Vulnerability index

Browse CVEs

8,423 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Linux Kernel HIGH 8.1
CVE-2026-53390

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() The permission-check ACE…

Fix: 5.15.212 / 6.6.144+
Fix from $1,950 2026-07-19
Unclassified MEDIUM 5.3
CVE-2026-16013

A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPat…

No fix yet
Fix from $1,600 2026-07-17
H2o MEDIUM 5.9
CVE-2026-44452

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC…

Fix: 2026-05-29+
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.1
CVE-2026-57075

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in t…

Mitigation only
Fix from $2,300 2026-07-16
Unclassified HIGH 7.7
CVE-2026-57077

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_le…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-57896

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCT…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.9
CVE-2026-60073

An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead to a s…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-60140

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCT…

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.1
CVE-2026-57073

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter str…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.1
CVE-2026-57074

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter stri…

Mitigation only
Fix from $2,300 2026-07-16
Squid MEDIUM 6.5
CVE-2026-47729

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/F…

Fix: 7.6+
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.5
CVE-2026-45612

rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds rea…

No fix yet
Fix from $1,600 2026-07-16
Busybox MEDIUM 5.1
CVE-2026-38754

A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a cra…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 5.4
CVE-2026-62353

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() inc…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 7.5
CVE-2026-62351

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompress…

Mitigation only
Fix from $1,950 2026-07-15
Zephyr HIGH 8.8
CVE-2026-10673

The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ethernet frames in OPEN Alliance (…

Mitigation only
Fix from $1,950 2026-07-15
Nginx Gateway Fabric MEDIUM 5.3
CVE-2026-60065

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated at…

Fix: 2.6.7 / 5.5.3+
Fix from $1,600 2026-07-15
Unclassified MEDIUM 5.6
CVE-2026-15030

Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read…

Mitigation only
Fix from $1,600 2026-07-15
Media Encoder MEDIUM 5.5
CVE-2026-47979

Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this v…

Fix: after 26.2.2
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.5
CVE-2026-15714

An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_he…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 5.9
CVE-2026-15712

A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the lib…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 8.6
CVE-2026-15720

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wid…

Mitigation only
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-58539

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.8
CVE-2026-58528

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

Mitigation only
Fix from $1,600 2026-07-14
Windows 11 26h1 HIGH 7.1
CVE-2026-58529

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

Fix: 10.0.28000.2525+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.8
CVE-2026-57094

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Unclassified MEDIUM 5.5
CVE-2026-57085

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

Mitigation only
Fix from $1,600 2026-07-14
365 Apps MEDIUM 5.5
CVE-2026-56192

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
365 Apps MEDIUM 5.5
CVE-2026-56195

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 6.5
CVE-2026-56186

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14