Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Windows 11 26h1 HIGH 7.8
CVE-2026-44808

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.28000.2269+
Fix from $1,950 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42968

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.3
CVE-2026-42914

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows App HIGH 7.5
CVE-2026-42908

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

Fix: 2.0.1193.0 / 10.0.14393.9234+
Fix from $1,950 2026-06-09
Windows 10 1809 HIGH 7.8
CVE-2026-42837

Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
OpenSSL MEDIUM 6.2
CVE-2026-42771

Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message …

Patch available
Fix from $1,600 2026-06-09
OpenSSL HIGH 7.5
CVE-2026-34180

Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap bu…

Fix: 1.0.2zq / 1.1.1zh+
Fix from $1,950 2026-06-09
Directory Server MEDIUM 6.5
CVE-2026-11786

A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolon…

Mitigation only
Fix from $1,600 2026-06-09
Chrome HIGH 7.5
CVE-2026-11690

Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer proc…

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Chrome HIGH 7.5
CVE-2026-11667

Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the GPU process to potentially ex…

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Chrome HIGH 8.8
CVE-2026-11645 KEV

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Openvpn HIGH 7.4
CVE-2026-40215

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak hea…

Fix: 2.6.20 / 2.7.2+
Fix from $1,950 2026-06-08
Linux Kernel HIGH 8.3
CVE-2026-46307

In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access array OOB Vincent reports: > The ath5k driver seems …

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-06-08
Linux Kernel HIGH 7.1
CVE-2026-46293

In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds access during output registration U…

Fix: 6.1.175 / 6.6.140+
Fix from $1,950 2026-06-08
HTTP Server MEDIUM 6.5
CVE-2026-43951

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP…

Fix: after 2.4.67
Fix from $1,600 2026-06-08
HTTP Server HIGH 7.3
CVE-2026-44185

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP…

Fix: 2.4.68+
Fix from $1,950 2026-06-08
7 Zip MEDIUM 6.5
CVE-2026-48112

7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF …

Fix: 26.01+
Fix from $1,600 2026-06-05
7 Zip HIGH 7.1
CVE-2026-48103

7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bounds read in the WIM (Windows…

Fix: 26.01+
Fix from $1,950 2026-06-05
7 Zip HIGH 7.1
CVE-2026-48111

7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an off-by-one out-of-bounds read vulnerability in the Par…

Fix: 26.01+
Fix from $1,950 2026-06-05
7 Zip HIGH 8.1
CVE-2026-48092

7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain a heap memory disclosure via SquashFS fragment offset int…

Fix: 26.01+
Fix from $1,950 2026-06-05
Enterprise Linux MEDIUM 5.5
CVE-2026-50262

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can re…

Fix: 21.1.23 / 24.1.12+
Fix from $1,600 2026-06-05
Android Usb Driver MEDIUM 5.5
CVE-2026-21038

Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.

Fix: 1.9.5.0+
Fix from $1,600 2026-06-05
Chrome MEDIUM 6.5
CVE-2026-11299

Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-05
Chrome HIGH 8.8
CVE-2026-11301

Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds me…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-05
Chrome HIGH 8.8
CVE-2026-11279

Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a cra…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-05
Chrome HIGH 8.3
CVE-2026-11256

Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-05
Chrome HIGH 8.8
CVE-2026-11191

Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory ac…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11183

Out of bounds read in GWP-ASan in Google Chrome prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from proc…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11160

Out of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information fr…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome HIGH 8.1
CVE-2026-11111

Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted H…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04