Vulnerability index

Browse CVEs

5,193 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Unclassified MEDIUM 5.3
CVE-2026-73502

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-derefer…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-59949

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the …

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-75012

A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the fi…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-75013

A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The …

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.9
CVE-2026-55401

CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-18699

An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unex…

No fix yet
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.5
CVE-2026-65681

Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 21h2 HIGH 8.6
CVE-2026-62702

Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

Fix: 10.0.19044.7663 / 10.0.19045.7663+
Fix from $4,900 2026-08-11
Windows 10 1607 MEDIUM 6.5
CVE-2026-59138

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Windows 10 1607 MEDIUM 6.5
CVE-2026-61345

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.5
CVE-2026-59132

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
C2pa HIGH 7.5
CVE-2026-48438

CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker co…

Fix: 0.12.1 / 0.27.6+
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-20787

Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Net…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-20878

Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Net…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.3
CVE-2026-20727

Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivilege…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-18638

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by c…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.5
CVE-2026-11810

The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.5
CVE-2026-71967

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler t…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72582

A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a s…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-17510

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. prin…

No fix yet
Fix from $4,900 2026-08-09
Unclassified HIGH 7.5
CVE-2026-52878

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-19012

Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Communi…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.8
CVE-2026-48097

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a co…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.5
CVE-2026-45204

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel null pointer dereference i…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.5
CVE-2026-70639

llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() funct…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.0
CVE-2026-70640

llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and …

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67870

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remo…

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.2
CVE-2026-19024

NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose version 1 or 2 f…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.8
CVE-2026-19026

H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or t…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.7
CVE-2026-46334

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerabilit…

No fix yet
Fix from $1,950 2026-08-05