Vulnerability index

Browse CVEs

8,423 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
HIGH 8.1 CVE-2026-53390 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() The permission-check ACE… Linux Kernel 5.15.212 / 6.6.144+ Fix from $1,9502026-07-19 MEDIUM 5.3 CVE-2026-16013 A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPat… No fix yet Fix from $1,6002026-07-17 MEDIUM 5.9 CVE-2026-44452 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC… H2o 2026-05-29+ Fix from $1,6002026-07-16 CRITICAL 9.1 CVE-2026-57075 YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in t… Mitigation only Fix from $2,3002026-07-16 HIGH 7.7 CVE-2026-57077 YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_le… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.1 CVE-2026-57896 An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCT… No fix yet Fix from $1,6002026-07-16 MEDIUM 5.9 CVE-2026-60073 An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead to a s… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.1 CVE-2026-60140 An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCT… No fix yet Fix from $1,6002026-07-16 CRITICAL 9.1 CVE-2026-57073 HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter str… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-57074 XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter stri… Mitigation only Fix from $2,3002026-07-16 MEDIUM 6.5 CVE-2026-47729 Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/F… Squid 7.6+ Fix from $1,6002026-07-16 MEDIUM 5.5 CVE-2026-45612 rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds rea… No fix yet Fix from $1,6002026-07-16 MEDIUM 5.1 CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a cra… Busybox Mitigation only Fix from $1,6002026-07-15 MEDIUM 5.4 CVE-2026-62353 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() inc… Mitigation only Fix from $1,6002026-07-15 HIGH 7.5 CVE-2026-62351 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompress… Mitigation only Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-10673 The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ethernet frames in OPEN Alliance (… Zephyr Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.3 CVE-2026-60065 When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated at… Nginx Gateway Fabric 2.6.7 / 5.5.3+ Fix from $1,6002026-07-15 MEDIUM 5.6 CVE-2026-15030 Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read… Mitigation only Fix from $1,6002026-07-15 MEDIUM 5.5 CVE-2026-47979 Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this v… Media Encoder after 26.2.2 Fix from $1,6002026-07-14 MEDIUM 6.5 CVE-2026-15714 An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_he… Mitigation only Fix from $1,6002026-07-14 MEDIUM 5.9 CVE-2026-15712 A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the lib… Mitigation only Fix from $1,6002026-07-14 HIGH 8.6 CVE-2026-15720 In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wid… Mitigation only Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-58539 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 6.8 CVE-2026-58528 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. Mitigation only Fix from $1,6002026-07-14 HIGH 7.1 CVE-2026-58529 Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. Windows 11 26h1 10.0.28000.2525+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-57094 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-57085 Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. Mitigation only Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-56192 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 365 Apps 16.0.19725.20434+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-56195 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 365 Apps Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.5 CVE-2026-56186 Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14