2026 · Medium
Medium-severity vulnerabilities disclosed in 2026
Medium-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.
4010 published vulnerabilities · page 19 of 41
- CVE-2025-5085MEDIUM 5.5
The WP Nano AD plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability affecting versions 1.31 and earlier. An authenticated administrator can inject malicious scripts through the 'blogrole_link' parameter that persist in the database and execute in the browsers of users who view affected pages. The vulnerability is limited to WordPress multisite installations or those with the 'unfiltered_html' capability disabled, which narrows its real-world scope but makes it critical for affected deployments.
- CVE-2025-55641MEDIUM 5.5
GPAC MP4Box version 2.4 contains a flaw that can crash when processing a specially crafted MP4 video file. A user who opens a malicious MP4 file in MP4Box will experience a denial-of-service condition, rendering the tool unavailable. This is a local vulnerability requiring user interaction—the attacker must trick someone into opening a malicious file.
- CVE-2025-55643MEDIUM 5.5
CVE-2025-55643 is a denial-of-service vulnerability in GPAC MP4Box v2.4 that occurs when the application processes a specially crafted MP4 file. The flaw stems from a NULL pointer dereference in the TrackWriter handling code, which causes the application to crash. An attacker can exploit this by distributing a malicious MP4 file that, when opened by a user, terminates the MP4Box process. This is a local attack requiring user interaction—the victim must open the file—but no special privileges are needed.
- CVE-2025-55644MEDIUM 5.5
A memory safety flaw in GPAC MP4Box version 2.4 allows an attacker to crash the application by submitting a specially crafted MP4 video file. The vulnerability stems from improper handling of memory references in the scene graph processing code, where the application attempts to access memory that has already been freed. An attacker would need local access or the ability to trick a user into opening a malicious MP4 file.
- CVE-2025-55645MEDIUM 5.5
CVE-2025-55645 is a memory safety issue in GPAC MP4Box v2.4 that can be triggered by opening a specially crafted MP4 file. The vulnerability exists in code that handles digital rights management (DRM) protection information within MP4 containers. An attacker who creates a malicious MP4 file can cause the application to crash, denying service to legitimate users. The vulnerability requires local file system access and user interaction to trigger—an attacker cannot exploit it remotely over the network.
- CVE-2025-55647MEDIUM 5.5
GPAC MP4Box version 2.4 contains a flaw that causes the application to consume excessive memory and crash when processing a maliciously crafted MP4 file. An attacker can exploit this by distributing a specially designed MP4 that triggers an out-of-memory condition during the CENC (Common Encryption) PSSH (Protection System Specific Header) insertion process, effectively denying service to users attempting to process the file.
- CVE-2025-55648MEDIUM 5.5
GPAC's MP4Box version 2.4 contains a memory handling defect that can be triggered by opening a specially crafted MP4 media file. The vulnerability allows an attacker to crash the application, disrupting work for anyone using the tool to process or analyze video files. An attacker would need local access or the ability to deliver a malicious file to a target user, but no special privileges or complex exploitation steps are required once the file is opened.
- CVE-2025-55649MEDIUM 5.5
CVE-2025-55649 is a NULL pointer dereference vulnerability in GPAC MP4Box v2.4 that crashes the application when processing a maliciously crafted MP4 file. An attacker can trigger a denial-of-service condition by supplying a specially constructed media file, rendering the tool temporarily unavailable. This is a local attack that requires user interaction—the victim must open the malicious MP4 file—but does not require any elevated privileges.
- CVE-2025-55650MEDIUM 5.5
CVE-2025-55650 is a memory safety flaw in GPAC MP4Box v2.4 that occurs when the application processes a specially crafted MP4 file. The vulnerability causes the program to access memory that has already been freed (a 'use-after-free' condition), leading to a crash or denial of service. An attacker would need to trick a user into opening a malicious MP4 file, but no special privileges are required to exploit it.
- CVE-2025-55651MEDIUM 5.5
CVE-2025-55651 is a denial-of-service vulnerability in GPAC's MP4Box v2.4 that crashes the application when processing a specially crafted MP4 file. The flaw stems from the software attempting to access memory without first checking whether a critical pointer is valid. An attacker can exploit this by distributing a malformed MP4 file; if a user opens it with the vulnerable version, the application will crash. This is a local attack requiring user interaction—someone must open the malicious file—but no special privileges are needed.
- CVE-2025-55652MEDIUM 5.5
A memory corruption vulnerability exists in GPAC MP4Box version 2.4 that can be triggered by opening a specially crafted MP4 media file. The flaw is in code responsible for handling video codec configuration data, and exploiting it causes the application to crash, resulting in a denial of service. An attacker would need to trick a user into opening a malicious MP4 file locally on their system to trigger the vulnerability.
- CVE-2025-55660MEDIUM 5.5
CVE-2025-55660 is a stack overflow vulnerability in GPAC's MP4Box tool version 2.4. When a user opens a specially crafted MP4 video file, the vulnerability triggers a crash that renders the application temporarily unusable. An attacker would need to trick a user into opening a malicious MP4 file; the vulnerability does not allow remote code execution or data theft, but causes a denial of service. This is a localized threat affecting anyone using MP4Box to process untrusted video files.
