|
3591
|
7.8 |
HIGH
Local
|
google
|
android
|
In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution priv…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-0036
|
2026-06-3 23:21 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3592
|
9.8 |
CRITICAL
Network
|
trendnet
|
tew-432brp_firmware
|
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-10062
|
2026-06-3 23:21 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3593
|
7.8 |
HIGH
Local
|
google
|
android
|
In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. This could lead to local escalation of privilege with no add…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-0045
|
2026-06-3 23:21 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3594
|
9.8 |
CRITICAL
Network
|
trendnet
|
tew-432brp_firmware
|
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-bas…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-10063
|
2026-06-3 23:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3595
|
- |
|
-
|
-
|
NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private…
|
CWE-862
Missing Authorization
|
CVE-2026-40571
|
2026-06-3 23:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3596
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the com…
|
CWE-287
Improper Authentication
|
CVE-2026-10548
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3597
|
7.8 |
HIGH
Local
|
google
|
android
|
In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with …
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-0077
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3598
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed.…
|
CWE-89
SQL Injection
|
CVE-2026-0075
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3599
|
7.8 |
HIGH
Local
|
google
|
android
|
In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This c…
|
CWE-862
Missing Authorization
|
CVE-2025-26418
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3600
|
7.8 |
HIGH
Local
|
google
|
android
|
In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional exe…
|
CWE-284
Improper Access Control
|
CVE-2025-22426
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|