Vulnerability index

Browse CVEs

4,220 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Classic Buffer OverflowCWE-120 × clear
Libraw CRITICAL 9.8
CVE-2026-20889

A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file …

Mitigation only
Fix from $2,300 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-20911

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially cr…

Mitigation only
Fix from $2,300 2026-04-07
Exynos W1000 Firmware CRITICAL 9.8
CVE-2025-52909

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…

Mitigation only
Fix from $2,300 2026-04-07
Firefox CRITICAL 9.8
CVE-2026-5734

Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed eviden…

Fix: 140.9.1 / 149.0.2+
Fix from $2,300 2026-04-07
Job Management Partner 1\/it Desktop Management Manager MEDIUM 5.5
CVE-2025-65116

Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job …

Fix: after 13-01-06
Fix from $1,600 2026-04-07
Cologne Firmware HIGH 7.8
CVE-2026-21382

Memory Corruption when handling power management requests with improperly sized input/output buffers.

No fix yet
Fix from $1,950 2026-04-06
Ar8035 Firmware HIGH 7.8
CVE-2025-47389

Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 8.8
CVE-2026-5566

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Pe…

Mitigation only
Fix from $1,950 2026-04-05
M3 Firmware HIGH 8.8
CVE-2026-5567

A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the comp…

No fix yet
Fix from $1,950 2026-04-05
Unclassified CRITICAL 9.8
CVE-2018-25237

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication …

Mitigation only
Fix from $2,300 2026-04-03
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-34124

A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces …

Fix: 1.2.4+
Fix from $1,600 2026-04-02
Mbed Tls CRITICAL 9.8
CVE-2026-34875

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

Fix: 1.1.0 / 3.6.6+
Fix from $2,300 2026-04-01
A3600r Firmware CRITICAL 9.8
CVE-2026-31027

TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerab…

Mitigation only
Fix from $2,300 2026-04-01
Chrome HIGH 8.8
CVE-2026-5279

Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Virtio Win MEDIUM 5.5
CVE-2026-5164

A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap …

Patch available
Fix from $1,600 2026-03-30
Zephyr HIGH 7.8
CVE-2026-1679

The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; oversized sends overflow `eswifi…

Fix: after 4.3.0
Fix from $1,950 2026-03-28
Lr350 Firmware HIGH 8.8
CVE-2026-4976

A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstec…

No fix yet
Fix from $1,950 2026-03-27
Hcxtools MEDIUM 6.2
CVE-2026-29976

Buffer Overflow vulnerability in ZerBea hcxpcapngtool v. 7.0.1-43-g2ee308e allows a local attacker to obtain sensitive information via the getradiota…

No fix yet
Fix from $1,600 2026-03-26
Unclassified HIGH 8.8
CVE-2026-4862

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file /goform/…

Mitigation only
Fix from $1,950 2026-03-26
Unclassified HIGH 7.2
CVE-2024-51347

A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handling of the Time Zone (TZ) para…

Mitigation only
Fix from $1,950 2026-03-25
Ipados HIGH 7.5
CVE-2026-28875

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may be able to caus…

Fix: 26.4+
Fix from $1,950 2026-03-25
Safari MEDIUM 6.5
CVE-2026-28857

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4.…

Fix: 26.4+
Fix from $1,600 2026-03-25
Ipados CRITICAL 9.8
CVE-2026-28858

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause un…

Fix: 26.4+
Fix from $2,300 2026-03-25
macOS MEDIUM 6.2
CVE-2026-28841

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corrup…

Fix: 26.4+
Fix from $1,600 2026-03-25
Nginx Plus HIGH 8.2
CVE-2026-27654EPSS 22%

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to …

Fix: 1.28.3 / 1.29.7+
Fix from $1,950 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4729

Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4720

Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4721

Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showe…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Firefox HIGH 8.6
CVE-2026-4687

Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Fire…

Fix: 115.34.0 / 140.9.0+
Fix from $1,950 2026-03-24
Firefox CRITICAL 10.0
CVE-2026-4689

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ES…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24