- CVE-2025-55661MEDIUM 5.5
GPAC MP4Box version 2.4 contains a memory safety defect in its Opus audio parser that can be triggered by opening a specially crafted MP4 file. The flaw causes the application to crash, denying service to legitimate users. An attacker needs only local file access and user interaction (opening the file); no special privileges or network connectivity are required.
- CVE-2025-55663MEDIUM 5.5
GPAC MP4Box version 2.4 contains a crash vulnerability in how it processes MP4 video files. When a specially crafted MP4 file is opened, the application can crash due to improper memory handling in the track descriptor function. This is a local issue—an attacker would need to trick a user into opening a malicious file—but the impact is straightforward: service disruption. Media processing pipelines, automated transcoding systems, and any workflow relying on MP4Box could experience unexpected downtime.
- CVE-2025-55664MEDIUM 5.5
CVE-2025-55664 is a heap buffer overflow vulnerability in GPAC MP4Box version 2.4 that can be triggered when processing a specially crafted MP4 file. An attacker can exploit this by tricking a user into opening a malicious MP4 file, causing the application to crash or become unresponsive. This is a local, user-interaction-based attack that does not allow data theft or system compromise, but disrupts availability of the MP4Box tool.
- CVE-2025-59609MEDIUM 5.5
CVE-2025-59609 is a medium-severity information disclosure vulnerability affecting multiple Qualcomm wireless and audio chipset products. The flaw occurs when devices process Wi-Fi advertisement frames containing malformed MBSSID (Multiple BSSID) elements that are shorter than expected. An attacker with network proximity and valid credentials can craft these frames to trigger uninitialized memory access, potentially exposing sensitive data. The attack requires user interaction and specific network conditions to succeed, limiting its practical exploitability but still warranting prompt patching given the breadth of affected components.
- CVE-2025-59868MEDIUM 5.5
HCL Traveler for Microsoft Outlook contains a vulnerability that allows an authenticated attacker on the same system to read sensitive application data. An attacker with local access and valid user credentials could extract confidential information, which could then be leveraged for further attacks or cause unpredictable application behavior. This is a local privilege concern rather than a remote network attack.
- CVE-2025-60468MEDIUM 5.5
GPAC's MP4Box multimedia processing tool contains a memory safety defect that allows local users to crash the application by processing specially crafted video files. When MP4Box handles certain malformed MPEG-2 Transport Stream or MP4 files during filter cleanup operations, it attempts to access memory that has already been freed, triggering a denial-of-service condition. The flaw requires local system access and authenticated user privileges to exploit.
- CVE-2025-60471MEDIUM 5.5
GPAC Project's MP4Box, a widely-used multimedia processing tool, contains a use-after-free memory flaw in its filter configuration logic. When processing a specially crafted media file, the vulnerable code attempts to access memory that has already been freed, causing the application to crash. An attacker can exploit this by distributing a malicious media file that, when opened by a user, brings down MP4Box. This is a denial-of-service vulnerability—it doesn't steal data or grant unauthorized access, but it can disrupt workflows that depend on MP4Box for media processing.
- CVE-2025-60473MEDIUM 5.5
A flaw in GPAC Project's MP4Box media processing tool (versions before 26.02.0) can be triggered by opening a specially crafted media file, causing the application to crash. The vulnerability stems from improper handling of null pointers in the filter chain processing logic. While the crash itself doesn't lead to data theft or system compromise, it disrupts media processing workflows and could be weaponized in batch processing environments to degrade service availability.
- CVE-2025-60481MEDIUM 5.5
GPAC Project's MP4Box, a widely-used multimedia framework and command-line tool, contains a flaw in how it processes AC4 audio configuration data within media files. When a specially crafted AC4 file is opened, the application crashes due to a null pointer dereference—essentially trying to access memory that hasn't been properly initialized. This is a local denial-of-service vulnerability that requires user interaction (opening the malicious file) but could disrupt workflows involving media processing or transcoding pipelines.
- CVE-2025-60483MEDIUM 5.5
A flaw in GPAC Project/MP4Box's AC4 audio file parser can crash the application when processing a specially crafted audio file. An attacker would need to trick a user into opening a malicious AC4 file, causing the service to stop responding. This is a moderate-risk issue affecting organizations that rely on MP4Box for media processing or transcoding workflows.
- CVE-2025-60485MEDIUM 5.5
CVE-2025-60485 is a memory safety flaw in GPAC's MP4Box tool that causes the application to crash when processing a specially crafted MP4 media file. An attacker can exploit this by distributing a malicious MP4 that triggers the crash, disrupting service for anyone using MP4Box to process or analyze video files. The vulnerability requires local access and user interaction (opening or processing the file), so it is most relevant in environments where untrusted media files are routinely handled.
- CVE-2025-60486MEDIUM 5.5
A memory safety flaw in GPAC's MP4Box tool allows an attacker to crash the application by processing a specially crafted MPEG-2 video file. The vulnerability stems from improper memory management in the dasher_process function—specifically, the code attempts to access memory that has already been freed. An attacker with local file access can exploit this by distributing a malicious video file that, when opened in MP4Box, triggers the defect and renders the tool unusable. This is a denial-of-service issue rather than a path to code execution or data theft.
- CVE-2025-60495MEDIUM 5.5
GPAC's MP4Box, a widely-used multimedia toolkit, contains a memory safety flaw in its color information parsing logic. When MP4Box processes a specially crafted media file, the vulnerable code attempts to access memory in an unsafe manner, causing the application to crash. An attacker with the ability to supply a malicious file to a user or system running MP4Box can trigger this denial of service. This is a local impact issue—it requires user interaction to open the file—but the barrier to exploitation is low.
