Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Linux Kernel HIGH 7.8
CVE-2026-23406

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix side-effect bug in match_char() macro usage The match_char() macr…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-01
Linux Kernel HIGH 7.8
CVE-2026-23407

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix missing bounds check on DEFAULT table in verify_dfa() The verify_…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-01
Chrome HIGH 8.8
CVE-2026-5292

Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a craf…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome HIGH 8.1
CVE-2026-5282

Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a craf…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Connext Professional MEDIUM 6.5
CVE-2026-2394

Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4…

Fix: 7.3.1.1 / 7.7.0+
Fix from $1,600 2026-04-01
Iccdev MEDIUM 5.5
CVE-2026-34554

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a heap-buffer-overflow (HBO) i…

Fix: 2.3.1.6+
Fix from $1,600 2026-03-31
Iccdev MEDIUM 5.5
CVE-2026-34556

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a heap-buffer-overflo…

Fix: 2.3.1.6+
Fix from $1,600 2026-03-31
Pjsip CRITICAL 9.1
CVE-2026-34235

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists …

Fix: 2.17+
Fix from $2,300 2026-03-31
Freerdp HIGH 8.1
CVE-2026-33982

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 by…

Fix: 3.24.2+
Fix from $1,950 2026-03-30
Freerdp HIGH 7.1
CVE-2026-33985

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen,…

Fix: 3.24.2+
Fix from $1,950 2026-03-30
Botan HIGH 8.2
CVE-2026-32877

Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication cod…

Fix: 3.11.0+
Fix from $1,950 2026-03-30
Nanomq HIGH 7.5
CVE-2026-25627

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed …

Fix: 0.24.8+
Fix from $1,950 2026-03-30
Opensc MEDIUM 6.8
CVE-2025-66037

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes O…

Fix: 0.27.0+
Fix from $1,600 2026-03-30
Btstack HIGH 7.3
CVE-2026-28527

BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAYER_APPLICATION_SETTING_ATTRIB…

Fix: 1.8.1+
Fix from $1,950 2026-03-30
Btstack MEDIUM 5.7
CVE-2026-28526

BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_ATTRI…

Fix: 1.8.1+
Fix from $1,600 2026-03-30
Grafana HIGH 7.5
CVE-2026-27880

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

Fix: 12.1.0 / 12.2.0+
Fix from $1,950 2026-03-27
Siyuan HIGH 7.5
CVE-2026-33669

SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then t…

Fix: 3.6.2+
Fix from $1,950 2026-03-26
Tl Wr841n Firmware HIGH 7.5
CVE-2026-3622

The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing …

Fix: 0.9.1_4.19+
Fix from $1,950 2026-03-26
Msgpack HIGH 7.5
CVE-2026-32284

The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead …

Fix: after 3.1.2
Fix from $1,950 2026-03-26
Libpng HIGH 7.6
CVE-2026-33636

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versio…

Fix: 1.6.56+
Fix from $1,950 2026-03-26
Everest HIGH 7.5
CVE-2026-26008

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/…

Fix: 2026.02.0+
Fix from $1,950 2026-03-26
Linux Kernel HIGH 7.1
CVE-2026-23397

In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths in fingerprints nfnl_osf_add_…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-03-26
Squid MEDIUM 6.5
CVE-2026-33515

Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling…

Fix: 7.5+
Fix from $1,600 2026-03-26
Linux Kernel HIGH 7.1
CVE-2026-23388

In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within range Syzkaller reports a "gene…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-03-25
Linux Kernel HIGH 7.1
CVE-2026-23363

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211() Ch…

Fix: 6.12.77 / 6.18.17+
Fix from $1,950 2026-03-25
Linux Kernel HIGH 7.1
CVE-2026-23325

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() Ch…

Fix: 6.6.130 / 6.12.77+
Fix from $1,950 2026-03-25
Linux Kernel HIGH 7.1
CVE-2026-23327

In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_us…

Fix: 6.19.7+
Fix from $1,950 2026-03-25
Linux Kernel HIGH 7.1
CVE-2026-23318

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of th…

Fix: 4.20 / 5.4+
Fix from $1,950 2026-03-25
Linux Kernel HIGH 7.1
CVE-2026-23315

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() Chec…

Fix: 6.1.167 / 6.6.130+
Fix from $1,950 2026-03-25
Linux Kernel HIGH 7.1
CVE-2026-23305

In the Linux kernel, the following vulnerability has been resolved: accel/rocket: fix unwinding in error path in rocket_probe When rocket_core_init…

Fix: 6.18.17 / 6.19.7+
Fix from $1,950 2026-03-25