Vulnerability index

Browse CVEs

8,423 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
MEDIUM 6.9 CVE-2026-9267 Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate(… Mitigation only Fix from $1,6002026-06-29 HIGH 7.8 CVE-2026-45258 dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition … FreeBSD Mitigation only Fix from $1,9502026-06-27 MEDIUM 5.0 CVE-2026-48770 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malforme… Notepad\+\+ 8.9.6.1+ Fix from $1,6002026-06-26 HIGH 7.1 CVE-2026-53303 In the Linux kernel, the following vulnerability has been resolved: f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show() In f2fs_sb… Linux Kernel 6.1.175 / 6.6.141+ Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-54341 Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload triggers an out-of-bounds rea… Patch available Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-5757 Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the serve… Ollama after 0.13.5 Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-12340 Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Iden… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.1 CVE-2026-56788 RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allowi… Rtklib after 2.4.3 Fix from $1,9502026-06-25 HIGH 8.4 CVE-2026-12897 Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful explo… Mitigation only Fix from $1,9502026-06-25 CRITICAL 9.1 CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supp… Wolfssl 5.9.2+ Fix from $2,3002026-06-25 MEDIUM 6.1 CVE-2026-57451 Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline af… Vim 9.2.0670+ Fix from $1,6002026-06-25 MEDIUM 5.5 CVE-2026-57452 Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05! method (xch… Vim 9.2.0671+ Fix from $1,6002026-06-25 MEDIUM 6.1 CVE-2026-57454 Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a virtual-text property whose of… Vim 9.2.0679+ Fix from $1,6002026-06-25 HIGH 8.2 CVE-2026-57235 Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) … Nokogiri 1.19.4+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-4526 In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. … Emberznet after 9.0.2 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-47149 In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process… Emberznet after 9.0.2 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-47154 In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminat… Emberznet after 9.0.2 Fix from $1,6002026-06-25 HIGH 7.1 CVE-2026-47147 In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM i… Emberznet after 9.0.2 Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-47148 In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate t… Emberznet after 9.0.2 Fix from $1,6002026-06-25 HIGH 8.2 CVE-2026-53268 In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack_irc: fix possible out-of-bounds read When parsing fails af… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-06-25 HIGH 7.1 CVE-2026-53253 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before parsing A BNEP peer can send a shor… Linux Kernel 5.15.210 / 6.1.176+ Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-53254 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in MCC handlers The RFCOMM MCC handlers … Linux Kernel 5.15.210 / 6.1.176+ Fix from $1,9502026-06-25 HIGH 7.1 CVE-2026-53255 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before type checks tlv_data_is_valid(… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-06-25 CRITICAL 9.1 CVE-2026-53224 In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpa… Linux Kernel 6.18.36 / 7.0.13+ Fix from $2,3002026-06-25 HIGH 8.7 CVE-2026-53230 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list mlx5_query_ni… Linux Kernel 6.6.143 / 6.12.94+ Fix from $1,9502026-06-25 HIGH 7.1 CVE-2026-53179 In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix buffer over-read in rtw_update_protection rtw_update_pr… Linux Kernel 6.18.36 / 7.0.13+ Fix from $1,9502026-06-25 HIGH 7.8 CVE-2026-53172 In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix IFM region index out-of-bounds in command stream parser NPU_S… Linux Kernel 7.0.13+ Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-53147 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Validate XDomain request packet size before type cast tb_xdp_handl… Linux Kernel 6.1.176 / 6.6.143+ Fix from $1,9502026-06-25 HIGH 7.1 CVE-2026-53149 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block size __tb_property_parse_dir… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-06-25 HIGH 7.1 CVE-2026-53138 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loops [Why & How] All record-cha… Linux Kernel 5.10.260 / 5.15.211+ Fix from $1,9502026-06-25