Vulnerability index

Browse CVEs

5,193 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Big Ip Next Cloud Native Network Functions HIGH 7.5
CVE-2026-42409

When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests c…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Nanazip MEDIUM 5.5
CVE-2026-42442

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image pars…

Fix: 6.0.1698.0+
Fix from $1,600 2026-05-12
Windows 10 1607 HIGH 7.4
CVE-2026-40413

Windows TCP/IP Denial of Service Vulnerability

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.4
CVE-2026-40414

Windows TCP/IP Denial of Service Vulnerability

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 11 24h2 HIGH 7.5
CVE-2026-40405

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

Fix: 10.0.26100.8390 / 10.0.26100.32772+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.1
CVE-2026-40401

Windows TCP/IP Denial of Service Vulnerability

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Illustrator MEDIUM 5.5
CVE-2026-34662

Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-…

Fix: 29.8.7 / 30.4+
Fix from $1,600 2026-05-12
Windows Server 2025 MEDIUM 6.5
CVE-2026-34350

Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.

Fix: 10.0.26100.32772+
Fix from $1,600 2026-05-12
Windows 10 1607 MEDIUM 5.5
CVE-2026-34339

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,600 2026-05-12
Quickassist Technology MEDIUM 5.5
CVE-2026-20914

Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial …

Fix: 2.6.0-0018+
Fix from $1,600 2026-05-12
Quickassist Technology MEDIUM 6.1
CVE-2026-20771

Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial o…

Fix: 1.13.0-0021+
Fix from $1,600 2026-05-12
Unclassified HIGH 7.5
CVE-2025-40833

The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. This could allow an attacker …

Mitigation only
Fix from $1,950 2026-05-12
Ipados MEDIUM 6.2
CVE-2026-28985

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5…

Fix: 26.5+
Fix from $1,600 2026-05-11
Open5gs MEDIUM 6.5
CVE-2026-8252

A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a…

Fix: after 2.7.7
Fix from $1,600 2026-05-11
PHP MEDIUM 6.5
CVE-2026-7259

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma…

Fix: 8.2.31 / 8.3.31+
Fix from $1,600 2026-05-10
PHP HIGH 7.5
CVE-2026-7262

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, t…

Fix: 8.2.31 / 8.3.31+
Fix from $1,950 2026-05-10
Argo Workflows MEDIUM 6.5
CVE-2026-42183

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version…

Fix: 4.0.5+
Fix from $1,600 2026-05-09
Pgbouncer HIGH 7.5
CVE-2026-6666

A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.

Fix: 1.25.2+
Fix from $1,950 2026-05-09
Linux Kernel MEDIUM 5.5
CVE-2026-43471

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_tra…

Fix: 6.6.130 / 6.10+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43473

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Add NULL checks when resetting request and reply queues The drive…

Fix: 6.1.167 / 6.6.130+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43463

In the Linux kernel, the following vulnerability has been resolved: rxrpc, afs: Fix missing error pointer check after rxrpc_kernel_lookup_peer() rx…

Fix: 6.8 / 6.18.19+
Fix from $1,600 2026-05-08
Linux Kernel HIGH 7.5
CVE-2026-43441

In the Linux kernel, the following vulnerability has been resolved: net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled When booting wi…

Fix: 6.1.167 / 6.6.130+
Fix from $1,950 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43443

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-mach-common: Add missing error check for clock acquisition The a…

Fix: 6.19.9+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43444

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Unreserve bo if queue update failed Error handling path should unre…

Fix: 6.12.78 / 6.18.19+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43431

In the Linux kernel, the following vulnerability has been resolved: xhci: Fix NULL pointer dereference when reading portli debugfs files Michal rep…

Fix: 6.19.9+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43436

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces T…

Fix: 6.1.167 / 6.6.130+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43421

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Fix net_device lifecycle with device_move The network devic…

Fix: 6.12.78 / 6.18.19+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43424

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling The `tpg->t…

Fix: 5.10.253 / 6.1.167+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43412

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: qdsp6: Fix q6apm remove ordering during ADSP stop and start During …

Fix: 6.1.167 / 6.6.130+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43413

In the Linux kernel, the following vulnerability has been resolved: scsi: hisi_sas: Fix NULL pointer exception during user_scan() user_scan() invok…

Fix: 6.6.130 / 6.12.78+
Fix from $1,600 2026-05-08