Vulnerability index

Browse CVEs

8,440 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
MEDIUM 5.5 CVE-2026-25920 SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in SumatraPDF's MOBI HuffDic de… Sumatrapdf after 3.5.2 Fix from $1,6002026-02-09 MEDIUM 6.1 CVE-2026-2241 A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/os.c. Performing a manipulatio… Janet after 1.40.1 Fix from $1,6002026-02-09 MEDIUM 6.1 CVE-2026-2242 A vulnerability was determined in janet-lang janet up to 1.40.1. This impacts the function janetc_if of the file src/core/specials.c. Executing a man… Janet after 1.40.1 Fix from $1,6002026-02-09 MEDIUM 6.1 CVE-2026-2240 A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef of the file src/core/compile… Janet after 1.40.1 Fix from $1,6002026-02-09 HIGH 7.1 CVE-2026-24921 Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. Harmonyos No fix yet Fix from $1,9502026-02-06 HIGH 7.1 CVE-2026-24915 Out-of-bounds read issue in the media subsystem. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. Harmonyos Mitigation only Fix from $1,9502026-02-06 CRITICAL 9.3 CVE-2026-0106 In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege … Android Mitigation only Fix from $2,3002026-02-05 HIGH 7.8 CVE-2026-25585 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to… Iccdev 2.3.1.3+ Fix from $1,9502026-02-04 CRITICAL 9.1 CVE-2026-25139 RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de… Riot after 2025.10 Fix from $2,3002026-02-04 MEDIUM 6.3 CVE-2026-25508 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, an out-of-bounds read vul… Esp Idf Patch available Fix from $1,6002026-02-04 HIGH 7.1 CVE-2026-23102 In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: signal: Fix restoration of SVE context When SME is supported, Res… Linux Kernel 6.1.162 / 6.6.123+ Fix from $1,9502026-02-04 HIGH 7.1 CVE-2026-23099 In the Linux kernel, the following vulnerability has been resolved: bonding: limit BOND_MODE_8023AD to Ethernet devices BOND_MODE_8023AD makes sens… Linux Kernel 5.15.199 / 6.1.162+ Fix from $1,9502026-02-04 HIGH 7.1 CVE-2026-23076 In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Fix potential OOB access in audio mixer handling In the audio mixe… Linux Kernel 5.10.249 / 5.15.199+ Fix from $1,9502026-02-04 MEDIUM 6.9 CVE-2025-65081 An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged… Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.9 CVE-2025-64098 Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.… Debian Linux 2.6.11 / 3.3.1+ Fix from $1,6002026-02-03 HIGH 7.5 CVE-2025-62603 Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ParticipantGenericMessage is … Debian Linux 2.6.11 / 3.3.1+ Fix from $1,9502026-02-03 MEDIUM 6.5 CVE-2025-47402 Transient DOS when processing a received frame with an excessively large authentication information element. Sa8620p Firmware No fix yet Fix from $1,6002026-02-02 MEDIUM 6.5 CVE-2026-20420 In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a r… Nr15 Mitigation only Fix from $1,6002026-02-02 MEDIUM 6.5 CVE-2026-20421 In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a … Nr15 Mitigation only Fix from $1,6002026-02-02 HIGH 7.5 CVE-2025-63656 An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service … Monkey after 1.8.5 Fix from $1,9502026-01-29 HIGH 7.5 CVE-2025-63657 An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Servi… Monkey after 1.8.5 Fix from $1,9502026-01-29 HIGH 7.5 CVE-2025-63649 An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to… Monkey after 1.8.5 Fix from $1,9502026-01-29 HIGH 7.5 CVE-2025-63650 An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (… Monkey after 1.8.5 Fix from $1,9502026-01-29 HIGH 7.5 CVE-2025-63653 An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Servic… Monkey after 1.8.5 Fix from $1,9502026-01-29 HIGH 8.1 CVE-2026-23568 An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26… Digital Employee Experience 26.1+ Fix from $1,9502026-01-29 HIGH 7.5 CVE-2026-23569 An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26… Digital Employee Experience 26.1+ Fix from $1,9502026-01-29 MEDIUM 6.5 CVE-2025-71004 A segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted inpu… Oneflow No fix yet Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2025-71001 A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. Oneflow No fix yet Fix from $1,6002026-01-28 MEDIUM 5.5 CVE-2025-46306 The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciou… Keynote 15.1 / 26.0+ Fix from $1,6002026-01-28 HIGH 8.1 CVE-2026-24852 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to… Iccdev 2.3.1.2+ Fix from $1,9502026-01-28