Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Linux Kernel HIGH 8.1
CVE-2026-31464

In the Linux kernel, the following vulnerability has been resolved: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() A malicious or c…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-22
Linux Kernel HIGH 7.8
CVE-2026-31449

In the Linux kernel, the following vulnerability has been resolved: ext4: validate p_idx bounds in ext4_ext_correct_indexes ext4_ext_correct_indexe…

Fix: 6.12.80 / 6.18.21+
Fix from $1,950 2026-04-22
Linux Kernel HIGH 7.8
CVE-2026-31442

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix possible invalid memory access after FLR In the case that …

Fix: 6.18.21 / 6.19.11+
Fix from $1,950 2026-04-22
Linux Kernel HIGH 8.8
CVE-2026-31435

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under certain circumstances, all the r…

Fix: 6.18.21 / 6.19.11+
Fix from $1,950 2026-04-22
Linux Kernel HIGH 8.8
CVE-2026-31433

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for compound requests When a co…

Fix: 5.15.203 / 6.1.168+
Fix from $1,950 2026-04-22
Markdown HIGH 7.5
CVE-2026-40890

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing…

Fix: 2026-04-10+
Fix from $1,950 2026-04-21
Unclassified HIGH 8.2
CVE-2026-24189

NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously c…

Mitigation only
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6784

Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 150.0+
Fix from $1,950 2026-04-21
Linux Kernel HIGH 7.1
CVE-2026-31430

In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access when parsing extensions Leo reports an out-of-b…

Fix: 6.6.135 / 6.12.82+
Fix from $1,950 2026-04-20
Unclassified MEDIUM 6.1
CVE-2026-40340

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulnerability in `ptp_unpack_OI()` …

Patch available
Fix from $1,600 2026-04-18
Unclassified MEDIUM 6.1
CVE-2026-40333

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data poi…

Patch available
Fix from $1,600 2026-04-18
Unclassified MEDIUM 5.2
CVE-2026-40335

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/p…

Patch available
Fix from $1,600 2026-04-18
Unclassified MEDIUM 5.2
CVE-2026-40338

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of…

Patch available
Fix from $1,600 2026-04-18
Unclassified MEDIUM 5.2
CVE-2026-40339

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `caml…

Patch available
Fix from $1,600 2026-04-18
Miniupnpd CRITICAL 9.1
CVE-2026-5720

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or infor…

Fix: 2.3.10+
Fix from $2,300 2026-04-17
Libcoap CRITICAL 9.8
CVE-2026-29013

libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c reli…

Fix: 4.3.5b+
Fix from $2,300 2026-04-17
Xrdp CRITICAL 9.1
CVE-2026-33689

xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing log…

Fix: 0.10.6+
Fix from $2,300 2026-04-17
Xrdp CRITICAL 9.1
CVE-2026-33516

xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The …

Fix: 0.10.6+
Fix from $2,300 2026-04-17
Opencryptoki MEDIUM 6.1
CVE-2026-40253

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared …

Fix: after 3.26.0
Fix from $1,600 2026-04-16
Unclassified MEDIUM 5.0
CVE-2026-41034

ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vector…

Mitigation only
Fix from $1,600 2026-04-16
Chrome MEDIUM 6.5
CVE-2026-6364

Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 147.0.7727.101+
Fix from $1,600 2026-04-15
Chrome HIGH 7.5
CVE-2026-6308

Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Enterprise Linux HIGH 7.1
CVE-2026-40917

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS i…

Mitigation only
Fix from $1,950 2026-04-15
Framemaker HIGH 7.8
CVE-2026-27294

Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a…

Fix: 2022.9+
Fix from $1,950 2026-04-14
Libsixel HIGH 7.1
CVE-2026-33019

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out…

Fix: 1.8.7-r1+
Fix from $1,950 2026-04-14
Incopy HIGH 7.8
CVE-2026-27287

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a rea…

Fix: 20.5.3 / 21.3+
Fix from $1,950 2026-04-14
Photoshop HIGH 7.8
CVE-2026-27289

Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a …

Fix: 27.5+
Fix from $1,950 2026-04-14
365 Apps MEDIUM 6.1
CVE-2026-33822

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,600 2026-04-14
Windows 11 23h2 HIGH 7.5
CVE-2026-33096

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

Fix: 10.0.20348.5020 / 10.0.22631.6936+
Fix from $1,950 2026-04-14
365 Apps HIGH 7.1
CVE-2026-32188

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,950 2026-04-14