Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Unclassified HIGH 8.3
CVE-2026-20751

Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.7
CVE-2026-43916

pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior to 0.2.0-alpha, a heap buffe…

Patch available
Fix from $1,950 2026-05-12
Barebox HIGH 7.7
CVE-2026-34961

barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries fie…

Fix: 2026.04.0+
Fix from $1,950 2026-05-11
Barebox MEDIUM 6.5
CVE-2026-34960

barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that f…

Fix: 2026.04.0+
Fix from $1,600 2026-05-11
Ipados HIGH 7.3
CVE-2026-43655

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watc…

Fix: 26.5+
Fix from $1,950 2026-05-11
Ipados HIGH 7.5
CVE-2026-28991

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visi…

Fix: 26.5+
Fix from $1,950 2026-05-11
Ipados MEDIUM 6.5
CVE-2026-28956

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS …

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Ipados MEDIUM 6.5
CVE-2026-28918

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26…

Fix: 26.5+
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.3
CVE-2026-4891EPSS 6%

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted …

Patch available
Fix from $1,600 2026-05-11
Unclassified HIGH 7.3
CVE-2026-5172

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malform…

Patch available
Fix from $1,950 2026-05-11
Unclassified HIGH 7.5
CVE-2026-8177

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A…

Patch available
Fix from $1,950 2026-05-10
PHP CRITICAL 9.1
CVE-2026-6104

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() …

Fix: 8.4.21 / 8.5.6+
Fix from $2,300 2026-05-10
PHP HIGH 7.5
CVE-2026-7258

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass si…

Fix: 8.2.21 / 8.3.31+
Fix from $1,950 2026-05-10
PHP HIGH 7.5
CVE-2026-7568

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metap…

Fix: 8.2.31 / 8.3.31+
Fix from $1,950 2026-05-10
Gdal MEDIUM 5.5
CVE-2026-8212

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWap…

Fix: after 3.12.4
Fix from $1,600 2026-05-09
Gdal MEDIUM 5.5
CVE-2026-8213

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDa…

Fix: after 3.12.4
Fix from $1,600 2026-05-09
Open5gs HIGH 7.5
CVE-2026-8186

A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in the library lib/sbi/client.c of…

Fix: after 2.7.7
Fix from $1,950 2026-05-09
Linux Kernel HIGH 7.1
CVE-2026-43453

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() pipapo…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-05-08
Linux Kernel HIGH 7.1
CVE-2026-43449

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set dev->online_queues is a coun…

Fix: 4.15 / 4.20+
Fix from $1,950 2026-05-08
Linux Kernel HIGH 7.1
CVE-2026-43450

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() nfnl_…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-05-08
Linux Kernel HIGH 7.1
CVE-2026-43427

In the Linux kernel, the following vulnerability has been resolved: usb: class: cdc-wdm: fix reordering issue in read code path Quoting the bug rep…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-05-08
Linux Kernel CRITICAL 9.1
CVE-2026-43406

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If t…

Fix: 5.15.203 / 6.1.167+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.1
CVE-2026-43407

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This pa…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-05-08
Linux Kernel HIGH 7.1
CVE-2026-43380

In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read The q54sj108a2_deb…

Fix: 5.15.203 / 6.1.167+
Fix from $1,950 2026-05-08
Linux Kernel HIGH 7.1
CVE-2026-43386

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie The…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-05-08
Unclassified MEDIUM 6.8
CVE-2026-3508

An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read…

Mitigation only
Fix from $1,600 2026-05-08
Gdal MEDIUM 5.5
CVE-2026-8088

A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi…

Fix: after 3.12.4
Fix from $1,600 2026-05-07
Gdal MEDIUM 5.5
CVE-2026-8084

A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.…

Fix: after 3.12.4
Fix from $1,600 2026-05-07
Firefox HIGH 8.1
CVE-2026-8092

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption…

Fix: 115.35.2 / 140.10.2+
Fix from $1,950 2026-05-07
Openexr CRITICAL 9.1
CVE-2026-42216

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From…

Fix: 3.2.9 / 3.3.11+
Fix from $2,300 2026-05-07