Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Imagemagick HIGH 8.1
CVE-2026-28693

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer o…

Fix: 6.9.13-41 / 7.1.2-16+
Fix from $1,950 2026-03-10
Commgr2 HIGH 7.5
CVE-2026-3631

Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.

Fix: 2.11.1+
Fix from $1,950 2026-03-09
Libssh HIGH 7.5
CVE-2026-3731

A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the …

Fix: after 0.11.3
Fix from $1,950 2026-03-08
Xlnt HIGH 7.1
CVE-2026-3663

A vulnerability was found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_document_istreambuf::xsgetn of t…

Fix: after 1.6.1
Fix from $1,950 2026-03-07
Xlnt MEDIUM 5.5
CVE-2026-3664

A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_document::read_directory of the fi…

Fix: after 1.6.1
Fix from $1,600 2026-03-07
Ettercap MEDIUM 5.5
CVE-2026-3606

A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/u…

No fix yet
Fix from $1,600 2026-03-05
Chrome HIGH 8.8
CVE-2026-3540

Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access vi…

Fix: 145.0.7632.159 / 145.0.7632.160+
Fix from $1,950 2026-03-04
Linux Kernel HIGH 7.1
CVE-2026-23235

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix out-of-bounds access in sysfs attribute read/write Some f2fs sysfs at…

Fix: 5.10.251 / 5.15.201+
Fix from $1,950 2026-03-04
Libbiosig HIGH 7.1
CVE-2025-64736

An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (5462afb0). A spe…

No fix yet
Fix from $1,950 2026-03-03
Exiv2 HIGH 7.5
CVE-2026-27596

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, …

Fix: 0.28.8+
Fix from $1,950 2026-03-02
Exiv2 HIGH 8.1
CVE-2026-25884

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, …

Fix: 0.28.8+
Fix from $1,950 2026-03-02
Android HIGH 8.4
CVE-2026-0035

In createRequest of MediaProvider.java, there is a possible way for an app to gain read/write access to non-existing files due to a logic error in th…

Mitigation only
Fix from $1,950 2026-03-02
Freetype MEDIUM 5.3
CVE-2026-23865

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bo…

Fix: after 2.14.1
Fix from $1,600 2026-03-02
Lily MEDIUM 5.5
CVE-2026-3391

A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The mani…

Fix: after 2.3
Fix from $1,600 2026-03-01
Lily MEDIUM 5.5
CVE-2026-3390

A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of …

Fix: after 2.3
Fix from $1,600 2026-03-01
Wren HIGH 7.1
CVE-2026-3386

A flaw has been found in wren-lang wren up to 0.4.0. Affected by this vulnerability is the function emitOp of the file src/vm/wren_compiler.c. This m…

Fix: after 0.4.0
Fix from $1,950 2026-03-01
Vim MEDIUM 5.5
CVE-2026-28418

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-sty…

Fix: 9.2.0074+
Fix from $1,600 2026-02-27
Vim MEDIUM 6.6
CVE-2026-28419

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsi…

Fix: 9.2.0075+
Fix from $1,600 2026-02-27
Pillow Heif CRITICAL 9.1
CVE-2026-28231

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path bu…

Fix: 1.3.0+
Fix from $2,300 2026-02-27
Ocaml HIGH 7.8
CVE-2026-28364

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a…

Fix: 4.14.3 / 5.4.1+
Fix from $1,950 2026-02-27
Berry HIGH 7.8
CVE-2026-3285

A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the file src/be_lexer.c. This man…

Patch available
Fix from $1,950 2026-02-27
Libvips HIGH 7.1
CVE-2026-3282

A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultipl…

Patch available
Fix from $1,950 2026-02-27
Libvips HIGH 7.1
CVE-2026-3283

A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. T…

Patch available
Fix from $1,950 2026-02-27
Unclassified HIGH 7.5
CVE-2026-27831

rldns is an open source DNS server. Version 1.3 has a heap-based out-of-bounds read that leads to denial of service. Version 1.4 contains a patch for…

Patch available
Fix from $1,950 2026-02-26
Imagemagick HIGH 7.1
CVE-2026-27798

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffe…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-02-26
Nanazip MEDIUM 6.6
CVE-2026-27709

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File A…

Fix: 6.0.1638.0+
Fix from $1,600 2026-02-26
Nanazip MEDIUM 6.6
CVE-2026-27711

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerabi…

Fix: 6.0.1638.0+
Fix from $1,600 2026-02-26
Freerdp HIGH 7.5
CVE-2026-25942

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result` indexes the global `error_c…

Fix: 3.23.0+
Fix from $1,950 2026-02-25
Freerdp HIGH 8.1
CVE-2026-25941

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 …

Fix: 2.11.8 / 3.23.0+
Fix from $1,950 2026-02-25
Iccdev HIGH 7.1
CVE-2026-27692

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-ove…

Fix: after 2.3.1.4
Fix from $1,950 2026-02-25