Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Thrift HIGH 8.2
CVE-2026-41604

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.2…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Thrift MEDIUM 6.5
CVE-2026-41607

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.2…

Fix: 0.23.0+
Fix from $1,600 2026-04-28
Mupdf MEDIUM 6.1
CVE-2026-7233

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of…

Fix: after 1.27.2
Fix from $1,600 2026-04-28
Unclassified MEDIUM 5.3
CVE-2026-7135

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of…

Patch available
Fix from $1,600 2026-04-27
Firefox HIGH 7.5
CVE-2026-6785

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showe…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-26
Firefox HIGH 7.5
CVE-2026-6786

Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-26
Linux Kernel HIGH 7.8
CVE-2026-31675

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-bounds access in packet corruption In netem_en…

Fix: 6.6.134 / 6.12.81+
Fix from $1,950 2026-04-25
Bacnet Stack CRITICAL 9.1
CVE-2026-41475

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-sta…

Fix: 1.4.3+
Fix from $2,300 2026-04-24
Bacnet Stack HIGH 7.5
CVE-2026-41502

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of-bounds read vulnerability in…

Fix: 1.4.3+
Fix from $1,950 2026-04-24
Bacnet Stack HIGH 7.5
CVE-2026-41503

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-sta…

Fix: 1.4.3+
Fix from $1,950 2026-04-24
Pjsip CRITICAL 9.1
CVE-2026-41415

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a mal…

Fix: 2.17+
Fix from $2,300 2026-04-24
Rust Openssl CRITICAL 9.1
CVE-2026-41677

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validat…

Fix: 0.10.78+
Fix from $2,300 2026-04-24
Cups MEDIUM 5.4
CVE-2026-41079

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can…

Fix: 2.4.17+
Fix from $1,600 2026-04-24
Linux Kernel HIGH 7.8
CVE-2026-31641

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrpc_preparse_xdr_yfs_rxgk() rea…

Fix: 6.18.23 / 6.19.13+
Fix from $1,950 2026-04-24
Linux Kernel CRITICAL 9.1
CVE-2026-31636

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() c…

Fix: 6.18.23 / 6.19.13+
Fix from $2,300 2026-04-24
Linux Kernel HIGH 8.1
CVE-2026-31613

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB reads parsing symlink error response When a CREATE returns…

Fix: 6.18.24 / 6.19.14+
Fix from $1,950 2026-04-24
Linux Kernel HIGH 7.1
CVE-2026-31614

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix off-by-8 bounds check in check_wsl_eas() The bounds check uses…

Fix: 6.6.136 / 6.12.83+
Fix from $1,950 2026-04-24
Linux Kernel HIGH 7.1
CVE-2026-31568

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Add missing secure storage access fixups for donated memory There are …

Fix: 6.18.21 / 6.19.11+
Fix from $1,950 2026-04-24
Linux Kernel HIGH 7.3
CVE-2026-31569

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Handle the case that EIOINTC's coremap is empty EIOINTC's corem…

Fix: 6.18.21 / 6.19.11+
Fix from $1,950 2026-04-24
Linux Kernel HIGH 8.8
CVE-2026-31570

In the Linux kernel, the following vulnerability has been resolved: can: gw: fix OOB heap access in cgw_csum_crc8_rel() cgw_csum_crc8_rel() correct…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-24
Linux Kernel HIGH 8.8
CVE-2026-31558

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid(…

Fix: 6.12.80 / 6.18.21+
Fix from $1,950 2026-04-24
Op Tee HIGH 8.7
CVE-2026-33317

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,950 2026-04-24
Swupdate MEDIUM 6.8
CVE-2026-28525

SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows unauthenticated attackers to …

Fix: after 2025.12
Fix from $1,600 2026-04-23
Chrome CRITICAL 9.6
CVE-2026-6920

Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to p…

Fix: 147.0.7727.116+
Fix from $2,300 2026-04-23
Unclassified HIGH 7.8
CVE-2026-34003

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, l…

Mitigation only
Fix from $1,950 2026-04-23
Dnsdist CRITICAL 9.1
CVE-2026-33598

A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet c…

Fix: 1.9.13 / 2.0.4+
Fix from $2,300 2026-04-22
Dnsdist HIGH 8.1
CVE-2026-33599

A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) opti…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Linux Kernel HIGH 7.8
CVE-2026-31528

In the Linux kernel, the following vulnerability has been resolved: perf: Make sure to use pmu_ctx->pmu for groups Oliver reported that x86_pmu_del…

Fix: 6.6.131 / 6.12.80+
Fix from $1,950 2026-04-22
Linux Kernel HIGH 8.1
CVE-2026-31513

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req Syzbot r…

Fix: 6.12.80 / 6.18.21+
Fix from $1,950 2026-04-22
Linux Kernel HIGH 7.1
CVE-2026-31484

In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: fix OOB read in SQE_MIXED wrap check __io_uring_show_fdinfo() …

Fix: 6.19.11+
Fix from $1,950 2026-04-22