Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
HIGH 7.8 CVE-2026-23406 In the Linux kernel, the following vulnerability has been resolved: apparmor: fix side-effect bug in match_char() macro usage The match_char() macr… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-04-01 HIGH 7.8 CVE-2026-23407 In the Linux kernel, the following vulnerability has been resolved: apparmor: fix missing bounds check on DEFAULT table in verify_dfa() The verify_… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-04-01 HIGH 8.8 CVE-2026-5292 Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a craf… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 HIGH 8.1 CVE-2026-5282 Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a craf… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 MEDIUM 6.5 CVE-2026-2394 Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4… Connext Professional 7.3.1.1 / 7.7.0+ Fix from $1,6002026-04-01 MEDIUM 5.5 CVE-2026-34554 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a heap-buffer-overflow (HBO) i… Iccdev 2.3.1.6+ Fix from $1,6002026-03-31 MEDIUM 5.5 CVE-2026-34556 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a heap-buffer-overflo… Iccdev 2.3.1.6+ Fix from $1,6002026-03-31 CRITICAL 9.1 CVE-2026-34235 PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists … Pjsip 2.17+ Fix from $2,3002026-03-31 HIGH 8.1 CVE-2026-33982 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 by… Freerdp 3.24.2+ Fix from $1,9502026-03-30 HIGH 7.1 CVE-2026-33985 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen,… Freerdp 3.24.2+ Fix from $1,9502026-03-30 HIGH 8.2 CVE-2026-32877 Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication cod… Botan 3.11.0+ Fix from $1,9502026-03-30 HIGH 7.5 CVE-2026-25627 NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed … Nanomq 0.24.8+ Fix from $1,9502026-03-30 MEDIUM 6.8 CVE-2025-66037 OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes O… Opensc 0.27.0+ Fix from $1,6002026-03-30 HIGH 7.3 CVE-2026-28527 BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAYER_APPLICATION_SETTING_ATTRIB… Btstack 1.8.1+ Fix from $1,9502026-03-30 MEDIUM 5.7 CVE-2026-28526 BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_ATTRI… Btstack 1.8.1+ Fix from $1,6002026-03-30 HIGH 7.5 CVE-2026-27880 The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes. Grafana 12.1.0 / 12.2.0+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-33669 SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then t… Siyuan 3.6.2+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-3622 The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing … Tl Wr841n Firmware 0.9.1_4.19+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-32284 The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead … Msgpack after 3.1.2 Fix from $1,9502026-03-26 HIGH 7.6 CVE-2026-33636 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versio… Libpng 1.6.56+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-26008 EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/… Everest 2026.02.0+ Fix from $1,9502026-03-26 HIGH 7.1 CVE-2026-23397 In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths in fingerprints nfnl_osf_add_… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-03-26 MEDIUM 6.5 CVE-2026-33515 Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling… Squid 7.5+ Fix from $1,6002026-03-26 HIGH 7.1 CVE-2026-23388 In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within range Syzkaller reports a "gene… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-23363 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211() Ch… Linux Kernel 6.12.77 / 6.18.17+ Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-23325 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() Ch… Linux Kernel 6.6.130 / 6.12.77+ Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-23327 In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_us… Linux Kernel 6.19.7+ Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-23318 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of th… Linux Kernel 4.20 / 5.4+ Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-23315 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() Chec… Linux Kernel 6.1.167 / 6.6.130+ Fix from $1,9502026-03-25 HIGH 7.1 CVE-2026-23305 In the Linux kernel, the following vulnerability has been resolved: accel/rocket: fix unwinding in error path in rocket_probe When rocket_core_init… Linux Kernel 6.18.17 / 6.19.7+ Fix from $1,9502026-03-25