CVE tracker
369 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-18577 - Incomplete patch leads to administrative account takeover

CVE ID :CVE-2026-18577
Published : Aug. 2, 2026, 11:16 p.m. | 43 minutes ago
Description :An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-3245 - PRISMAproduction Deserialization Arbitrary Code Execution

CVE ID :CVE-2026-3245
Published : Aug. 2, 2026, 11:32 p.m. | 27 minutes ago
Description :A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20478 - MediaTek Audio HAL Heap Buffer Overflow

CVE ID :CVE-2026-20478
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20479 - Modem Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-20479
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20480 - MediaTek Audio HAL Heap Buffer Overflow

CVE ID :CVE-2026-20480
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20481 - Geniezone Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20481
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20482 - Qualcomm WLAN STA Firmware Denial of Service Vulnerability

CVE ID :CVE-2026-20482
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20483 - Telephony Local Privilege Escalation

CVE ID :CVE-2026-20483
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20484 - TFA Information Disclosure Vulnerability

CVE ID :CVE-2026-20484
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20485 - HFRP Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20485
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20486 - Imgsensor Improper Error Handling Local Privilege Escalation

CVE ID :CVE-2026-20486
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20488 - MediaTek Display Information Disclosure Vulnerability

CVE ID :CVE-2026-20488
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20489 - MediaTek Display Integer Overflow Information Disclosure

CVE ID :CVE-2026-20489
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20490 - CCCI Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-20490
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20491 - MediaTek med Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20491
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20492 - MediaTek Audio HAL Denial of Service Vulnerability

CVE ID :CVE-2026-20492
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20493 - Wi-Fi Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20493
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20494 - MediaTek WiFi Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-20494
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20495 - Bluetooth Driver Permission Bypass

CVE ID :CVE-2026-20495
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20496 - Geniezone Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-20496
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20497 - Geniezone Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20497
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...