- CVE-2025-7005MEDIUM 5.5
Avast Antivirus and related Gen Digital products contain a flaw that causes their scanning engine to get stuck in an infinite loop when it encounters a specially crafted Windows executable file. An attacker who tricks a user into downloading a malformed file could crash the antivirus process, leaving the system temporarily unprotected. The vulnerability affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus across Windows, macOS, and Linux platforms. Gen Digital has fixed the issue in virus definition build VPS 25031700 and later, which rolls out automatically to all affected products through a shared update channel.
- CVE-2025-7006MEDIUM 5.5
Avast, AVG, and Norton antivirus products (along with Avast One and Avast Business variants) contain a use-after-free defect in their scanning engine that can crash the antivirus process when it encounters a specially crafted Windows PE file. This is a denial-of-service vulnerability affecting Windows, macOS, and Linux systems running virus definitions older than build 25022500. The vulnerability does not allow attackers to execute code or steal data, but disabling antivirus protection on a system could expose it to other threats.
- CVE-2025-7010MEDIUM 5.5
A stack overflow flaw in the antivirus engines used by Avast, AVG, Norton, and related products can crash the scanning process when it encounters a specially crafted PDF file. The vulnerability stems from unchecked recursive calls in the PDF parsing logic, which is shared across multiple Gen Digital consumer and business antivirus products via a centralized virus definition update channel. An attacker who can deliver a malformed PDF to a user could trigger a denial-of-service condition, temporarily disabling real-time malware protection until the antivirus process restarts.
- CVE-2025-70100MEDIUM 5.5
CVE-2025-70100 is a denial-of-service vulnerability in lwext4, a lightweight ext4 filesystem library. An attacker can craft a malicious ext4 filesystem image containing a zero logical block size that crashes any application using lwext4 to mount or process the image. The library fails to validate the block size parameter before performing arithmetic operations, leading to a divide-by-zero condition. While this vulnerability cannot be exploited for data theft or system compromise, it can disrupt services that depend on lwext4 for filesystem operations, such as embedded systems, recovery tools, or specialized storage applications.
- CVE-2025-7018MEDIUM 5.5
Avira Antivirus contains a vulnerability that can crash its scanning engine when it encounters a specially crafted Windows PE file. An attacker or malicious file could trigger this crash, temporarily disabling the antivirus protection on a system. The vulnerability affects Avira on Windows, macOS, and Linux platforms running engine versions before 8.3.70.64.
- CVE-2025-7019MEDIUM 5.5
A stack overflow flaw in antivirus scanning engines affects Avast, AVG, Norton, Avast One, and Avast Business products across Windows, macOS, and Linux. When these products scan a deliberately malformed Office Open XML file, the scanning process can crash, temporarily disabling antivirus protection on the affected machine. This is not a remote code execution or data theft risk, but it can leave systems unprotected during the outage. The vulnerability is fixed through a shared virus definition update; once your antivirus definitions reach build VPS 25020100 or later, you are protected.
- CVE-2025-71313MEDIUM 5.5
A memory allocation failure in the Linux kernel's PCI endpoint driver could cause the system to crash. When the kernel tries to create a work queue for handling PCI endpoint-to-endpoint communication, it doesn't properly check whether that operation succeeded. If memory is scarce and the allocation fails, the driver continues anyway and later attempts to use the non-existent queue, triggering a NULL pointer dereference that halts the affected system. The fix is straightforward: check whether the allocation succeeded before proceeding.
- CVE-2025-71314MEDIUM 5.5
A vulnerability in the Linux kernel's Panthor GPU driver can cause the graphics system to hang indefinitely when memory subsystem operations fail to complete. The issue arises because the driver lacks proper recovery mechanisms for stuck cache-flush operations. When a GPU memory flush times out, the driver now schedules a reset and recovers gracefully instead of hanging. This affects systems using Panthor-based GPUs (primarily ARM Mali GPUs in certain SoCs).
- CVE-2025-71315MEDIUM 5.5
A flaw exists in the Linux kernel's virtual kernel modesetting (vkms) driver related to how it manages display refresh timing. The vkms driver previously used its own custom timer implementation for vblank (vertical blank) events, which are critical synchronization points for display rendering. The vulnerability stems from inconsistencies between this custom implementation and the standard DRM (Direct Rendering Manager) vblank timer framework. When the kernel converts vkms to use the standardized DRM vblank timer, it removes the custom hrtimer mechanism, but improper handling during this transition can cause denial-of-service conditions—specifically, the system may become unresponsive or crash when display refresh timing is disrupted.
- CVE-2026-0018MEDIUM 5.5
CVE-2026-0018 is a denial-of-service vulnerability in Android's AccessibilityManagerService that allows a local attacker with user-level privileges to crash or hang the accessibility subsystem persistently. No special permissions, code execution, or user interaction are required to trigger the flaw—an authenticated local process can simply send malformed input to designated service functions that fail to properly validate their parameters. This could degrade or disable accessibility features for affected users.
