Vulnerability index

Browse CVEs

5,200 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Windows 11 26h1 MEDIUM 5.5
CVE-2026-32216

Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.

Fix: 10.0.28000.1836+
Fix from $1,600 2026-04-14
Windows 10 1607 HIGH 7.5
CVE-2026-32071

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-26173

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Jq MEDIUM 6.1
CVE-2026-39956

jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes …

Fix: 2026-04-08+
Fix from $1,600 2026-04-13
Nitro Pdf Pro HIGH 7.5
CVE-2025-66769

A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA packet.

Mitigation only
Fix from $1,950 2026-04-13
Nitro Pdf Pro HIGH 7.5
CVE-2025-69624

Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.al…

Mitigation only
Fix from $1,950 2026-04-13
Linux Kernel MEDIUM 5.5
CVE-2026-31424

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPR…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-04-13
Linux Kernel MEDIUM 5.5
CVE-2026-31425

In the Linux kernel, the following vulnerability has been resolved: rds: ib: reject FRMR registration before IB connection is established rds_ib_ge…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-04-13
Linux Kernel MEDIUM 5.5
CVE-2026-31421

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL pointer dereference on shared blocks The old-method…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-04-13
Linux Kernel MEDIUM 5.5
CVE-2026-31422

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: fix NULL pointer dereference on shared blocks flow_change(…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-04-13
Chamilo Lms HIGH 7.1
CVE-2026-32894

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebo…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Hardened Images HIGH 7.5
CVE-2026-1584

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with…

Mitigation only
Fix from $1,950 2026-04-09
Linux Kernel MEDIUM 5.5
CVE-2026-31411

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer av…

Fix: 5.10.252 / 5.15.202+
Fix from $1,600 2026-04-08
OpenSSL HIGH 7.5
CVE-2026-28389

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact sum…

Fix: 1.0.2zp / 1.1.1zg+
Fix from $1,950 2026-04-07
OpenSSL HIGH 7.5
CVE-2026-28390

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact…

Fix: 1.0.2zp / 1.1.1zg+
Fix from $1,950 2026-04-07
OpenSSL HIGH 7.5
CVE-2026-28388

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CR…

Fix: 1.0.2zp / 1.1.1zg+
Fix from $1,950 2026-04-07
Hardened Images MEDIUM 5.5
CVE-2026-5745

A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_te…

Mitigation only
Fix from $1,600 2026-04-07
Zephyr MEDIUM 5.3
CVE-2026-5590

A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() …

Fix: after 4.3.0
Fix from $1,600 2026-04-05
Linux Kernel HIGH 7.8
CVE-2026-31404

In the Linux kernel, the following vulnerability has been resolved: NFSD: Defer sub-object cleanup in export put callbacks svc_export_put() calls p…

Fix: 6.18.20 / 6.19.10+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 7.8
CVE-2026-31397

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix use of NULL folio in move_pages_huge_pmd() move_pages_huge_…

Fix: 6.18.20 / 6.19.10+
Fix from $1,950 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-31394

In the Linux kernel, the following vulnerability has been resolved: mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations ieee80211_…

Fix: 6.12.78 / 6.18.20+
Fix from $1,600 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23475

In the Linux kernel, the following vulnerability has been resolved: spi: fix statistics allocation The controller per-cpu statistics is not allocat…

Fix: 6.1.167 / 6.6.130+
Fix from $1,600 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23467

In the Linux kernel, the following vulnerability has been resolved: drm/i915/dmc: Fix an unlikely NULL pointer deference at probe intel_dmc_update_…

Fix: 6.18.20 / 6.19.10+
Fix from $1,600 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23460

In the Linux kernel, the following vulnerability has been resolved: net/rose: fix NULL pointer dereference in rose_transmit_link on reconnect syzka…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23442

In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6_dev_get() can return NULL wh…

Fix: 6.12.83 / 6.19.10+
Fix from $1,600 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23443

In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix After commi f13…

Fix: 6.1.167 / 6.6.130+
Fix from $1,600 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23435

In the Linux kernel, the following vulnerability has been resolved: perf/x86: Move event pointer setup earlier in x86_pmu_enable() A production AMD…

Fix: 6.18 / 6.18.20+
Fix from $1,600 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23438

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: guard flow control update with global_tx_fc in buffer switching mvp…

Fix: 5.15.203 / 6.1.167+
Fix from $1,600 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23439

In the Linux kernel, the following vulnerability has been resolved: udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n When C…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23433

In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Fix null pointer dereference when restoring bandwidth counters When a…

Fix: 6.19.10+
Fix from $1,600 2026-04-03