Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-55012
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
Malware Protection Engine
1.1.26060.3008+
HIGH 7.8
CVE-2026-54109
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 6.8
CVE-2026-50298
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 6.8
CVE-2026-50299
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-49800
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
MEDIUM 6.8
CVE-2026-49168
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.5
CVE-2026-59199
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coo…
Pillow
12.3.0+
HIGH 7.8
CVE-2026-10669
On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the architecture hook that verif…
Zephyr
4.5.0+
CRITICAL 9.1
CVE-2026-51536
In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed…
Opener
Mitigation only
HIGH 7.5
CVE-2026-39042
An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial o…
Mitigation only
HIGH 8.4
CVE-2026-57432
Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.
S_measure_struc…
Perl
after 5.43.10
CRITICAL 9.8
CVE-2026-57433
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.
retrieve_hook_common reads a sign…
Storable
3.41+
CRITICAL 9.1
CVE-2026-13221
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is co…
Perl
after 5.43.9
CRITICAL 9.1
CVE-2026-40469
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap…
Gawk
after 5.4.0
CRITICAL 9.1
CVE-2026-40468
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating …
Gawk
after 5.4.0
HIGH 7.8
CVE-2026-7162
Successful
exploitation of the integer overflow vulnerability could allow an attacker to
achieve system-level access to the affected software.
No fix yet
MEDIUM 5.5
CVE-2026-15551
Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
This issue affects .
Patch available
CRITICAL 9.8
CVE-2026-57156
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in upd…
Freerdp
3.28.0+
HIGH 7.5
CVE-2026-38076
An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a cra…
Mitigation only
MEDIUM 6.5
CVE-2026-58207
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send …
Nats Server
2.12.12 / 2.14.3+
HIGH 7.5
CVE-2026-59879
Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the…
Immutable
4.3.9 / 5.1.8+
HIGH 7.5
CVE-2026-53482
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug…
Data Domain Operating System
7.13.1.80 / 8.3.1.40+
MEDIUM 5.3
CVE-2026-58470
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c …
Wget
after 1.25.0
HIGH 7.1
CVE-2026-58472
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c …
Wget
after 1.25.0
HIGH 7.8
CVE-2026-58384
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table…
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2026-59089
A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color …
Enterprise Linux
No fix yet
HIGH 7.8
CVE-2026-14787
A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/core/cmd_print.inc of the com…
Radare2
after 6.1.6
MEDIUM 5.5
CVE-2026-14786
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The m…
Radare2
6.1.8+
MEDIUM 5.5
CVE-2026-14761
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file…
Radare2
6.1.8+
HIGH 7.8
CVE-2026-14757
A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This m…
Radare2
6.1.8+