Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-43492
In the Linux kernel, the following vulnerability has been resolved:
lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()
Yiming report…
Linux Kernel
5.10.259 / 5.15.210+
MEDIUM 5.5
CVE-2026-32849
NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where th…
Patch available
HIGH 7.5
CVE-2026-44673
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results…
Mitigation only
HIGH 7.8
CVE-2026-44636
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's…
Libsixel
1.8.7-r2+
HIGH 7.1
CVE-2026-44637
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's ima…
Libsixel
1.8.7-r2+
HIGH 8.8
CVE-2026-43909
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…
Openimageio
3.0.18.0 / 3.1.13.0+
HIGH 7.8
CVE-2026-43905
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…
Openimageio
3.0.18.0 / 3.1.13.0+
HIGH 8.3
CVE-2026-43907
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…
Openimageio
3.0.18.0 / 3.1.13.0+
HIGH 8.8
CVE-2026-43908
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 a…
Openimageio
3.0.18.0 / 3.1.13.0+
HIGH 7.5
CVE-2026-44216
Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained check…
Wasmtime
36.0.8 / 43.0.2+
HIGH 8.8
CVE-2026-6473
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and wri…
PostgreSQL
14.23 / 15.18+
MEDIUM 6.9
CVE-2026-8295
An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_appen…
Mitigation only
MEDIUM 6.5
CVE-2026-42580
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently ove…
Netty
4.1.133 / 4.2.13+
MEDIUM 6.2
CVE-2026-34680
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could …
C2pa
0.7.1 / 0.80.1+
MEDIUM 6.2
CVE-2026-34671
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could …
C2pa
0.7.1 / 0.80.1+
HIGH 7.8
CVE-2026-42896
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.8457 / 10.0.26100.32860+
HIGH 7.3
CVE-2026-35433
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
.net Framework
8.0.27 / 9.0.16+
HIGH 7.8
CVE-2026-35415
Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.8
CVE-2026-34640
Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code…
Media Encoder
25.6.5 / 26.2+
HIGH 7.8
CVE-2026-34644
After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code e…
After Effects
25.6.5+
HIGH 7.8
CVE-2026-34333
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.8
CVE-2026-34330
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to…
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 8.7
CVE-2026-20753
Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adversary with a privileged user …
Mitigation only
HIGH 7.8
CVE-2026-34963
barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in …
Barebox
2026.04.0+
HIGH 7.8
CVE-2026-42046
libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows …
Patch available
HIGH 7.5
CVE-2026-28952
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS So…
Ipados
14.8.7 / 15.7.7+
MEDIUM 5.5
CVE-2026-43894
jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D…
Jq
after 1.8.1
MEDIUM 5.5
CVE-2026-41257
jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack…
Jq
after 1.8.1
HIGH 7.5
CVE-2026-7568
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metap…
PHP
8.2.31 / 8.3.31+
HIGH 7.8
CVE-2026-42311
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, po…
Pillow
12.2.0+