Busca de CVEs
375.173 resultadosCVE-2026-28587CRITICALIn MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This EPSS 0.1%CVE-2026-28576CRITICALIn Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disEPSS 0.1%CVE-2026-28615CRITICALIn Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalationEPSS 0.1%CVE-2026-0083CRITICALIn Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privileEPSS 0.1%CVE-2026-0082CRITICALIn tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure defaultEPSS 0.2%CVE-2026-12199HIGHUnauthenticated Denial of Service in nltk.app.wordnet_appEPSS 0.3%CVE-2026-0081CRITICALIn NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2026-0071CRITICALIn SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilEPSS 0.2%CVE-2026-28575CRITICALIn PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a poEPSS 0.1%CVE-2026-0064CRITICALIn multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service EPSS 0.1%CVE-2026-0092CRITICALIn Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalationEPSS 0.2%CVE-2026-8494MEDIUMPermalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post TitleEPSS 0.3%CVE-2026-8607MEDIUMmyCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode AttributeEPSS 0.3%CVE-2026-0068CRITICALIn createSessionInternal of PackageInstallerService.java, there is a possible method to remove a DPC app from a managed device without DO coEPSS 0.1%CVE-2026-10094CRITICALPath Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026EPSS 0.4%CVE-2026-9570HIGHTaskbuilder < 5.0.8 - Reflected XSS via ShortcodeEPSS 0.1%CVE-2026-8383MEDIUMLearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST APIEPSS 0.6%CVE-2026-8089HIGHweMail < 2.1.3 - Reflected Cross-Site ScriptingEPSS 0.2%CVE-2026-7850MEDIUMWP Magnific Popup <= 1.0 - Author+ Stored XSS via href AttributeEPSS 0.1%CVE-2026-0057LOWIn Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission EPSS 0.1%