CVE & CISA-KEV Catalog

395,283 CVEs1,715 actively exploited (KEV)
Active:
  • CVSS 8.5 v3·EPSS -·No fix yet

    A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service. This vulnerability is due to an error when checking the privilege level of a user who is invoking remote diagnostics. An attacker could exploit this vulnerability by authenticating to the device, either through the web-based management interface or the REST API, and using the remote diagnostics debugger to grant a user elevated privileges. A successful exploit could allow the attacker to elevate privileges to root. Notes: To exploit this vulnerability, the attacker must have valid user credentials on the affected device. The CVSSv3.1 Attack Complexity is High due to the multistage process required to fully e

    Published 2026-09-16

  • CVSS 4.3 v3·EPSS 0.1%·No fix yet

    DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-09-09

  • CVSS 7.1 v3·EPSS 0.1%·No fix yet

    DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-09-09

  • CVSS 5.5 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-09-09

  • CVSS 4.0 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-09-09

  • CVSS 8.6 v3·EPSS 0.3%·No fix yet

    Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-09-09

  • CVSS 4.8 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-09-09

  • CVSS 6.2 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-09-09

  • CVSS 5.5 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-08-17

  • CVSS 6.2 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-08-17

  • CVSS 5.1 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-08-17

  • CVSS 5.6 v3·EPSS 0.3%·No fix yet

    A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published 2026-08-03

  • CVSS 5.1 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-07-15

  • CVSS 6.6 v3·EPSS 0.1%·No fix yet

    Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-07-15

  • CVSS 6.3 v3·EPSS 0.4%·No fix yet

    A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipulation leads to sandbox issue. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.

    Published 2026-07-06

  • CVSS 3.6 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-06-09

  • CVSS 7.3 v3·EPSS 0.4%·No fix yet

    A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox issue. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published 2026-05-24

  • CVSS 3.6 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-05-15

  • CVSS 5.6 v3·EPSS 0.3%·No fix yet

    A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published 2026-04-23

  • CVSS 7.3 v3·EPSS 0.3%·No fix yet

    A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published 2026-04-13

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component install-upload Endpoint. The manipulation of the argument File results in sandbox issue. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published 2026-04-12

  • CVSS 8.8 v3·EPSS 0.1%·Fix available

    A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by using the CLI command to bypass the task group–based checks. A successful exploit could allow the attacker to elevate privileges and perform actions on an affected device without authorization checks.

    Published 2026-03-11

  • CVSS 4.0 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-03-05

  • CVSS 3.3 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.

    Published 2026-03-05

  • CVSS 6.1 v3·EPSS 0.1%·No fix yet

    Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-02-06

  • CVSS 6.2 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2026-02-06

  • CVSS 5.9 v3·EPSS 0.1%·No fix yet

    Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-02-06

  • CVSS 6.3 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-02-06

  • CVSS 5.7 v3·EPSS 0.1%·No fix yet

    Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2026-01-14

  • CVSS 4.0 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2025-12-08

  • CVSS 6.2 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2025-12-08

  • CVSS 8.4 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2025-11-28

  • CVSS 4.4 v3·EPSS 0.1%·No fix yet

    Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.

    Published 2025-11-28

  • CVSS 5.5 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2025-11-28

  • CVSS 5.1 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2025-11-28

  • CVSS 6.8 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

    Published 2025-11-28

  • CVSS 6.2 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2025-11-28

  • CVSS 5.5 v3·EPSS 0.1%·No fix yet

    Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

    Published 2025-10-11

  • CVSS 5.3 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2025-10-11

  • CVSS 5.9 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2025-10-11

  • CVSS 5.5 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2025-10-11

  • CVSS 2.8 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published 2025-10-11

  • CVSS 6.2 v3·EPSS 0.1%·No fix yet

    Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality

    Published 2025-10-11

  • CVSS 6.8 v3·EPSS 0.1%·No fix yet

    Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2025-09-05

  • CVSS 6.2 v3·EPSS 0.1%·No fix yet

    Vulnerability that allows setting screen rotation direction without permission verification in the screen management module. Impact: Successful exploitation of this vulnerability may cause device screen orientation to be arbitrarily set.

    Published 2025-08-06

  • CVSS 5.9 v3·EPSS 0.1%·No fix yet

    Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2025-07-07

  • CVSS 4.8 v3·EPSS 0.1%·No fix yet

    Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.

    Published 2025-07-07

  • CVSS 3.9 v3·EPSS 0.1%·No fix yet

    Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.

    Published 2025-07-07

  • CVSS 4.6 v3·EPSS 0.3%·No fix yet

    A vulnerability was found in Redash up to 10.1.0/25.1.0. It has been rated as problematic. This issue affects the function run_query of the file /query_runner/python.py of the component getattr Handler. The manipulation leads to sandbox issue. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains, that "[t]he Python data source is disabled by default and is clearly marked in our documentation as discouraged due to its security implications. Users who choose to enable it are doing so at their own risk, with full awareness that it bypasses standard safeguards."

    Published 2025-06-09

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.

    Published 2025-06-06

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.