Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Windows 11 23h2 MEDIUM 6.7
CVE-2026-20876

Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.6491 / 10.0.25398.2092+
Fix from $1,600 2026-01-13
Windows 10 1607 HIGH 8.8
CVE-2026-20868

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20864

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20840

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20837

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20820

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20809

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Fortios CRITICAL 9.8
CVE-2025-25249

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiO…

Fix: 6.4.17 / 7.0.6+
Fix from $2,300 2026-01-13
Quickjs HIGH 8.8
CVE-2026-0822

A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The man…

Fix: after 0.11.0
Fix from $1,950 2026-01-10
Quickjs CRITICAL 9.8
CVE-2026-0821

A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file qui…

Fix: after 0.11.0
Fix from $2,300 2026-01-10
Cryptolib HIGH 7.5
CVE-2026-22697

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication…

Fix: 1.4.3+
Fix from $1,950 2026-01-10
Cryptolib MEDIUM 6.0
CVE-2026-22027

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication…

Fix: 1.4.3+
Fix from $1,600 2026-01-10
Iccdev HIGH 8.8
CVE-2026-21682

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) co…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-07
Iccdev HIGH 7.8
CVE-2026-21678

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-07
Iccdev HIGH 7.8
CVE-2026-21504

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-07
Iccdev HIGH 7.1
CVE-2026-21494

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) co…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-06
Iccdev HIGH 7.1
CVE-2026-21490

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) co…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-06
Iccdev HIGH 7.1
CVE-2026-21491

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) co…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-06
Iccdev HIGH 7.1
CVE-2026-21488

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-boun…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-06
Iccdev HIGH 8.8
CVE-2026-21676

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have a Heap-based Buffer Overfl…

Fix: 2.3.1.1+
Fix from $1,950 2026-01-06
Iccdev HIGH 7.8
CVE-2026-21486

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below contain Use After Free, Heap-…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-06
Gpsd CRITICAL 9.8
CVE-2025-67268

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, wh…

Fix: 3.27.1+
Fix from $2,300 2026-01-02
Fontforge HIGH 7.8
CVE-2025-15277

FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 7.8
CVE-2025-15279

FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15272

FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15274

FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15275

FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2025-12-31
Matio CRITICAL 9.8
CVE-2025-50343

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the …

Mitigation only
Fix from $2,300 2025-12-30
Snap7 Rs CRITICAL 9.8
CVE-2025-15247

A vulnerability was identified in gmg137 snap7-rs up to 153d3e8c16decd7271e2a5b2e3da4d6f68589424. Affected by this issue is the function snap7_rs::cl…

Mitigation only
Fix from $2,300 2025-12-30
M3 Firmware HIGH 8.8
CVE-2025-15234

A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanIn…

No fix yet
Fix from $1,950 2025-12-30