Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Hdf5 MEDIUM 5.5
CVE-2026-29043

HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buf…

Fix: after 1.14.1-2
Fix from $1,600 2026-04-10
Wolfssl CRITICAL 9.8
CVE-2026-5264

Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer overfl…

Fix: 5.9.1+
Fix from $2,300 2026-04-09
Wolfssl HIGH 7.5
CVE-2026-5447

Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when converting an X.509 certificate in…

Fix: 5.9.1+
Fix from $1,950 2026-04-09
Wolfssl CRITICAL 9.8
CVE-2026-5187

Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one availab…

Fix: after 5.9.0
Fix from $2,300 2026-04-09
Chrome HIGH 8.8
CVE-2026-5868

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome HIGH 8.8
CVE-2026-5858

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (C…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Symcrypt MEDIUM 6.1
CVE-2026-35199

SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes …

Fix: 103.11.0+
Fix from $1,600 2026-04-06
X2000094 Firmware HIGH 7.8
CVE-2026-21372

Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.

Mitigation only
Fix from $1,950 2026-04-06
Cups MEDIUM 5.3
CVE-2026-34979

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-ba…

Fix: after 2.4.16
Fix from $1,600 2026-04-03
Core Flight System HIGH 8.8
CVE-2026-5474

A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c…

Fix: after 7.0.0
Fix from $1,950 2026-04-03
Xz MEDIUM 5.3
CVE-2026-34743

XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to deco…

Fix: 5.8.3+
Fix from $1,600 2026-04-02
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-34118

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missin…

Fix: 1.2.4+
Fix from $1,600 2026-04-02
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-34119

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when appending segmented request b…

Fix: 1.2.4+
Fix from $1,600 2026-04-02
Tapo C520ws Firmware MEDIUM 6.5
CVE-2026-34120

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of local video stream content d…

Fix: 1.2.4+
Fix from $1,600 2026-04-02
Mongoose CRITICAL 9.8
CVE-2026-5244

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS…

Fix: 7.21+
Fix from $2,300 2026-04-02
Openexr HIGH 7.3
CVE-2026-34545

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From…

Fix: 3.4.7+
Fix from $1,950 2026-04-01
Chrome HIGH 8.8
CVE-2026-5272

Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Ch…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome HIGH 8.8
CVE-2026-5275

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML …

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Unclassified MEDIUM 5.3
CVE-2026-5235

A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4_BitReader::ReadCache of the file Ap4Dac4Atom.cpp of…

Mitigation only
Fix from $1,600 2026-03-31
Unclassified MEDIUM 5.3
CVE-2026-5236

A vulnerability was identified in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_BitReader::SkipBits of the file Ap4Dac4Atom.cpp of t…

Mitigation only
Fix from $1,600 2026-03-31
Iccdev MEDIUM 5.5
CVE-2026-34539

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile and TIFF…

Fix: 2.3.1.6+
Fix from $1,600 2026-03-31
Iccdev MEDIUM 5.5
CVE-2026-34540

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trig…

Fix: 2.3.1.6+
Fix from $1,600 2026-03-31
Iccdev MEDIUM 5.5
CVE-2026-34534

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trig…

Fix: 2.3.1.6+
Fix from $1,600 2026-03-31
Iccdev MEDIUM 5.5
CVE-2026-34535

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trig…

Fix: 2.3.1.6+
Fix from $1,600 2026-03-31
Enterprise Linux HIGH 7.5
CVE-2026-5201

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation …

Mitigation only
Fix from $1,950 2026-03-31
Unclassified MEDIUM 5.3
CVE-2026-5185

A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of the file stb_image.h of the co…

Mitigation only
Fix from $1,600 2026-03-31
Freerdp MEDIUM 6.6
CVE-2026-33987

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in persistent_cache_read_entry_v3() in libfreerdp/cache/per…

Fix: 3.24.2+
Fix from $1,600 2026-03-30
Freerdp HIGH 7.5
CVE-2026-33984

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEnt…

Fix: 3.24.2+
Fix from $1,950 2026-03-30
Freerdp HIGH 7.5
CVE-2026-33986

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libfreerdp/codec/h264.c, h264->wi…

Fix: 3.24.2+
Fix from $1,950 2026-03-30
Everest MEDIUM 5.9
CVE-2026-26073

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/`std::deque` corruption. The …

Fix: 2026.02.0+
Fix from $1,600 2026-03-26