- CVE-2026-0042MEDIUM 5.5
CVE-2026-0042 is a resource exhaustion vulnerability in Google Android's UBSan runtime component that allows a local attacker to cause a persistent denial of service. An attacker with basic user-level access can trigger the flaw without user interaction, exhausting system resources and rendering the device unavailable. The vulnerability does not enable unauthorized access or data theft—only availability disruption.
- CVE-2026-0043MEDIUM 5.5
CVE-2026-0043 is a medium-severity integer overflow vulnerability in Android's UBSan runtime library that can cause a persistent denial of service and local privilege escalation. The flaw resides in multiple functions within ubsan_throwing_runtime.cpp and requires only local access to exploit—no special privileges or user interaction are needed. Once triggered, the integer overflow can exhaust system resources or corrupt memory state, denying service to the affected device or enabling an attacker to elevate their privileges locally.
- CVE-2026-0060MEDIUM 5.5
CVE-2026-0060 is a local denial-of-service vulnerability in Android's graphics driver management system. A local attacker with basic user privileges can trigger a persistent crash condition in the GraphicsDriverEnableAngleAsSystemDriverController component, rendering the graphics subsystem unavailable without requiring elevated permissions or user interaction. The issue stems from improper state handling in the updateState method.
- CVE-2026-0064MEDIUM 5.5
CVE-2026-0064 is a resource exhaustion vulnerability affecting Google Android that allows a locally authenticated attacker to cause a persistent denial of service. The vulnerability exists in multiple code paths and requires only standard user privileges to trigger—no special permissions or user interaction are needed. Once exploited, the affected system can be rendered unresponsive or unstable until remediated.
- CVE-2026-0067MEDIUM 5.5
A logic error in Android's ubsan_throwing_runtime.cpp file can be exploited by a local attacker to permanently deny service to affected devices. The vulnerability requires only basic user-level permissions and no special interaction to trigger, making it a straightforward availability threat for any Android user or administrator managing affected deployments.
- CVE-2026-0069MEDIUM 5.5
CVE-2026-0069 is a resource exhaustion vulnerability in Android's signature verification code that allows a local attacker to crash the system without needing special privileges or user interaction. An attacker with basic local access can trigger excessive resource consumption in the APK checksum verification process, causing a denial of service.
- CVE-2026-0070MEDIUM 5.5
A flaw in Android's DevicePolicyManagerService allows a local attacker with standard user privileges to hide critical system packages through improper validation of input parameters. This creates a denial-of-service condition by making essential system components inaccessible, potentially rendering the device unstable or non-functional without requiring any special permissions or user interaction.
- CVE-2026-0074MEDIUM 5.5
CVE-2026-0074 is a denial-of-service vulnerability in Android's LauncherProcessImageListener component. An attacker with local system access can exhaust device resources through the getPreferredSize function, causing the launcher process to become unresponsive or crash. No special privileges or user interaction are required to trigger the flaw, making it a concern for multi-user devices and environments where untrusted code may run locally.
- CVE-2026-0079MEDIUM 5.5
CVE-2026-0079 is a denial-of-service vulnerability in Android's ubsan_throwing_runtime.cpp component. An integer overflow flaw allows a local attacker to crash or hang affected systems persistently without requiring elevated privileges or user interaction. The vulnerability resides in multiple functions within the runtime component responsible for undefined behavior sanitization, making it accessible to processes running with standard user permissions.
- CVE-2026-0085MEDIUM 5.5
A flaw in Android's contact data handling allows a local attacker to crash the system by inserting an unusually large contact name. The vulnerability exists in the DataRowHandler component, which fails to properly validate the size of contact name input before processing it. Because the attack requires only local access and no special privileges, any app on a compromised device could trigger the denial of service without user interaction.
- CVE-2026-0267MEDIUM 5.5
A vulnerability in Palo Alto Networks' GlobalProtect app for macOS allows a local user to read stored passcodes that protect critical app functions. Once an attacker learns these passcodes, they can disable, disconnect, or uninstall GlobalProtect even when the app's security policy would normally prevent such actions. This is a local-only risk that requires prior access to the affected macOS device.
- CVE-2026-0466MEDIUM 5.5
AMD uProf, a performance profiling tool, contains an access control vulnerability that allows a user with local system access to write data into memory regions normally reserved for the kernel. This weakness could crash the system or render it temporarily unavailable. The vulnerability requires an attacker to already have an account on the target system—it cannot be exploited remotely.
- CVE-2026-10688MEDIUM 5.5
A code injection vulnerability exists in ahujasid blender-mcp, a tool used for integrating Blender with model context protocol systems. An authenticated attacker can inject and execute arbitrary code by manipulating the 'code' parameter passed to the execute_blender_code function in the server. The vulnerability has been publicly disclosed and exploit code is available. The project uses rolling releases, making it difficult to identify fixed versions; however, the maintainers have been notified but have not yet responded with a patch or mitigation guidance.
- CVE-2026-11397MEDIUM 5.5
The WP Import Export Lite plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability affecting all versions up to 3.9.30. When administrators use the plugin's URL import feature, it first attempts a safe check to block requests to internal IP addresses. However, if that check fails or is bypassed, the plugin falls back to an unprotected method that sends requests directly to attacker-specified URLs without proper security controls. This allows a compromised administrator to make the WordPress server itself reach out to internal services, including cloud metadata endpoints that may expose sensitive credentials or configuration data.
