Vulnerability index

Browse CVEs

2,652 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
MEDIUM 6.7 CVE-2026-20876 Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.22631.6491 / 10.0.25398.2092+ Fix from $1,6002026-01-13 HIGH 8.8 CVE-2026-20868 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20864 Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20840 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20837 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20820 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20809 Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2025-25249 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiO… Fortios 6.4.17 / 7.0.6+ Fix from $2,3002026-01-13 HIGH 8.8 CVE-2026-0822 A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The man… Quickjs after 0.11.0 Fix from $1,9502026-01-10 CRITICAL 9.8 CVE-2026-0821 A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file qui… Quickjs after 0.11.0 Fix from $2,3002026-01-10 HIGH 7.5 CVE-2026-22697 CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication… Cryptolib 1.4.3+ Fix from $1,9502026-01-10 MEDIUM 6.0 CVE-2026-22027 CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communication… Cryptolib 1.4.3+ Fix from $1,6002026-01-10 HIGH 8.8 CVE-2026-21682 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) co… Iccdev 2.3.1.2+ Fix from $1,9502026-01-07 HIGH 7.8 CVE-2026-21678 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to… Iccdev 2.3.1.2+ Fix from $1,9502026-01-07 HIGH 7.8 CVE-2026-21504 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to… Iccdev 2.3.1.2+ Fix from $1,9502026-01-07 HIGH 7.1 CVE-2026-21494 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) co… Iccdev 2.3.1.2+ Fix from $1,9502026-01-06 HIGH 7.1 CVE-2026-21490 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) co… Iccdev 2.3.1.2+ Fix from $1,9502026-01-06 HIGH 7.1 CVE-2026-21491 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) co… Iccdev 2.3.1.2+ Fix from $1,9502026-01-06 HIGH 7.1 CVE-2026-21488 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-boun… Iccdev 2.3.1.2+ Fix from $1,9502026-01-06 HIGH 8.8 CVE-2026-21676 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have a Heap-based Buffer Overfl… Iccdev 2.3.1.1+ Fix from $1,9502026-01-06 HIGH 7.8 CVE-2026-21486 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below contain Use After Free, Heap-… Iccdev 2.3.1.2+ Fix from $1,9502026-01-06 CRITICAL 9.8 CVE-2025-67268 gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, wh… Gpsd 3.27.1+ Fix from $2,3002026-01-02 HIGH 7.8 CVE-2025-15277 FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu… Fontforge Mitigation only Fix from $1,9502025-12-31 HIGH 7.8 CVE-2025-15279 FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu… Fontforge Mitigation only Fix from $1,9502025-12-31 HIGH 8.8 CVE-2025-15272 FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Fontforge Mitigation only Fix from $1,9502025-12-31 HIGH 8.8 CVE-2025-15274 FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Fontforge Mitigation only Fix from $1,9502025-12-31 HIGH 8.8 CVE-2025-15275 FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Fontforge Mitigation only Fix from $1,9502025-12-31 CRITICAL 9.8 CVE-2025-50343 An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the … Matio Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-15247 A vulnerability was identified in gmg137 snap7-rs up to 153d3e8c16decd7271e2a5b2e3da4d6f68589424. Affected by this issue is the function snap7_rs::cl… Snap7 Rs Mitigation only Fix from $2,3002025-12-30 HIGH 8.8 CVE-2025-15234 A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanIn… M3 Firmware No fix yet Fix from $1,9502025-12-30