Vulnerability index

Browse CVEs

3,540 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Stack-based Buffer OverflowCWE-121 × clear
Unclassified HIGH 7.5
CVE-2026-42485

AGL agl-service-can-low-level contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c allocates a 6-byte…

Mitigation only
Fix from $1,950 2026-05-01
Open Vehicle Monitoring System Firmware CRITICAL 10.0
CVE-2026-37541

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is n…

Mitigation only
Fix from $2,300 2026-05-01
Unclassified HIGH 8.8
CVE-2026-37536

miaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7a (2016-10-05) contains a stack buffer overflow in send_diagnostic_request. A 6-byte stac…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified HIGH 7.5
CVE-2026-37538

Buffer overflow vulnerability in socketcand 0.4.2 in file socketcand.c in function main allows attackers to cause a denial of service or other unspec…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-37539

Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFr…

Mitigation only
Fix from $2,300 2026-05-01
Automotive Grade Linux HIGH 7.5
CVE-2026-37530

AGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c alloc…

Fix: after 17.1.12
Fix from $1,950 2026-05-01
Hashcat CRITICAL 9.8
CVE-2026-42482

A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a deni…

Mitigation only
Fix from $2,300 2026-05-01
Unclassified CRITICAL 10.0
CVE-2026-42996

JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long …

Patch available
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-7546

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the compon…

Mitigation only
Fix from $2,300 2026-05-01
Secure Access MEDIUM 6.5
CVE-2026-40950

CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send …

Fix: 14.50+
Fix from $1,600 2026-04-30
Secure Access HIGH 7.5
CVE-2026-33449

CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified…

Fix: 14.50+
Fix from $1,950 2026-04-30
Secure Access MEDIUM 5.5
CVE-2026-33452

CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows c…

Fix: 14.50+
Fix from $1,600 2026-04-30
Secure Access CRITICAL 9.8
CVE-2026-33447

CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified …

Fix: 14.50+
Fix from $2,300 2026-04-30
FreeBSD HIGH 7.8
CVE-2026-39457

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descrip…

Mitigation only
Fix from $1,950 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-6537

ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-6538

BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark HIGH 7.5
CVE-2026-5654

AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,950 2026-04-30
Wireshark HIGH 7.5
CVE-2026-6868

HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: 4.4.15 / 4.6.5+
Fix from $1,950 2026-04-30
4g300 Firmware HIGH 8.8
CVE-2026-7470

A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This ma…

Mitigation only
Fix from $1,950 2026-04-30
Unclassified HIGH 8.4
CVE-2018-25303

Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to exec…

No fix yet
Fix from $1,950 2026-04-29
Wazuh HIGH 8.2
CVE-2026-28221

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-ba…

Fix: 4.14.4+
Fix from $1,950 2026-04-29
Unclassified HIGH 7.5
CVE-2026-36837

TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname parameter in the formMapDelDevi…

Mitigation only
Fix from $1,950 2026-04-29
Hg3 Firmware HIGH 8.8
CVE-2026-7151

A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of…

No fix yet
Fix from $1,950 2026-04-27
Fh1202 Firmware HIGH 8.8
CVE-2026-7035

A vulnerability was determined in Tenda FH1202 1.2.0.14. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component…

No fix yet
Fix from $1,950 2026-04-26
Fh1202 Firmware HIGH 8.8
CVE-2026-7034

A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function WrlExtraSet of the file /goform/WrlExtraSet of the co…

No fix yet
Fix from $1,950 2026-04-26
Arduino Esp32 HIGH 8.8
CVE-2026-41429

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, there is a remo…

Fix: 3.3.8+
Fix from $1,950 2026-04-24
Rust Openssl HIGH 7.5
CVE-2026-41681

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX…

Fix: 0.10.78+
Fix from $1,950 2026-04-24
As320t Firmware CRITICAL 9.8
CVE-2026-1951

Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.

Fix: 1.12+
Fix from $2,300 2026-04-24
As320t Firmware CRITICAL 9.8
CVE-2026-1950

Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.

Fix: 1.16+
Fix from $2,300 2026-04-24
Powerprotect Dp Series Appliance CRITICAL 9.8
CVE-2026-26354

Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 t…

Fix: 2.7.9 / 7.13.1.60+
Fix from $2,300 2026-04-22