Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-0240

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

PUBLISHED
Vendor
Palo Alto Networks
Product
Trust Protection Foundation
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0239

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

PUBLISHED
Vendor
Palo Alto Networks
Product
Chronosphere Chronocollector
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0238

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

PUBLISHED
Vendor
Palo Alto Networks
Product
Broker VM
Provider severity
LOW
Conflicts
0

CVE-2026-0237

An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.

PUBLISHED
Vendor
Palo Alto Networks
Product
Prisma Browser
Provider severity
HIGH
Conflicts
0

CVE-2026-0236

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser.

PUBLISHED
Vendor
Palo Alto Networks
Product
Prisma Browser
Provider severity
HIGH
Conflicts
0

CVE-2026-0235

A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.

PUBLISHED
Vendor
Palo Alto Networks
Product
Prisma Browser
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0234

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

PUBLISHED
Vendor
Palo Alto Networks, Palo Alto Networks
Product
Cortex XSIAM Microsoft Teams Marketplace, Cortex XSOAR Microsoft Teams Marketplace
Provider severity
HIGH
Conflicts
1

CVE-2026-0233

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

PUBLISHED
Vendor
Palo Alto Networks
Product
Autonomous Digital Experience Manager
Provider severity
LOW
Conflicts
0

CVE-2026-0232

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

PUBLISHED
Vendor
Palo Alto Networks, Palo Alto Networks
Product
Cortex XDR Agent, Cortex XDR Agent
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0231

An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cortex UI and modifying any configuration setting.  The attacker must have network access to the Broker VM to exploit this issue.

PUBLISHED
Vendor
Palo Alto Networks
Product
Cortex XDR Broker VM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0230

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.

PUBLISHED
Vendor
Palo Alto Networks
Product
Cortex XDR Agent
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0229

A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

PUBLISHED
Vendor
Palo Alto Networks, Palo Alto Networks, Palo Alto Networks
Product
Cloud NGFW, PAN-OS, Prisma Access
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0228

An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.

PUBLISHED
Vendor
Palo Alto Networks, Palo Alto Networks, Palo Alto Networks
Product
Cloud NGFW, PAN-OS, Prisma Access
Provider severity
LOW
Conflicts
1

CVE-2026-0227

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

PUBLISHED
Vendor
Palo Alto Networks, Palo Alto Networks, Palo Alto Networks
Product
Cloud NGFW, PAN-OS, Prisma Access
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0209

Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured.

PUBLISHED
Vendor
PureStorage
Product
FlashArray
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0207

A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.

PUBLISHED
Vendor
PureStorage
Product
FlashBlade
Provider severity
HIGH
Conflicts
0

CVE-2026-0206

A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

PUBLISHED
Vendor
SonicWall
Product
SonicOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0205

A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.

PUBLISHED
Vendor
SonicWall
Product
SonicOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0204

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

PUBLISHED
Vendor
SonicWall
Product
SonicOS
Provider severity
HIGH
Conflicts
1

CVE-2026-0203

An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and restart, resulting in a Denial of Service (DoS). When an ICMP packet is received with a specifically malformed IP header value, the FPC receiving the packet crashes and restarts. Due to the specific type of malformed packet, adjacent upstream routers would no

PUBLISHED
Vendor
Juniper Networks
Product
Junos OS
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-0165

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0164

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0162

In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0161

In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0160

In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0158

In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1

CVE-2026-0157

In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0156

In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0155

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0154

In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0153

In Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0152

In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to maliciously expand the VMA out of bounds due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0151

In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0150

In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with root privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0149

In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0148

In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0147

In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0146

In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0145

In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1

CVE-2026-0144

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0143

In lwis_device_external_event_emit of lwis_event.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0142

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1

CVE-2026-0141

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0140

In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0139

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0138

In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0137

In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0136

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0135

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0134

In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1