VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,982 CVE recordsPage 648 of 1333 · EPSS data 2026.08.13
ReviewHigh
CVE-2026-0156

Google Android, android

In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0154

Google Android, android

In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0153

Google Android, android

In Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0152

Google Android, android

In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to maliciously expand the VMA out of bounds due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0151

Google Android, android

In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0150

Google Android, android

In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with root privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0149

Google Android, android

In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0148

Google Android, android

In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0147

Google Android, android

In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0146

Google Android, android

In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0143

Google Android, android

In lwis_device_external_event_emit of lwis_event.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0139

Google Android, android

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0138

Google Android, android

In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0137

Google Android, android

In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0135

Google Android, android

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

The CVSS severity warrants an early asset and exposure review.