Vulnerability index

Browse CVEs

3,242 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Radare2 MEDIUM 5.5
CVE-2026-14758

A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_an…

Fix: 6.1.8+
Fix from $1,600 2026-07-05
Edge Chromium HIGH 8.8
CVE-2026-57974

Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Data Domain Operating System MEDIUM 6.5
CVE-2026-46463

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug…

Fix: after 8.7.0.0
Fix from $1,600 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-14544

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attac…

Mitigation only
Fix from $2,300 2026-07-03
Chrome HIGH 8.8
CVE-2026-14430

Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Chrome MEDIUM 5.3
CVE-2026-14391

Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to ob…

Fix: 150.0.7871.46+
Fix from $1,600 2026-07-01
Imagemagick MEDIUM 6.5
CVE-2026-53466

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer o…

Fix: 6.9.13-51 / 7.1.2-26+
Fix from $1,600 2026-07-01
Fatfs HIGH 7.6
CVE-2026-6682

In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlle…

No fix yet
Fix from $1,950 2026-07-01
Ultravnc HIGH 8.8
CVE-2026-7838

UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failure-response parsing path. In …

Fix: after 1.8.2.2
Fix from $1,950 2026-07-01
Ultravnc MEDIUM 5.3
CVE-2026-7828

UltraVNC repeater through 1.8.2.2 contains an integer overflow in the HTTP request logging path. In repeater/webgui/settings.c:336, the win_log() fun…

Fix: after 1.8.2.2
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54900

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in usual mode with create_id ena…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54903

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corrupt…

Mitigation only
Fix from $1,600 2026-07-01
Fzf HIGH 7.5
CVE-2026-53432

fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately 2,200,000 bytes and pattern …

Fix: 0.73.1+
Fix from $1,950 2026-06-30
Enterprise Linux MEDIUM 5.1
CVE-2026-57965

A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This…

Mitigation only
Fix from $1,600 2026-06-29
Libssh2 HIGH 7.5
CVE-2026-58050

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attr…

Fix: after 1.11.1
Fix from $1,950 2026-06-28
FreeBSD HIGH 7.8
CVE-2026-49416

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size c…

Mitigation only
Fix from $1,950 2026-06-27
FreeBSD HIGH 7.8
CVE-2026-45258

dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition …

Mitigation only
Fix from $1,950 2026-06-27
Node.js HIGH 7.5
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affe…

Patch available
Fix from $1,950 2026-06-26
Wolfssl HIGH 7.5
CVE-2026-6679

A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to…

Fix: 5.9.1+
Fix from $1,950 2026-06-25
Jq MEDIUM 5.5
CVE-2026-54679

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing…

Fix: 1.8.2+
Fix from $1,600 2026-06-25
Nokogiri HIGH 8.2
CVE-2026-57235

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) …

Fix: 1.19.4+
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.4
CVE-2026-54226

A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0…

No fix yet
Fix from $1,600 2026-06-25
Nsd HIGH 8.8
CVE-2026-12244

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVC…

Fix: 4.14.3+
Fix from $1,950 2026-06-25
Linux Kernel HIGH 7.1
CVE-2026-53068

In the Linux kernel, the following vulnerability has been resolved: drm/komeda: fix integer overflow in AFBC framebuffer size check The AFBC frameb…

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-06-24
Linux Kernel HIGH 7.8
CVE-2026-53059

In the Linux kernel, the following vulnerability has been resolved: dm log: fix out-of-bounds write due to region_count overflow The local variable…

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-06-24
Linux Kernel MEDIUM 5.5
CVE-2026-53021

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix integer overflow in UNMAP bounds check sbc_execute_unma…

Fix: 5.10.258 / 5.15.209+
Fix from $1,600 2026-06-24
Linux Kernel HIGH 7.8
CVE-2026-52969

In the Linux kernel, the following vulnerability has been resolved: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() kvm_reset_dirty_gfn() guard…

Fix: 5.15.209 / 6.1.175+
Fix from $1,950 2026-06-24
Linux Kernel MEDIUM 5.5
CVE-2026-52972

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Cap AEAD AD length to 0x80000000 In order to prevent arithmeti…

Fix: 5.10.258 / 5.15.209+
Fix from $1,600 2026-06-24
Linux Kernel MEDIUM 5.5
CVE-2026-52948

In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzk…

Fix: 5.10.259 / 5.15.210+
Fix from $1,600 2026-06-24
Messagepack HIGH 7.5
CVE-2026-48502

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based o…

Fix: 2.5.301 / 3.1.7+
Fix from $1,950 2026-06-22