OCTOBER 10, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

151,191 records on file
Page 1721 of 5,040
CVE ID Score Description
2mo ago
7.6

Authenticated RCE via Path Traversal

2mo ago
8.3

Pre-Auth RCE via Path Traversal

2mo ago
8.3

Pre-Auth RCE via Path Traversal

2mo ago
8.1

An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.

2mo ago
8.3

Missing Authentication - User & System Configuration

2mo ago
8.8

A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support.

Exploit 2mo ago
8.8

A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formEasySetTimezone of the file /goform/formEasySetTimezone. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Exploit 2mo ago
8.4

Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.

Exploit 2mo ago
8.8

IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.

2mo ago
7

Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.

Exploit 2mo ago
8.8

A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formEasySetPassword of the file /goform/formEasySetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Exploit 2mo ago
8.8

A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formAdvNetwork of the file /goform/formAdvNetwork. The manipulation of the argument curTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

2mo ago
7.3

A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler (SEH) registers. This could allow attackers to execute arbitrary code via a long filename argument.

2mo ago
7.3

A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler (SEH) registers. This could allow attackers to execute arbitrary code via a long filename argument.

Exploit 2mo ago
8.8

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. This issue affects the function formAdvFirewall of the file /goform/formAdvFirewall. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Exploit 2mo ago
8.8

A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of the argument next_page leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

KEV 2mo ago
7.8

Memory corruption while maintaining memory maps of HLOS memory.

2mo ago
8.4

Memory corruption while processing user packets to generate page faults.

2mo ago
7.5

Transient DOS while parsing probe response and assoc response frame.

2mo ago
8.2

Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

2mo ago
7.5

Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.

2mo ago
7.5

Transient DOS while parsing ESP IE from beacon/probe response frame.

2mo ago
7.5

Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.

2mo ago
8.4

Memory corruption while taking snapshot when an offset variable is set by camera driver.

2mo ago
8.2

Information disclosure while parsing the multiple MBSSID IEs from the beacon.

2mo ago
7.5

Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.

2mo ago
7.8

Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.

2mo ago
7.8

Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.

2mo ago
7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.13.11.

Exploit 2mo ago
7.5

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00843282; Issue ID: MSV-1535.