Vulnerability index

Browse CVEs

2,635 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Unclassified MEDIUM 6.8
CVE-2026-35590

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verify…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.0
CVE-2026-35591

libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could inco…

No fix yet
Fix from $1,950 2026-07-20
Proftpd HIGH 8.8
CVE-2026-63090

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privileg…

Fix: 1.3.9c+
Fix from $1,950 2026-07-20
Freerdp CRITICAL 9.1
CVE-2026-64620

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function wri…

Fix: 3.28.0+
Fix from $2,300 2026-07-20
Proftpd MEDIUM 6.5
CVE-2026-53994

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-s…

Fix: 1.3.10+
Fix from $1,600 2026-07-18
Unclassified HIGH 8.8
CVE-2026-11826

OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between tw…

No fix yet
Fix from $1,950 2026-07-18
Acrobat HIGH 7.8
CVE-2026-48373

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current …

Fix: 24.001.30383 / 26.001.21662+
Fix from $1,950 2026-07-17
Unclassified HIGH 7.1
CVE-2026-16118

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little…

No fix yet
Fix from $1,950 2026-07-17
Storage Protect CRITICAL 9.8
CVE-2026-13473

IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer o…

Fix: 8.2.1.2+
Fix from $2,300 2026-07-17
Wazuh HIGH 7.8
CVE-2026-40106

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap…

Fix: 4.14.5+
Fix from $1,950 2026-07-17
Wazuh MEDIUM 6.5
CVE-2026-44251

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t …

Fix: 4.14.5+
Fix from $1,600 2026-07-17
Wazuh HIGH 7.5
CVE-2026-34150

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap bu…

Fix: 4.14.5+
Fix from $1,950 2026-07-17
Unclassified CRITICAL 9.1
CVE-2026-15422

The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chu…

No fix yet
Fix from $2,300 2026-07-16
Unclassified MEDIUM 5.8
CVE-2026-15449

A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC_GETMACPROP and DLDIOC_SETMAC…

No fix yet
Fix from $1,600 2026-07-16
Squid MEDIUM 5.5
CVE-2026-50012

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in s…

Fix: 7.6+
Fix from $1,600 2026-07-16
Busybox MEDIUM 5.1
CVE-2026-38754

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a cra…

Mitigation only
Fix from $1,600 2026-07-15
Busybox HIGH 7.5
CVE-2026-38755

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a cr…

Mitigation only
Fix from $1,950 2026-07-15
Nginx Gateway Fabric HIGH 8.1
CVE-2026-42533

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's rege…

Fix: 2.6.7 / 5.5.3+
Fix from $1,950 2026-07-15
Bridge HIGH 7.8
CVE-2026-48339

Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Ex…

Fix: 15.1.5 / 16.0.3+
Fix from $1,950 2026-07-14
Premiere Pro HIGH 7.8
CVE-2026-48269

Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current us…

Fix: after 26.2.2
Fix from $1,950 2026-07-14
Unclassified HIGH 7.5
CVE-2026-47471

NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. …

Mitigation only
Fix from $1,950 2026-07-14
Tensorrt HIGH 7.8
CVE-2026-24268

NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might…

Fix: 11.0+
Fix from $1,950 2026-07-14
Tensorrt HIGH 7.8
CVE-2026-24272

NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability…

Fix: 11.0+
Fix from $1,950 2026-07-14
Chrome HIGH 8.8
CVE-2026-15767

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandb…

Fix: 150.0.7871.125+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.8
CVE-2026-58542

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-58547

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-58538

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-58534

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-58530

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.8
CVE-2026-57094

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14