Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Windows 10 1607 HIGH 7.8
CVE-2026-33837

Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Visual Studio 2022 HIGH 7.3
CVE-2026-32177

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

Fix: 8.0.27 / 9.0.16+
Fix from $1,950 2026-05-12
Unclassified HIGH 7.8
CVE-2025-12659

Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 7.8
CVE-2026-42046

libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows …

Patch available
Fix from $1,950 2026-05-11
Unclassified HIGH 8.4
CVE-2026-4892

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root pri…

Patch available
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.9
CVE-2026-8261

A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipul…

Mitigation only
Fix from $1,600 2026-05-11
Gdal MEDIUM 5.5
CVE-2026-8212

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWap…

Fix: after 3.12.4
Fix from $1,600 2026-05-09
Gdal MEDIUM 5.5
CVE-2026-8213

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDa…

Fix: after 3.12.4
Fix from $1,600 2026-05-09
Pillow MEDIUM 5.5
CVE-2026-42309

Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates…

Fix: 12.2.0+
Fix from $1,600 2026-05-09
Neovim MEDIUM 5.5
CVE-2026-45130

Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when …

Fix: 9.2.0450+
Fix from $1,600 2026-05-08
Cross Implementation CRITICAL 9.8
CVE-2026-41509

CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there i…

Fix: 2026-03-23+
Fix from $2,300 2026-05-08
Gdal HIGH 7.8
CVE-2026-8087

A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Perf…

Fix: after 3.12.4
Fix from $1,950 2026-05-07
Gdal HIGH 7.8
CVE-2026-8086

A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Su…

Fix: after 3.12.4
Fix from $1,950 2026-05-07
Chrome HIGH 8.3
CVE-2026-7900

Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Unclassified HIGH 7.7
CVE-2026-20185

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series St…

Mitigation only
Fix from $1,950 2026-05-06
Unclassified HIGH 8.7
CVE-2026-6210

A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker refe…

Mitigation only
Fix from $1,950 2026-05-06
HTTP Server CRITICAL 9.8
CVE-2026-28780

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server …

Fix: 2.4.67+
Fix from $2,300 2026-05-05
Redis HIGH 8.8
CVE-2026-25243

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values…

Fix: 8.6.3+
Fix from $1,950 2026-05-05
Redistimeseries HIGH 8.8
CVE-2026-25588

RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialize…

Fix: 1.12.14+
Fix from $1,950 2026-05-05
Redisbloom HIGH 8.8
CVE-2026-25589

RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate se…

Fix: 2.8.20+
Fix from $1,950 2026-05-05
Gpac MEDIUM 5.5
CVE-2026-39103

Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the…

Fix: 2026-04-01+
Fix from $1,600 2026-05-05
Unclassified HIGH 8.1
CVE-2026-29004

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/u…

Patch available
Fix from $1,950 2026-05-04
Unclassified CRITICAL 9.8
CVE-2025-70067

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, w…

Mitigation only
Fix from $2,300 2026-05-04
Open Cascade Technology HIGH 7.1
CVE-2026-42477

A heap-based out-of-bounds read vulnerability in RWObj_Reader::read in the OBJ file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows user-a…

Fix: after 7.9.3
Fix from $1,950 2026-05-01
Hashcat CRITICAL 9.8
CVE-2026-42483

A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitr…

Mitigation only
Fix from $2,300 2026-05-01
Wireshark HIGH 7.8
CVE-2026-5403

SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Fix: 4.4.15 / 4.6.5+
Fix from $1,950 2026-05-01
Wireshark HIGH 7.8
CVE-2026-5405

RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Fix: 4.4.15 / 4.6.5+
Fix from $1,950 2026-05-01
FreeBSD HIGH 8.1
CVE-2026-35547

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious pro…

Mitigation only
Fix from $1,950 2026-04-30
FreeBSD HIGH 8.1
CVE-2026-42512

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the ar…

Mitigation only
Fix from $1,950 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-6529

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30