Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Windows 11 23h2 HIGH 7.8
CVE-2026-32076

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.6936 / 10.0.25398.2274+
Fix from $1,950 2026-04-14
Windows 10 21h2 MEDIUM 5.5
CVE-2026-27931

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

Fix: 10.0.19044.7184 / 10.0.19045.7184+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-27930

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-26156

Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1809 HIGH 7.8
CVE-2026-26153

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,950 2026-04-14
Indesign HIGH 7.8
CVE-2026-27284

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could resul…

Fix: 20.5.3 / 21.3+
Fix from $1,950 2026-04-14
Unclassified MEDIUM 5.3
CVE-2026-5713

The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree"…

Patch available
Fix from $1,600 2026-04-14
Jq MEDIUM 6.1
CVE-2026-39956

jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes …

Fix: 2026-04-08+
Fix from $1,600 2026-04-13
Jq MEDIUM 6.5
CVE-2026-39979

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted …

Fix: 2026-04-12+
Fix from $1,600 2026-04-13
Imagemagick HIGH 7.1
CVE-2026-33905

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sa…

Fix: 6.9.13-44 / 7.1.2-19+
Fix from $1,950 2026-04-13
Nimiq Proof Of Stake HIGH 7.5
CVE-2026-32605

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.…

Fix: 1.3.0+
Fix from $1,950 2026-04-13
Ffmpeg HIGH 7.5
CVE-2026-30997

An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) …

Fix: after 8.0.1
Fix from $1,950 2026-04-13
Escargot CRITICAL 9.1
CVE-2026-25206

Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a…

Patch available
Fix from $2,300 2026-04-13
Escargot CRITICAL 9.1
CVE-2026-25209

Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a…

Patch available
Fix from $2,300 2026-04-13
Linux Kernel HIGH 7.8
CVE-2026-31413

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR maybe_fork_s…

Fix: 6.12.80 / 6.18.21+
Fix from $1,950 2026-04-12
Wolfssl MEDIUM 5.4
CVE-2026-5392

Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bounds check is in the indefinite-…

Fix: 5.9.1+
Fix from $1,600 2026-04-10
Wolfssl CRITICAL 9.1
CVE-2026-5393

Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on c…

Fix: 5.9.1+
Fix from $2,300 2026-04-10
Wasmtime CRITICAL 9.9
CVE-2026-34987

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler back…

Fix: 36.0.7 / 42.0.2+
Fix from $2,300 2026-04-09
Wasmtime HIGH 7.8
CVE-2026-34971

Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on a…

Fix: 36.0.7 / 42.0.2+
Fix from $1,950 2026-04-09
Wasmtime HIGH 8.1
CVE-2026-34941

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16…

Fix: 24.0.7 / 36.0.7+
Fix from $1,950 2026-04-09
Osslsigncode MEDIUM 5.5
CVE-2026-39855

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncod…

Fix: 2.13+
Fix from $1,600 2026-04-09
Osslsigncode MEDIUM 5.5
CVE-2026-39856

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsignco…

Fix: 2.13+
Fix from $1,600 2026-04-09
Orthanc HIGH 7.1
CVE-2026-5441

An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, whic…

Fix: 1.12.11+
Fix from $1,950 2026-04-09
Orthanc CRITICAL 9.1
CVE-2026-5445

An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used f…

Fix: 1.12.11+
Fix from $2,300 2026-04-09
Orthanc HIGH 7.5
CVE-2026-5437

An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, th…

Fix: 1.12.11+
Fix from $1,950 2026-04-09
Chrome HIGH 8.1
CVE-2026-5913

Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted H…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome HIGH 8.1
CVE-2026-5907

Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome MEDIUM 5.3
CVE-2026-5886

Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 147.0.7727.55+
Fix from $1,600 2026-04-08
Chrome HIGH 8.8
CVE-2026-5873

Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
The Sleuth Kit MEDIUM 6.1
CVE-2026-40025

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class fo…

Fix: 4.15.0+
Fix from $1,600 2026-04-08