Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2026-53390
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
The permission-check ACE…
Linux Kernel
5.15.212 / 6.6.144+
MEDIUM 5.3
CVE-2026-16013
A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPat…
No fix yet
MEDIUM 5.9
CVE-2026-44452
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC…
H2o
2026-05-29+
CRITICAL 9.1
CVE-2026-57075
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.
The base64 decoder in t…
Mitigation only
HIGH 7.7
CVE-2026-57077
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len.
In the bundled libsyck newline_le…
No fix yet
MEDIUM 6.1
CVE-2026-57896
An out-of-bounds read vulnerability in the Productivity Suite allows a
local attacker to trigger kernel memory corruption by sending a crafted
IOCT…
No fix yet
MEDIUM 5.9
CVE-2026-60073
An out-of-bounds read in the Productivity Suite allows a physical
attacker to control the length of data sent to a USB device. This can
lead to a s…
No fix yet
MEDIUM 6.1
CVE-2026-60140
An out-of-bounds read vulnerability in the Productivity Suite allows a
local attacker to trigger kernel memory corruption by sending a crafted
IOCT…
No fix yet
CRITICAL 9.1
CVE-2026-57073
HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead.
The parserc_parse function attempts to check for multicharacter str…
No fix yet
CRITICAL 9.1
CVE-2026-57074
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead.
The parserc_parse function attempts to check for multicharacter stri…
Mitigation only
MEDIUM 6.5
CVE-2026-47729
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/F…
Squid
7.6+
MEDIUM 5.5
CVE-2026-45612
rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds rea…
No fix yet
MEDIUM 5.1
CVE-2026-38754
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a cra…
Busybox
Mitigation only
MEDIUM 5.4
CVE-2026-62353
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() inc…
Mitigation only
HIGH 7.5
CVE-2026-62351
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompress…
Mitigation only
HIGH 8.8
CVE-2026-10673
The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ethernet frames in OPEN Alliance (…
Zephyr
Mitigation only
MEDIUM 5.3
CVE-2026-60065
When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated at…
Nginx Gateway Fabric
2.6.7 / 5.5.3+
MEDIUM 5.6
CVE-2026-15030
Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read…
Mitigation only
MEDIUM 5.5
CVE-2026-47979
Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this v…
Media Encoder
after 26.2.2
MEDIUM 6.5
CVE-2026-15714
An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_he…
Mitigation only
MEDIUM 5.9
CVE-2026-15712
A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the lib…
Mitigation only
HIGH 8.6
CVE-2026-15720
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wid…
Mitigation only
HIGH 7.5
CVE-2026-58539
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 6.8
CVE-2026-58528
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
Mitigation only
HIGH 7.1
CVE-2026-58529
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
Windows 11 26h1
10.0.28000.2525+
HIGH 8.8
CVE-2026-57094
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 5.5
CVE-2026-57085
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
Mitigation only
MEDIUM 5.5
CVE-2026-56192
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
16.0.19725.20434+
MEDIUM 5.5
CVE-2026-56195
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
Mitigation only
MEDIUM 6.5
CVE-2026-56186
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+