- CVE-2026-11516MEDIUM 5.5
A buffer overflow vulnerability exists in UTT HiPER 2610G network devices through version 3.0.0-171107. An authenticated local attacker can send specially crafted input to the device's web interface to overflow a buffer and potentially read sensitive data, modify settings, or crash the device. The vulnerability resides in the NAT Static Map configuration feature and leverages improper bounds checking on the NatBinds parameter. Exploit code has been disclosed publicly.
- CVE-2026-11819MEDIUM 5.5
An Ansible module that retrieves passphrases from your operating system's credential storage (such as GNOME Keyring, macOS Keychain, or Windows Credential Manager) fails to hide those secrets in its output. When you run the module and register its result or use debug statements, the plaintext passphrase appears in logs and terminal output. This affects anyone using the keyring_info module who might store SSH key passphrases, database credentials, or other sensitive secrets—those credentials can leak into Ansible logs, fact caches, and AWX/Tower job histories.
- CVE-2026-11931MEDIUM 5.5
Kiro IDE versions before 0.11.133 store authentication tokens in a cache file that is readable by any user on the same machine. This happens because the file is created with overly permissive access settings (world-readable) instead of being restricted to the owner alone. An attacker with local access could read this cache file and potentially reuse the stored authentication token to impersonate the legitimate user. The vulnerability affects macOS and Linux systems and is resolved by upgrading to version 0.11.133 or later.
- CVE-2026-11968MEDIUM 5.5
TortoiseGit's Blame feature can be tricked into writing files to arbitrary locations on your system if you open a repository containing maliciously crafted filenames in the Git history. An attacker would need you to clone or open a malicious repository, but once you do, they could modify or create files on your computer without additional prompts. This is a local attack that requires user interaction but can have serious consequences for system integrity.
- CVE-2026-12162MEDIUM 5.5
Devolutions Remote Desktop Manager version 2026.2.8 contains a flaw in how it validates the identity of social login providers during the autofill process. An attacker can craft a malicious web entry pointing to a lookalike domain that mimics a legitimate social login provider. When a user interacts with this entry, the application fails to properly verify the provider's authenticity, potentially exposing stored social login credentials to the attacker. This is a social engineering vulnerability that exploits the trust users place in the autofill mechanism.
- CVE-2026-12163MEDIUM 5.5
Fortra's File Integrity Monitoring (FIM) solution, previously known as Tripwire Enterprise, has a stored cross-site scripting (XSS) vulnerability affecting versions before 9.4.0.1. An authenticated insider with elevated privileges can inject malicious script into configuration fields that later execute in a user's browser when viewing the Asset View UI component. The vulnerability requires both authentication and privilege escalation, limiting immediate risk but posing a real threat in environments where privileged users may be compromised or act maliciously.
- CVE-2026-12166MEDIUM 5.5
CVE-2026-12166 is a local denial-of-service vulnerability in Little Orbit's GFAC system driver (GFAC_Sys_x64.sys). An attacker with local access can send specially crafted requests that cause the driver to crash, disrupting system availability. This is not a remote vulnerability and does not involve data theft or system takeover—it focuses purely on making the system unavailable.
- CVE-2026-12223MEDIUM 5.5
Yealink SIP-T46U IP phones running firmware version 108.86.0.118 contain a command injection vulnerability in their web service that allows authenticated users on the local network to execute arbitrary commands by manipulating network parameters. An attacker with local network access and valid credentials can exploit this flaw to compromise the phone's integrity and confidentiality. A patched firmware version (108.87.0.23) is available, though the vendor notes the fix currently exists only in a technical support branch and has not been publicly released yet.
- CVE-2026-12444MEDIUM 5.5
A memory reading vulnerability exists in Google Chrome's Chromoting feature (Google's remote desktop tool) on Windows systems running versions prior to 149.0.7827.155. An attacker with local access to a machine can craft a malicious file that, when interacted with by a user, causes Chrome to read data outside its intended memory boundaries. This out-of-bounds read could expose sensitive information already present in the process's memory—such as cached authentication tokens, encryption keys, or other confidential data—without requiring elevated privileges or special system access. The vulnerability is not currently known to be exploited in the wild.
- CVE-2026-12480MEDIUM 5.5
Keras, a popular deep learning library, contains a flaw that allows attackers to read files from a victim's computer by crafting malicious model files. The vulnerability exists because Keras doesn't properly validate certain types of datasets when loading `.keras` or `.h5` model files. An attacker can create a specially crafted model that, when loaded by a user, silently reads sensitive files from the filesystem without the user's knowledge. This is a regression—a previously patched vulnerability was incompletely fixed, leaving the door open to the same attack vector.
- CVE-2026-1288MEDIUM 5.5
Autodesk Revit contains a vulnerability that can be triggered when converting a specially crafted RFA (Revit Family) file to FormIt format using the built-in "Convert RFA to FormIt" feature. A successful attack causes the application to crash, rendering it unavailable to the user. The vulnerability requires local access and user interaction—someone must explicitly open and convert a malicious file—but does not allow an attacker to steal data or modify files. The crash is a denial-of-service impact only.
- CVE-2026-13508MEDIUM 5.5
Khoj AI's conversational search platform contains an authorization bypass vulnerability in its conversation sharing feature. By manipulating the conversation.agent parameter, an authenticated user can gain inappropriate access to conversations they shouldn't be able to view or modify. The vulnerability affects Khoj up to version 2.0.0-beta.28 and can be exploited remotely without additional privileges beyond basic authentication. A fix has been proposed but not yet merged into the codebase.
