Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Unclassified HIGH 7.1
CVE-2026-44064

An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or c…

Mitigation only
Fix from $1,950 2026-05-21
Unclassified HIGH 7.1
CVE-2026-44066

Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to ob…

Mitigation only
Fix from $1,950 2026-05-21
Chrome HIGH 8.8
CVE-2026-9121

Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 148.0.7778.178+
Fix from $1,950 2026-05-20
Chrome MEDIUM 6.5
CVE-2026-9122

Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from …

Fix: 148.0.7778.179+
Fix from $1,600 2026-05-20
Bind HIGH 7.5
CVE-2026-5946

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `…

Fix: 9.18.49 / 9.20.23+
Fix from $1,950 2026-05-20
Unbound MEDIUM 5.3
CVE-2026-32792

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnsc…

Fix: 1.25.1+
Fix from $1,600 2026-05-20
Triton Inference Server CRITICAL 9.8
CVE-2026-24213

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit…

Fix: 26.03+
Fix from $2,300 2026-05-20
Rsync HIGH 8.1
CVE-2026-43618

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked …

Fix: after 3.4.2
Fix from $1,950 2026-05-20
Rsync MEDIUM 5.5
CVE-2026-43620

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rs…

Fix: after 3.4.2
Fix from $1,600 2026-05-20
Unclassified HIGH 7.1
CVE-2026-32882

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in…

Mitigation only
Fix from $1,950 2026-05-19
Kitty CRITICAL 9.8
CVE-2026-33642

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds…

Fix: 0.47.0+
Fix from $2,300 2026-05-19
Libheif MEDIUM 6.5
CVE-2026-32738

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chun…

Fix: 1.22.0+
Fix from $1,600 2026-05-19
Unclassified MEDIUM 6.2
CVE-2026-38719

OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFor…

Mitigation only
Fix from $1,600 2026-05-18
Coremqtt CRITICAL 9.1
CVE-2026-8686

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a c…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified MEDIUM 5.8
CVE-2025-29937

An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location po…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified MEDIUM 6.9
CVE-2025-48520

An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds…

Mitigation only
Fix from $1,600 2026-05-15
Chrome MEDIUM 5.3
CVE-2026-8543

Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Chrome MEDIUM 5.3
CVE-2026-8546

Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer proc…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Chrome MEDIUM 5.3
CVE-2026-8535

Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Chrome MEDIUM 5.3
CVE-2026-8541

Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potent…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Openimageio HIGH 8.8
CVE-2026-43909

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…

Fix: 3.0.18.0 / 3.1.13.0+
Fix from $1,950 2026-05-14
Openimageio MEDIUM 5.5
CVE-2026-43996

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…

Fix: 3.0.18.0 / 3.1.13.0+
Fix from $1,600 2026-05-14
Argon HIGH 7.8
CVE-2025-65087

An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that…

Fix: after 12.6.1204.216
Fix from $1,950 2026-05-12
Argon HIGH 7.8
CVE-2025-65088

An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that…

Fix: after 12.6.1204.216
Fix from $1,950 2026-05-12
Nanazip HIGH 7.1
CVE-2026-42446

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image …

Fix: 6.0.1698.0+
Fix from $1,950 2026-05-12
Windows 10 1607 MEDIUM 6.2
CVE-2026-40380

Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,600 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40360

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Fix: 16.0.10417.20128+
Fix from $1,950 2026-05-12
Windows 10 1607 MEDIUM 5.4
CVE-2026-35423

Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,600 2026-05-12
Windows 11 24h2 MEDIUM 5.5
CVE-2026-35419

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Fix: 10.0.26100.8390 / 10.0.26100.32772+
Fix from $1,600 2026-05-12
Illustrator MEDIUM 5.5
CVE-2026-34663

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Fix: 29.8.7 / 30.4+
Fix from $1,600 2026-05-12