Vulnerability index

Browse CVEs

3,242 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Linux Kernel MEDIUM 5.5
CVE-2026-43492

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming report…

Fix: 5.10.259 / 5.15.210+
Fix from $1,600 2026-05-19
Unclassified MEDIUM 5.5
CVE-2026-32849

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where th…

Patch available
Fix from $1,600 2026-05-18
Unclassified HIGH 7.5
CVE-2026-44673

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results…

Mitigation only
Fix from $1,950 2026-05-14
Libsixel HIGH 7.8
CVE-2026-44636

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's…

Fix: 1.8.7-r2+
Fix from $1,950 2026-05-14
Libsixel HIGH 7.1
CVE-2026-44637

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's ima…

Fix: 1.8.7-r2+
Fix from $1,950 2026-05-14
Openimageio HIGH 8.8
CVE-2026-43909

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…

Fix: 3.0.18.0 / 3.1.13.0+
Fix from $1,950 2026-05-14
Openimageio HIGH 7.8
CVE-2026-43905

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…

Fix: 3.0.18.0 / 3.1.13.0+
Fix from $1,950 2026-05-14
Openimageio HIGH 8.3
CVE-2026-43907

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…

Fix: 3.0.18.0 / 3.1.13.0+
Fix from $1,950 2026-05-14
Openimageio HIGH 8.8
CVE-2026-43908

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…

Fix: 3.0.18.0 / 3.1.13.0+
Fix from $1,950 2026-05-14
Wasmtime HIGH 7.5
CVE-2026-44216

Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained check…

Fix: 36.0.8 / 43.0.2+
Fix from $1,950 2026-05-14
PostgreSQL HIGH 8.8
CVE-2026-6473

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and wri…

Fix: 14.23 / 15.18+
Fix from $1,950 2026-05-14
Unclassified MEDIUM 6.9
CVE-2026-8295

An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_appen…

Mitigation only
Fix from $1,600 2026-05-14
Netty MEDIUM 6.5
CVE-2026-42580

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently ove…

Fix: 4.1.133 / 4.2.13+
Fix from $1,600 2026-05-13
C2pa MEDIUM 6.2
CVE-2026-34680

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could …

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34671

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could …

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
Windows 11 24h2 HIGH 7.8
CVE-2026-42896

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8457 / 10.0.26100.32860+
Fix from $1,950 2026-05-12
.net Framework HIGH 7.3
CVE-2026-35433

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

Fix: 8.0.27 / 9.0.16+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-35415

Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Media Encoder HIGH 7.8
CVE-2026-34640

Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code…

Fix: 25.6.5 / 26.2+
Fix from $1,950 2026-05-12
After Effects HIGH 7.8
CVE-2026-34644

After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code e…

Fix: 25.6.5+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34333

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34330

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Unclassified HIGH 8.7
CVE-2026-20753

Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adversary with a privileged user …

Mitigation only
Fix from $1,950 2026-05-12
Barebox HIGH 7.8
CVE-2026-34963

barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in …

Fix: 2026.04.0+
Fix from $1,950 2026-05-11
Unclassified HIGH 7.8
CVE-2026-42046

libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows …

Patch available
Fix from $1,950 2026-05-11
Ipados HIGH 7.5
CVE-2026-28952

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS So…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Jq MEDIUM 5.5
CVE-2026-43894

jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D…

Fix: after 1.8.1
Fix from $1,600 2026-05-11
Jq MEDIUM 5.5
CVE-2026-41257

jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack…

Fix: after 1.8.1
Fix from $1,600 2026-05-11
PHP HIGH 7.5
CVE-2026-7568

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metap…

Fix: 8.2.31 / 8.3.31+
Fix from $1,950 2026-05-10
Pillow HIGH 7.8
CVE-2026-42311

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, po…

Fix: 12.2.0+
Fix from $1,950 2026-05-09