- CVE-2026-13750MEDIUM 5.5
Snowflake CLI versions before 3.19 inadvertently write authentication credentials—including passwords, API tokens, and private keys—to unencrypted debug log files stored locally on a user's machine. An attacker who gains read access to these logs (either through local system compromise, misconfigured file permissions, or physical access) can extract valid credentials without needing to crack them. The risk is confined to users running affected versions who have active credentials in their CLI session. Upgrading to version 3.19 or later stops this leakage at the source.
- CVE-2026-13769MEDIUM 5.5
AWS CLI versions before 1.44.78 (v1) and 2.34.29 (v2) create credential files with overly permissive file permissions on Unix-like systems. When a system's umask is not restrictively configured—which is the default on most Linux and macOS installations—other local users with access to the same machine can read sensitive AWS credentials that the CLI writes to disk. This affects three specific CLI subcommands: aws codeartifact login, aws iam create-virtual-mfa-device, and aws deploy register. An attacker with local system access could steal these credentials and use them to access AWS resources.
- CVE-2026-13914MEDIUM 5.5
Google Chrome on macOS contains a vulnerability in its password handling that could allow a local attacker to read sensitive data from the browser's memory if the user interacts with a specially crafted file. The vulnerability affects Chrome versions before 150.0.7871.47 on Mac systems. An attacker would need local access to the affected system and require user interaction to trigger the vulnerability, but no special privileges are needed to exploit it.
- CVE-2026-13929MEDIUM 5.5
A flaw in Google Chrome's Developer Tools on Android lets a local attacker trick the browser into ignoring certain navigation restrictions by supplying a malicious file. The attacker needs physical or local access to the device and user interaction (like opening a file), but doesn't require elevated permissions. The impact is limited to unauthorized navigation—not data theft or system crashes—making this a moderate-severity issue.
- CVE-2026-14607MEDIUM 5.5
CVE-2026-14607 is a memory corruption vulnerability affecting RT-Thread versions up to 5.0.2. The flaw exists in the sys_getaddrinfo function and can be triggered by manipulating the ai_addr argument during local system calls. An attacker with local access can crash the system or trigger undefined behavior through memory corruption. Exploit code has been publicly released, increasing the practical risk despite the medium CVSS score.
- CVE-2026-14867MEDIUM 5.5
PcVue projects store built-in user credentials in an insecure manner within the User directory. A local attacker with limited system access can retrieve these credentials without elevated privileges. Active Directory-integrated accounts are unaffected. The vulnerability exists in all versions before 17.0.0.
- CVE-2026-14868MEDIUM 5.5
PcVue, a SCADA/industrial automation platform by ArcInfo, uses weak encryption to protect user account configuration data stored locally in project files. An attacker with local access to a system running PcVue can exploit this weakness to decrypt and modify account settings, potentially escalating their privileges within the application. All versions before 17.0.0 are affected. This is a local-only risk that requires an existing account on the machine, but the consequences—unauthorized administrative access to an industrial control interface—are serious.
- CVE-2026-15163MEDIUM 5.5
Wireshark, a widely-used network traffic analysis tool, contains multiple bugs in its protocol dissectors—the components that interpret different network protocols—that can cause the application to loop infinitely when processing specially crafted packets. An attacker or malicious file can trigger these infinite loops, freezing Wireshark and making it unresponsive until the process is forcibly terminated. This affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The vulnerability requires user interaction (opening a malicious capture file or analyzing a malicious packet stream) but does not allow data theft or system compromise—only denial of service.
- CVE-2026-15164MEDIUM 5.5
A crash vulnerability exists in Wireshark's ciscodump utility affecting versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The flaw can be triggered locally by an unprivileged user through user interaction, causing the application to crash and denying service to legitimate users. This is a moderate-severity issue with no code execution or data exposure risk.
- CVE-2026-15165MEDIUM 5.5
Wireshark versions 4.6.0 through 4.6.6 contain a flaw in how they process TLS Encrypted Client Hello (ECH) data that can cause the application to crash when a user opens a maliciously crafted network capture file. This is a denial-of-service issue—an attacker cannot steal data or gain control of your system, but they can disrupt your ability to analyze network traffic. The vulnerability requires user interaction (opening a file) and only affects your local machine.
- CVE-2026-15166MEDIUM 5.5
Wireshark, a widely-used network traffic analysis tool, contains a flaw in its IEEE 802.11 wireless protocol parser that can cause the application to crash when processing specially crafted network packets. The vulnerability affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. An attacker who can trick a user into opening a malicious packet capture file or viewing live traffic on a compromised network could trigger a denial of service, forcing the analyst to restart their investigation. While the impact is localized to availability rather than exposing sensitive data, this disruption can interfere with incident response workflows and network troubleshooting.
- CVE-2026-15169MEDIUM 5.5
A vulnerability in Wireshark's UMTS FP protocol dissector can cause the application to crash when processing malformed network packets. This affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. An attacker could exploit this by crafting a specially designed UMTS packet that, when analyzed by Wireshark, triggers a denial of service condition, rendering the packet analysis tool temporarily unavailable.
