Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.9
CVE-2026-9267
Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate(…
Mitigation only
HIGH 7.8
CVE-2026-45258
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition …
FreeBSD
Mitigation only
MEDIUM 5.0
CVE-2026-48770
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malforme…
Notepad\+\+
8.9.6.1+
HIGH 7.1
CVE-2026-53303
In the Linux kernel, the following vulnerability has been resolved:
f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()
In f2fs_sb…
Linux Kernel
6.1.175 / 6.6.141+
HIGH 7.5
CVE-2026-54341
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload triggers an out-of-bounds rea…
Patch available
HIGH 7.5
CVE-2026-5757
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the serve…
Ollama
after 0.13.5
HIGH 7.5
CVE-2026-12340
Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Iden…
Wolfssl
5.9.2+
HIGH 7.1
CVE-2026-56788
RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allowi…
Rtklib
after 2.4.3
HIGH 8.4
CVE-2026-12897
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful explo…
Mitigation only
CRITICAL 9.1
CVE-2026-6094
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supp…
Wolfssl
5.9.2+
MEDIUM 6.1
CVE-2026-57451
Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline af…
Vim
9.2.0670+
MEDIUM 5.5
CVE-2026-57452
Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05!
method (xch…
Vim
9.2.0671+
MEDIUM 6.1
CVE-2026-57454
Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a virtual-text property whose of…
Vim
9.2.0679+
HIGH 8.2
CVE-2026-57235
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) …
Nokogiri
1.19.4+
MEDIUM 6.5
CVE-2026-4526
In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. …
Emberznet
after 9.0.2
MEDIUM 6.5
CVE-2026-47149
In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process…
Emberznet
after 9.0.2
MEDIUM 6.5
CVE-2026-47154
In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminat…
Emberznet
after 9.0.2
HIGH 7.1
CVE-2026-47147
In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM i…
Emberznet
after 9.0.2
MEDIUM 6.5
CVE-2026-47148
In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate t…
Emberznet
after 9.0.2
HIGH 8.2
CVE-2026-53268
In the Linux kernel, the following vulnerability has been resolved:
netfilter: conntrack_irc: fix possible out-of-bounds read
When parsing fails af…
Linux Kernel
5.10.259 / 5.15.210+
HIGH 7.1
CVE-2026-53253
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: bnep: reject short frames before parsing
A BNEP peer can send a shor…
Linux Kernel
5.15.210 / 6.1.176+
HIGH 8.1
CVE-2026-53254
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: RFCOMM: validate skb length in MCC handlers
The RFCOMM MCC handlers …
Linux Kernel
5.15.210 / 6.1.176+
HIGH 7.1
CVE-2026-53255
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: validate advertising TLV before type checks
tlv_data_is_valid(…
Linux Kernel
5.10.259 / 5.15.210+
CRITICAL 9.1
CVE-2026-53224
In the Linux kernel, the following vulnerability has been resolved:
sctp: validate embedded INIT chunk and address list lengths in cookie
sctp_unpa…
Linux Kernel
6.18.36 / 7.0.13+
HIGH 8.7
CVE-2026-53230
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
mlx5_query_ni…
Linux Kernel
6.6.143 / 6.12.94+
HIGH 7.1
CVE-2026-53179
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix buffer over-read in rtw_update_protection
rtw_update_pr…
Linux Kernel
6.18.36 / 7.0.13+
HIGH 7.8
CVE-2026-53172
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: fix IFM region index out-of-bounds in command stream parser
NPU_S…
Linux Kernel
7.0.13+
HIGH 8.1
CVE-2026-53147
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Validate XDomain request packet size before type cast
tb_xdp_handl…
Linux Kernel
6.1.176 / 6.6.143+
HIGH 7.1
CVE-2026-53149
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Bound root directory content to block size
__tb_property_parse_dir…
Linux Kernel
5.10.259 / 5.15.210+
HIGH 7.1
CVE-2026-53138
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Bound VBIOS record-chain walk loops
[Why & How]
All record-cha…
Linux Kernel
5.10.260 / 5.15.211+