Vulnerability index

Browse CVEs

2,635 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Unclassified CRITICAL 9.8
CVE-2026-67191

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write…

No fix yet
Fix from $2,300 2026-07-29
Advance Steel HIGH 7.8
CVE-2026-16463

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage t…

Fix: 2026.1.2+
Fix from $1,950 2026-07-29
Format Plugins HIGH 7.8
CVE-2026-48372

Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current …

Fix: 2026.07+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.8
CVE-2026-51273

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded …

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-51274

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers t…

Mitigation only
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-51275

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing function in audiolib allows remote attackers to ex…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51263

schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON r…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51266

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynam…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51267

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application s…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51268

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untr…

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 8.8
CVE-2026-51269

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function. The application accepts attacker-…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-51270

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the htmlToUTF8() HTML entity decoding function. The function pars…

Mitigation only
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.6
CVE-2026-51271

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The fun…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51259

Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subs…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.4
CVE-2026-51260

Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer overflow. The code cop…

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 8.8
CVE-2026-51235

LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp).

No fix yet
Fix from $1,950 2026-07-27
Thrift CRITICAL 9.8
CVE-2026-55971

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to u…

Fix: 0.24.0+
Fix from $2,300 2026-07-27
Ffmpeg HIGH 8.8
CVE-2026-66040

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remo…

Fix: after 8.1.2
Fix from $1,950 2026-07-24
Ffmpeg HIGH 8.8
CVE-2026-66036

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to cor…

Fix: after 8.1.2
Fix from $1,950 2026-07-24
Ffmpeg HIGH 7.8
CVE-2026-66039

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to c…

Fix: after 8.1.2
Fix from $1,950 2026-07-24
Libssh2 HIGH 7.5
CVE-2026-66035

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server …

Fix: after 1.11.1
Fix from $1,950 2026-07-24
Account CRITICAL 9.8
CVE-2026-56165

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-24
Unclassified HIGH 8.1
CVE-2026-49035

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstra…

No fix yet
Fix from $1,950 2026-07-23
MongoDB HIGH 8.1
CVE-2026-13072

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…

Mitigation only
Fix from $1,950 2026-07-22
Ffmpeg HIGH 8.8
CVE-2026-64830

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjac…

Fix: after 8.1.2
Fix from $1,950 2026-07-22
Unbound HIGH 7.5
CVE-2026-40691

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound …

Fix: 1.25.2+
Fix from $1,950 2026-07-22
Unclassified HIGH 7.7
CVE-2026-61390

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sen…

No fix yet
Fix from $1,950 2026-07-22
Maxicharger Single Charger Firmware HIGH 8.8
CVE-2026-8987

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoi…

Fix: after 1.03.51
Fix from $1,950 2026-07-21
Xrdp HIGH 8.8
CVE-2026-44178

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding…

Fix: 0.10.6.1+
Fix from $1,950 2026-07-20
Xrdp CRITICAL 9.8
CVE-2026-41252

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when o…

Fix: 0.10.6.1+
Fix from $2,300 2026-07-20