Search

Search Results (389436 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-20502 2 Mediatek, Mediatek, Inc. 107 Mt2718, Mt2718 Firmware, Mt6580 and 104 more 2026-09-09 8.4 High
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.
CVE-2026-20501 2 Mediatek, Mediatek, Inc. 107 Mt2718, Mt2718 Firmware, Mt6580 and 104 more 2026-09-09 8.4 High
In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.
CVE-2026-20500 1 Mediatek 45 Mediatek Chipset, Mt2716, Mt2716 Firmware and 42 more 2026-09-09 5.5 Medium
In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.
CVE-2026-15667 2026-09-09 7.5 High
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration.
CVE-2026-15406 2026-09-09 7.5 High
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
CVE-2026-13359 2026-09-09 7.2 High
The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload executes in the context of an administrator's browser session when they visit the plugin's message manager page at /wp-admin/admin.php?page=cntctfrmtdb_manager, making it possible to compromise administrator-level sessions via a simple unauthenticated contact form submission.
CVE-2026-87036 2026-09-09 8.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87021 2026-09-09 7.2 High
Tanium addressed an unauthorized code execution vulnerability in Comply.
CVE-2026-87023 2026-09-09 8.5 High
Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87084 2026-09-09 7.7 High
Tanium addressed a server-side request forgery vulnerability in Enforce.
CVE-2026-87048 2026-09-09 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87034 2026-09-09 8.3 High
Tanium addressed a SQL injection vulnerability in Comply.
CVE-2026-87073 2026-09-09 6.5 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87032 2026-09-09 4.3 Medium
Tanium addressed an information disclosure vulnerability in Tanium Server.
CVE-2026-87072 2026-09-09 7.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87035 2026-09-09 4.3 Medium
Tanium addressed an information disclosure vulnerability in Comply.
CVE-2026-87033 2026-09-09 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-14892 2026-09-09 4.3 Medium
Tanium addressed an improper access controls vulnerability in Tanium Server.
CVE-2026-87030 2026-09-09 8.5 High
Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87046 2026-09-09 4.3 Medium
Tanium addressed an improper access controls vulnerability in Comply.