Vulnerability index

Browse CVEs

8,452 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Nr15 MEDIUM 6.5
CVE-2026-20421

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a …

Mitigation only
Fix from $1,600 2026-02-02
Monkey HIGH 7.5
CVE-2025-63656

An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service …

Fix: after 1.8.5
Fix from $1,950 2026-01-29
Monkey HIGH 7.5
CVE-2025-63657

An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Servi…

Fix: after 1.8.5
Fix from $1,950 2026-01-29
Monkey HIGH 7.5
CVE-2025-63649

An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to…

Fix: after 1.8.5
Fix from $1,950 2026-01-29
Monkey HIGH 7.5
CVE-2025-63650

An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (…

Fix: after 1.8.5
Fix from $1,950 2026-01-29
Monkey HIGH 7.5
CVE-2025-63653

An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Servic…

Fix: after 1.8.5
Fix from $1,950 2026-01-29
Digital Employee Experience HIGH 8.1
CVE-2026-23568

An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26…

Fix: 26.1+
Fix from $1,950 2026-01-29
Digital Employee Experience HIGH 7.5
CVE-2026-23569

An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26…

Fix: 26.1+
Fix from $1,950 2026-01-29
Oneflow MEDIUM 6.5
CVE-2025-71004

A segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted inpu…

No fix yet
Fix from $1,600 2026-01-28
Oneflow MEDIUM 6.5
CVE-2025-71001

A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

No fix yet
Fix from $1,600 2026-01-28
Keynote MEDIUM 5.5
CVE-2025-46306

The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciou…

Fix: 15.1 / 26.0+
Fix from $1,600 2026-01-28
Iccdev HIGH 8.1
CVE-2026-24852

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-28
Wasmtime MEDIUM 5.5
CVE-2026-24116

Wasmtime is a runtime for WebAssembly. Starting in version 29.0.0 and prior to version 36.0.5, 40.0.3, and 41.0.1, on x86-64 platforms with AVX, Wasm…

Fix: 36.0.5 / 40.0.3+
Fix from $1,600 2026-01-27
Unclassified HIGH 7.8
CVE-2026-24873

Out-of-bounds Read vulnerability in Rinnegatamante lpp-vita.This issue affects lpp-vita: before lpp-vita r6.

Patch available
Fix from $1,950 2026-01-27
Unclassified MEDIUM 5.3
CVE-2025-41728

A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafte…

Mitigation only
Fix from $1,600 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24826

Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability i…

Patch available
Fix from $2,300 2026-01-27
Unclassified MEDIUM 6.9
CVE-2026-24818

Out-of-bounds Read vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with program files lparser.C. This…

Patch available
Fix from $1,600 2026-01-27
Unclassified MEDIUM 5.1
CVE-2026-24820

Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files ldebug.C.…

Patch available
Fix from $1,600 2026-01-27
Unclassified CRITICAL 9.3
CVE-2026-24821

Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files lparser.C…

Patch available
Fix from $2,300 2026-01-27
Root CRITICAL 9.8
CVE-2026-24811

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root.

Fix: after 6.34.08
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.3
CVE-2026-24812

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inftrees.C. This issue affects root:…

Patch available
Fix from $2,300 2026-01-27
Unclassified MEDIUM 6.9
CVE-2026-24796

Out-of-bounds Read vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Oniguruma modules). This vulnerabi…

Patch available
Fix from $1,600 2026-01-27
Linux Kernel HIGH 7.1
CVE-2026-22984

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in handle_auth_done() Perform an…

Fix: 5.15.198 / 6.1.161+
Fix from $1,950 2026-01-23
Sumatrapdf MEDIUM 5.5
CVE-2026-23951

SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that only triggers with exactly 2 re…

No fix yet
Fix from $1,600 2026-01-22
Chrome HIGH 8.8
CVE-2026-0899

Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a cr…

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $1,950 2026-01-20
Gpac HIGH 7.5
CVE-2025-70308

An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.

No fix yet
Fix from $1,950 2026-01-15
Gpac HIGH 8.2
CVE-2025-70298

GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.

No fix yet
Fix from $1,950 2026-01-15
Freerdp CRITICAL 9.1
CVE-2026-22855

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path wh…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.1
CVE-2026-22858

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding pa…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.1
CVE-2026-22859

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑suppli…

Fix: 3.20.1+
Fix from $2,300 2026-01-14