- CVE-2026-15170MEDIUM 5.5
Wireshark, the widely-used network analysis tool, contains a flaw in how it processes Z39.50 protocol traffic that can cause the application to crash. An attacker or malicious network traffic could trigger this crash, disrupting network troubleshooting and monitoring operations. This affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The vulnerability requires local access and user interaction to exploit, limiting its attack surface.
- CVE-2026-15171MEDIUM 5.5
Wireshark, the widely-used network packet analyzer, contains a flaw in its SSH protocol dissector that causes the application to crash when processing certain malformed SSH traffic. An attacker or adversary could exploit this by crafting specially malicious SSH packets that, when analyzed by a vulnerable Wireshark instance, would trigger a denial-of-service condition. The issue affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. While the vulnerability requires local user interaction (opening a file or live capture), it does not lead to data theft or system compromise—only application failure.
- CVE-2026-15172MEDIUM 5.5
Wireshark, a widely-used network traffic analysis tool, contains a flaw in how it processes FMP/NOTIFY protocol packets. When a user opens a specially crafted network capture file or views malicious traffic, the dissector (the component that parses the protocol) crashes, causing Wireshark to stop responding. This is a local denial-of-service issue affecting versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. An attacker would need to deliver a malicious capture file or convince a user to analyze untrusted network traffic, but no special privileges are required on the target system.
- CVE-2026-15174MEDIUM 5.5
Wireshark, a widely-used network packet analyzer, contains a flaw in its Catapult DCT2000 protocol dissector that can crash the application when processing malformed network packets. An attacker or malicious network traffic could trigger this crash, effectively denying service to anyone relying on Wireshark for network analysis. The vulnerability affects versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. Users outside these ranges are unaffected.
- CVE-2026-20259MEDIUM 5.5
A vulnerability in Splunk Enterprise and Splunk Cloud Platform allows authenticated users with the `edit_saved_search_owner` capability to reassign ownership of saved searches to any user, including those outside their normal scope of access. The affected endpoint lacks proper authorization checks, creating an avenue for privilege escalation or lateral movement within Splunk deployments. The vulnerability requires an authenticated attacker with a specific high-privilege role, limiting but not eliminating risk in environments where role delegation is common.
- CVE-2026-20456MEDIUM 5.5
A flaw in MediaTek's wireless LAN driver allows an authenticated local user to crash the system without any user interaction. The vulnerability stems from missing boundary validation in the wlan STA (Station) driver code, permitting an attacker with user-level access to send crafted input that causes an out-of-bounds write. The impact is denial of service—the device becomes unresponsive until rebooted.
- CVE-2026-21017MEDIUM 5.5
A privilege-escalation vulnerability exists in Samsung's SecTelephonyProvider component affecting multiple Android devices. A local attacker with basic user privileges can exploit improper access controls to read sensitive files that should be restricted to system-level processes. This is a local-only attack—the attacker must already have some access to the device—but once exploited, it can expose confidential data. Samsung addressed this flaw in the June 2026 SMR (Security Maintenance Release) 1.
- CVE-2026-21025MEDIUM 5.5
A privilege assignment flaw in Samsung's Telephony component allows local users to read sensitive information on affected Android devices. The vulnerability requires an attacker to already have local access to the device—meaning physical possession or a compromised app—but does not let them modify data or crash the system. Samsung addressed this in the June 2026 Security Maintenance Release 1 (SMR Jun-2026 Release 1).
- CVE-2026-21026MEDIUM 5.5
SpriteWallpaper, a Samsung Android component, contains a flaw that allows local attackers to read sensitive information stored within the application. The vulnerability stems from improper export of application components—essentially, the app fails to adequately restrict access to data that should be private. An attacker with local device access can exploit this to view confidential information. This is a moderate-severity issue that affects multiple Samsung Android releases prior to the June 2026 Security Maintenance Release (SMR) update.
- CVE-2026-21028MEDIUM 5.5
A flaw in Samsung's AuditLogService component fails to properly restrict access to sensitive information, allowing local users with basic device access to read data they shouldn't be able to see. The vulnerability is present in Android releases prior to June 2026 Security Maintenance Release 1 and has a moderate severity rating.
- CVE-2026-21036MEDIUM 5.5
Samsung Internet prior to version 30.0.0.39 contains an authorization flaw that allows a local attacker—someone already with access to the device—to read sensitive information they shouldn't have permission to access. The attacker doesn't need to interact with the user or have elevated system privileges, but they do need to have at least basic local access. This is a confidentiality risk, not a data-destruction or service-disruption issue.
- CVE-2026-21038MEDIUM 5.5
CVE-2026-21038 is a memory access vulnerability in Samsung's Android USB Driver for Windows. A locally authenticated user can trigger improper input validation to read sensitive data from memory outside the bounds of allocated buffers. The vulnerability requires local access and an authenticated session but does not require user interaction. It affects confidentiality but not integrity or availability.
- CVE-2026-28237MEDIUM 5.5
AMD uProf, a performance profiling tool used by developers and system administrators, contains a flaw in how it allocates system resources. An authenticated local user can trigger excessive resource consumption—such as memory or CPU—causing the application or system to become unresponsive or crash. This is a localized availability issue that does not expose data or allow privilege escalation, but it can disrupt legitimate work on affected machines.
