|
3061
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the com…
|
CWE-287
Improper Authentication
|
CVE-2026-10548
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3062
|
7.8 |
HIGH
Local
|
google
|
android
|
In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with …
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-0077
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3063
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed.…
|
CWE-89
SQL Injection
|
CVE-2026-0075
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3064
|
7.8 |
HIGH
Local
|
google
|
android
|
In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This c…
|
CWE-862
Missing Authorization
|
CVE-2025-26418
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3065
|
7.8 |
HIGH
Local
|
google
|
android
|
In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional exe…
|
CWE-284
Improper Access Control
|
CVE-2025-22426
|
2026-06-3 23:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3066
|
6.5 |
MEDIUM
Network
|
springaicommunity
|
mcp_security
|
mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45609
|
2026-06-3 23:08 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3067
|
3.3 |
LOW
Local
|
google
|
android
|
In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed.…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-0056
|
2026-06-3 22:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3068
|
7.8 |
HIGH
Local
|
google
|
android
|
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privi…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-28577
|
2026-06-3 22:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3069
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with n…
|
NVD-CWE-noinfo
|
CVE-2026-0067
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3070
|
8.0 |
HIGH
Adjacent
|
google
|
android
|
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additi…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-0059
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|