_pipeline or trust_remote_code=True. This issue is fixed in version 0.38.0.
CVE-2026-68813 1 Microsoft 5 365 Apps, Microsoft 365, Office 2019 and 2 more 2026-08-12 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-33167 1 Rubyonrails 1 Rails 2026-08-12 N/A 6.1 MEDIUM
Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.
CVE-2026-70318 1 Microsoft 6 365 Apps, Microsoft 365, Office 2019 and 3 more 2026-08-12 N/A 5.5 MEDIUM
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-1166 1 Hitachi 1 Ops Center Administrator 2026-08-12 N/A 4.3 MEDIUM
Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8.
CVE-2026-2072 1 Hitachi 2 Infrastructure Analytics Advisor, Ops Center Analyzer 2026-08-12 N/A 8.2 HIGH
Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00.
CVE-2025-9497 1 Microchip 2 Timeprovider 4100, Timeprovider 4100 Firmware 2026-08-12 N/A 9.8 CRITICAL
Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.
CVE-2026-2336 1 Microchip 1 Istax 2026-08-12 N/A 8.8 HIGH
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.
CVE-2026-14258 2026-08-12 N/A 6.5 MEDIUM
A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero-length Neighbor Discovery option can bypass validation during packet storage and later be reparsed without adequate validation, causing the parser to enter a non-advancing loop. Successful exploitation may result in excessive CPU consumption, leading to a denial of service.
CVE-2025-35988 2026-08-12 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-35977 2026-08-12 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2025-32737 2026-08-12 N/A N/A
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused