Vulnerabilities
2,307 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-25292 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. NVD description · AI analysis pending | 7.6 | <1% |
| — | ||
| CVE-2026-25289 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. NVD description · AI analysis pending | 9.6 | <1% |
| — | ||
| CVE-2026-25288 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. NVD description · AI analysis pending | 7.4 | <1% |
| — | ||
| CVE-2026-24084 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2026-24083 +1 in the same advisory: …24080 | Memory Corruption while processing IOCTL device driver requests with invalid arguments. Memory Corruption while processing IOCTL device driver requests with invalid arguments. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-24079 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2026-24078 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-24076 +1 in the same advisory: …24077 | Memory Corruption when processing registry values with incorrect types using a direct query method. Memory Corruption when processing registry values with incorrect types using a direct query method. NVD description · AI analysis pending | 6.7 group max | <1% |
| — | ||
| CVE-2026-21366 | Memory corruption while processing a packet with a size close to the maximum allowed value. Memory corruption while processing a packet with a size close to the maximum allowed value. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-25271 | Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use. Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use. NVD description · AI analysis pending | 7.0 | <1% |
| — | ||
| CVE-2026-25268 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-59616 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2026-21383 | Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. NVD description · AI analysis pending | 7.1 | <1% |
| — | ||
| CVE-2026-21379 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-21369 | Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-25276 +1 in the same advisory: …25277 | Memory corruption while using Strongbox due to missing bounds check. Memory corruption while using Strongbox due to missing bounds check. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-59606 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2026-24092 | Memory Corruption when processing fastboot commands to set display mode. Memory Corruption when processing fastboot commands to set display mode. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2026-24091 | Memory corruption while processing fastboot commands with improperly formatted input. Memory corruption while processing fastboot commands with improperly formatted input. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2026-24090 | Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. NVD description · AI analysis pending | 7.1 | <1% |
| — | ||
| CVE-2026-24088 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. NVD description · AI analysis pending | 8.2 | <1% |
| — | ||
| CVE-2026-24085 | Memory Corruption when processing display command line information due to improper initialization of a variable. Memory Corruption when processing display command line information due to improper initialization of a variable. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2025-59611 | Memory corruption in diagnostic services due to absence of input validation Memory corruption in diagnostic services due to absence of input validation NVD description · AI analysis pending | 6.7 | <1% |
| — | ||
| CVE-2025-59605 +1 in the same advisory: …59610 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. Memory Corruption when processing device identifier strings that exceed the expected maximum length. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2025-59609 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2025-59604 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-59601 | Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration. Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-25293 | Buffer overflow due to incorrect authorization in PLC FW Buffer overflow due to incorrect authorization in PLC FW NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-25266 | Memory corruption while processing IOCTL command when device is in power-save state. Memory corruption while processing IOCTL command when device is in power-save state. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-24082 | Memory Corruption when copying data from a freed source while executing performance counter deselect operation. Memory Corruption when copying data from a freed source while executing performance counter deselect operation. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-47408 | Memory corruption when another driver calls an IOCTL with invalid input/output buffer. Memory corruption when another driver calls an IOCTL with invalid input/output buffer. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-47407 | Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. NVD description · AI analysis pending | 7.0 | <1% |
| — | ||
| CVE-2025-47406 | Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. NVD description · AI analysis pending | 5.5 | <1% |
| — |