Total
396899 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-70403 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device. | |||||
| CVE-2026-20517 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID: MSV-6781. | |||||
| CVE-2026-20518 | 2026-09-08 | N/A | 4.4 MEDIUM | ||
| In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10867524 / ALPS10876355; Issue ID: MSV-6674. | |||||
| CVE-2026-20511 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID: MSV-8890. | |||||
| CVE-2026-69657 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device. | |||||
| CVE-2026-62928 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected. | |||||
| CVE-2026-20514 | 2026-09-08 | N/A | 4.4 MEDIUM | ||
| In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087632; Issue ID: MSV-8244. | |||||
| CVE-2026-20513 | 2026-09-08 | N/A | 4.4 MEDIUM | ||
| In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533; Issue ID: MSV-8245. | |||||
| CVE-2026-20508 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9012. | |||||
| CVE-2026-20509 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9011. | |||||
| CVE-2026-20512 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246. | |||||
| CVE-2026-20506 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9126. | |||||
| CVE-2026-20507 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9125. | |||||
| CVE-2026-84387 | 2026-09-08 | N/A | 7.2 HIGH | ||
| A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | |||||
| CVE-2026-77698 | 2026-09-08 | N/A | 5.7 MEDIUM | ||
| Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade. | |||||
| CVE-2026-22575 | 2026-09-08 | N/A | 4.9 MEDIUM | ||
| An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests. | |||||
| CVE-2026-84391 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here> | |||||
| CVE-2026-26084 | 2026-09-08 | N/A | 9.9 CRITICAL | ||
| A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests. | |||||
| CVE-2026-77699 | 2026-09-08 | N/A | 5.0 MEDIUM | ||
| Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path. | |||||
| CVE-2026-77697 | 2026-09-08 | N/A | 6.3 MEDIUM | ||
| Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction | |||||