- CVE-2026-28573MEDIUM 5.5
CVE-2026-28573 is a medium-severity vulnerability in Android's manifest configuration that allows a local attacker with limited user privileges to repeatedly crash or disable Android system functionality without needing to interact with the device directly. The flaw stems from missing permission validation in the AndroidManifest.xml processing, making it trivial to exploit once an attacker gains basic system access.
- CVE-2026-28575MEDIUM 5.5
A logic error in Android's package installation code allows a locally authenticated attacker to exhaust device memory, causing the system to become unresponsive or crash. The vulnerability exists in how the system handles file transfers during app installation and requires only local access—no special permissions or user interaction needed to trigger the denial of service.
- CVE-2026-28576MEDIUM 5.5
A SQL injection flaw in Android's Contacts Provider allows a local attacker with basic user permissions to read sensitive contact information from the device's contacts database without needing special privileges or user interaction. The vulnerability is limited to information disclosure—attackers cannot modify or delete data, but they can extract the entire contacts database contents.
- CVE-2026-28578MEDIUM 5.5
A flaw in Android's device policy management system allows a local attacker to cause the device to become unstable or unresponsive by exploiting improper input validation in DevicePolicyManagerService. An attacker with basic user-level access can trigger this issue without user interaction, potentially disrupting device functionality. This is a local denial-of-service vulnerability with no remote attack vector.
- CVE-2026-28587MEDIUM 5.5
CVE-2026-28587 is a local information disclosure vulnerability in Android's MmsSmsProvider component that allows an authenticated attacker to retrieve sensitive information without additional privileges or user interaction. The vulnerability stems from a missing permission check in the MmsSmsProvider.java file, potentially exposing SMS and MMS data to unauthorized local access.
- CVE-2026-3196MEDIUM 5.5
A flaw in the virtio-snd (virtual sound device) component allows a guest operating system to trick the host hypervisor into allocating excessive memory by sending specially crafted PCM (Pulse Code Modulation) stream count requests. This can exhaust host resources and render the system unresponsive—a denial-of-service condition. The vulnerability requires local access (the attacker must be running code on the guest VM), but poses meaningful risk in multi-tenant cloud or shared virtualization environments.
- CVE-2026-32315MEDIUM 5.5
motionEye versions before 0.44.0 store sensitive configuration files with overly permissive file access controls. Any user on the system can read the admin password hash and camera credentials from plain-text configuration files. An attacker with local access could extract these credentials, crack the password hash offline, and use it to impersonate an administrator—potentially combining this with other known flaws in motionEye to take complete control of the system.
- CVE-2026-33802MEDIUM 5.5
A local authentication bypass in Juniper EX Series switches allows an already-logged-in user without special privileges to run a sensitive CLI command that crashes network traffic, effectively disabling the switch until it recovers on its own. The attacker must already have console or SSH access, but does not need administrative rights to cause the outage.
- CVE-2026-34657MEDIUM 5.5
CAI Content Credentials, a library used to manage and verify digital content authenticity, contains a path traversal flaw in versions [email protected], c2pa-v0.80.1 and earlier. The vulnerability allows an attacker to write files to arbitrary locations on a system by crafting a malicious archive that, when extracted by a user, exploits insufficient pathname validation. This is a local attack requiring user interaction—an end user must actively extract or open the malicious file for the attack to succeed.
- CVE-2026-34703MEDIUM 5.5
A flaw in Adobe InDesign versions 21.3, 20.5.3 and earlier can cause the application to crash when a user opens a specially crafted malicious file. The vulnerability stems from improper handling of null pointer references in memory, which an attacker could weaponize by distributing a booby-trapped document. While this doesn't allow an attacker to steal data or take control of your system, it does enable denial-of-service attacks that interrupt work and productivity.
- CVE-2026-34704MEDIUM 5.5
InDesign Desktop has a vulnerability that causes the application to crash when a user opens a specially crafted malicious file. While the crash itself doesn't expose data or allow an attacker to take control of the system, it does disrupt work by forcing the application to shut down unexpectedly. Versions 21.3, 20.5.3, and earlier are affected. An attacker must trick someone into opening the malicious file—the vulnerability does not spread on its own or affect systems remotely.
- CVE-2026-34705MEDIUM 5.5
Adobe InDesign has a memory-reading vulnerability that can expose sensitive data stored in the application's working memory. When a user opens a specially crafted file, the vulnerability allows an attacker to read beyond the intended boundaries of memory, potentially revealing passwords, encryption keys, or other confidential information. This is a local attack that requires user interaction—the victim must be tricked into opening a malicious file. The vulnerability affects InDesign versions 21.3, 20.5.3, and earlier on both Windows and macOS systems.
- CVE-2026-36907MEDIUM 5.5
A stack overflow vulnerability exists in Bento4, a multimedia framework used for MP4 file processing. The flaw resides in how the AP4_StsdAtom component handles crafted MP4 files, allowing an attacker to trigger a denial-of-service condition by causing the application to crash. The vulnerability requires local access and user interaction (opening a malicious file), but does not allow data theft or system modification—only service disruption.
- CVE-2026-36908MEDIUM 5.5
Bento4, a popular MP4 multimedia library, contains a stack overflow flaw that crashes applications when processing specially crafted MP4 files. An attacker can trigger this denial-of-service condition by tricking a user into opening a malicious video file. The vulnerability affects Bento4 versions before 1.8.9 and is moderately severe because it requires user interaction but can reliably disable affected services.