Vulnerability index

Browse CVEs

2,635 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
HIGH 7.8 CVE-2026-50308 Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-49800 Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 MEDIUM 6.6 CVE-2026-49804 Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-49793 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-49796 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-49797 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-49790 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-49184 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-49172 Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-49175 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-49178 Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-49164 Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 HIGH 8.8 CVE-2026-48564 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-42975 Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-42990 Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 MEDIUM 5.3 CVE-2026-15520 A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of t… Patch available Fix from $1,6002026-07-13 HIGH 7.8 CVE-2026-15506 A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.… Mitigation only Fix from $1,9502026-07-12 CRITICAL 9.1 CVE-2026-56372 ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory… Imagemagick 7.1.2-19+ Fix from $2,3002026-07-11 CRITICAL 9.8 CVE-2026-57156 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in upd… Freerdp 3.28.0+ Fix from $2,3002026-07-10 HIGH 7.0 CVE-2026-54000 osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged att… Patch available Fix from $1,9502026-07-10 HIGH 7.0 CVE-2026-54001 osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged att… Patch available Fix from $1,9502026-07-10 MEDIUM 5.3 CVE-2026-15182 A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP … Patch available Fix from $1,6002026-07-09 MEDIUM 6.1 CVE-2026-58306 Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525f337fafdd… Patch available Fix from $1,6002026-07-09 HIGH 8.8 CVE-2026-15123 Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a c… Chrome 150.0.7871.115+ Fix from $1,9502026-07-08 MEDIUM 5.5 CVE-2026-15173 pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service Wireshark 4.6.7+ Fix from $1,6002026-07-08 MEDIUM 5.5 CVE-2026-15174 Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Wireshark 4.4.17 / 4.6.7+ Fix from $1,6002026-07-08 MEDIUM 5.5 CVE-2026-15164 Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Wireshark 4.4.17 / 4.6.7+ Fix from $1,6002026-07-08 MEDIUM 5.5 CVE-2026-15165 TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service Wireshark 4.6.7+ Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-15169 UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Wireshark 4.4.17 / 4.6.7+ Fix from $1,9502026-07-08 MEDIUM 5.5 CVE-2026-15170 Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Wireshark 4.4.17 / 4.6.7+ Fix from $1,6002026-07-08