Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2026-4018 | TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel. | 6.4 | 0.09% | 2026-07-14 | 2026-07-15 |
| CVE-2026-4017 | Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel. | 7.4 | 0.12% | 2026-07-14 | 2026-07-15 |
| CVE-2026-0515 | Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel. | 6.2 | 0.11% | 2026-07-14 | 2026-07-15 |
| CVE-2025-8090 | Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel. | 6.2 | 0.12% | 2026-01-13 | 2026-06-17 |
| CVE-2025-12766 | An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) version 7.21 could allow an attacker to potentially gain unauthorized knowledge about other organizations hosted on the same Interactive Warning System (IWS). | 5.0 | 0.16% | 2025-11-19 | 2026-06-17 |
| CVE-2025-2474 | Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec. | 9.8 | 0.61% | 2025-06-10 | 2026-06-17 |
| CVE-2024-48858 | Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec. | 7.5 | 0.55% | 2025-01-14 | 2026-06-17 |
| CVE-2024-48857 | NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec. | 7.5 | 0.43% | 2025-01-14 | 2026-06-17 |
| CVE-2024-48856 | Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec. | 9.8 | 0.61% | 2025-01-14 | 2026-06-17 |
| CVE-2024-48855 | Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec. | 5.3 | 0.35% | 2025-01-14 | 2026-06-17 |
| CVE-2024-48854 | Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec. | 5.3 | 0.35% | 2025-01-14 | 2026-06-17 |
| CVE-2024-51723 | A Stored Cross-Site Scripting (XSS) vulnerability in the Management Console of BlackBerry AtHoc version 7.15 could allow an attacker to potentially execute actions in the context of the victim's session. | 4.6 | 0.27% | 2024-11-25 | 2026-06-17 |
| CVE-2024-51722 | A local privilege escalation vulnerability in the SecuSUITE Server (System Configuration) of SecuSUITE versions 5.0.420 and earlier could allow a successful attacker that had gained control of code running under one of the system accounts listed in the configuration file to potentially issue privileged script commands. | 6.4 | 0.05% | 2024-11-12 | 2026-06-17 |
| CVE-2024-51721 | A code injection vulnerability in the SecuSUITE Server Web Administration Portal of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially inject script commands or other executable content into the server that would run with root privilege. | 7.3 | 0.23% | 2024-11-12 | 2026-06-17 |
| CVE-2024-51720 | An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number. | 4.8 | 0.31% | 2024-11-12 | 2026-06-17 |
| CVE-2024-35215 | NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process. | 6.2 | 0.16% | 2024-10-08 | 2026-06-17 |
| CVE-2024-35214 | A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.3 could allow an attacker to potentially uninstall CylanceOPTICS from a system thereby leaving it with only the protection of CylancePROTECT. | 7.1 | 0.19% | 2024-08-20 | 2026-06-17 |
| CVE-2024-35213 | An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process. | 9.0 | 0.52% | 2024-06-11 | 2026-06-17 |
| CVE-2023-32701 | Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause Information Disclosure or a Denial-of-Service condition. | 7.1 | 0.24% | 2023-11-14 | 2026-06-17 |
| CVE-2023-21523 | A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and Alerts) of BlackBerry AtHoc version 7.15 could allow an attacker to execute script commands in the context of the affected user account. | 5.4 | 0.30% | 2023-09-12 | 2026-06-17 |