Vulnerability index

Browse CVEs

3,540 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Stack-based Buffer OverflowCWE-121 × clear
Fatfs HIGH 7.6
CVE-2026-6687

FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec ma…

No fix yet
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54502

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-base…

Mitigation only
Fix from $1,600 2026-07-01
Safari MEDIUM 6.5
CVE-2026-43718

A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Tl Wr841n Firmware MEDIUM 6.5
CVE-2026-9105

An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated a…

Fix: 14_260518+
Fix from $1,600 2026-06-29
Libxml2 HIGH 7.8
CVE-2026-11979

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function proce…

Fix: after 2.15.3
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-13563

A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component …

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-13564

A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-13539

A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.c…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-13519

A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipu…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-13517

A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-13518

A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation …

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-13515

A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCf…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-13516

A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet.…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 5.5
CVE-2026-36907

A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.5
CVE-2026-36908

A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a…

No fix yet
Fix from $1,600 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57881

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabil…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57878

An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabi…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57879

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabili…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57880

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabili…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified HIGH 8.8
CVE-2026-56766

Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, …

Patch available
Fix from $1,950 2026-06-25
Gpac HIGH 7.5
CVE-2025-60474

A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denia…

Fix: 26.02.0+
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.2
CVE-2026-12488

A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially crafted network request can lea…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified CRITICAL 10.0
CVE-2026-12846

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 10.0
CVE-2026-12847

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 10.0
CVE-2026-12848

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 10.0
CVE-2026-12485

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.4
CVE-2026-44089

Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be expl…

Mitigation only
Fix from $2,300 2026-06-23
Radvd HIGH 8.8
CVE-2026-48715

radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in…

Fix: 2.21+
Fix from $1,950 2026-06-19
Ac7 Firmware CRITICAL 9.8
CVE-2026-51846

In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to rem…

Mitigation only
Fix from $2,300 2026-06-19
Ac7 Firmware CRITICAL 9.8
CVE-2026-51843

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.

Mitigation only
Fix from $2,300 2026-06-19