Vulnerability index

Browse CVEs

5,200 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Linux Kernel MEDIUM 5.5
CVE-2026-23279

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame() In mesh_rx_…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-03-25
Ipados MEDIUM 5.9
CVE-2026-28886

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
Libvncserver HIGH 7.5
CVE-2026-32854EPSS 5%

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within h…

Fix: 0.9.15+
Fix from $1,950 2026-03-24
Nginx Open Source HIGH 7.5
CVE-2026-27651

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate…

Fix: 1.28.3 / 1.29.7+
Fix from $1,950 2026-03-24
Unclassified MEDIUM 5.3
CVE-2026-4751

NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0.

Patch available
Fix from $1,600 2026-03-24
Android Imagemagick7 HIGH 7.5
CVE-2026-33853

NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.

Fix: 7.1.2-10+
Fix from $1,950 2026-03-24
Unclassified MEDIUM 5.2
CVE-2026-4743

NULL Pointer Dereference vulnerability in taurusxin ncmdump (‎src/utils‎ modules). This vulnerability is associated with program files cJSON.Cpp‎. T…

Patch available
Fix from $1,600 2026-03-24
Ella Core HIGH 7.5
CVE-2026-33282

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue…

Fix: 1.6.0+
Fix from $1,950 2026-03-24
Ella Core HIGH 7.5
CVE-2026-33283

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a…

Fix: 1.6.0+
Fix from $1,950 2026-03-24
Unclassified HIGH 7.5
CVE-2026-25075

strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote att…

Mitigation only
Fix from $1,950 2026-03-23
Unclassified HIGH 7.5
CVE-2026-26829

A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows attackers to cause a Denial of Se…

Patch available
Fix from $1,950 2026-03-23
Unclassified HIGH 7.5
CVE-2026-26828

A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allows attackers to cause a Denia…

Patch available
Fix from $1,950 2026-03-23
Libde265 HIGH 7.5
CVE-2026-33164

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fau…

Fix: 1.0.17+
Fix from $1,950 2026-03-20
Libfuse MEDIUM 5.5
CVE-2026-33179

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak i…

Fix: 3.18.2+
Fix from $1,600 2026-03-20
Linux Kernel MEDIUM 5.5
CVE-2026-23277

In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmi…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-03-20
Udm HIGH 7.5
CVE-2026-33064

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to procedure …

Fix: 1.4.2+
Fix from $1,950 2026-03-20
Free5gc HIGH 7.5
CVE-2026-33063

free5GC is an open source 5G core network. free5GC AUSF prior to version 1.4.2 has is an Improper Null Check vulnerability leading to Denial of Servi…

Fix: 1.4.2+
Fix from $1,950 2026-03-20
Samtools HIGH 7.5
CVE-2026-31973

SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in the cram-size command, used to …

Fix: 1.22.2+
Fix from $1,950 2026-03-18
Htslib HIGH 7.5
CVE-2026-31964

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a…

Fix: 1.21.1 / 1.22.2+
Fix from $1,950 2026-03-18
Linux Kernel MEDIUM 5.5
CVE-2026-23251

In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the …

Fix: 6.12.75 / 6.18.16+
Fix from $1,600 2026-03-18
Linux Kernel MEDIUM 5.5
CVE-2026-23249

In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidating two btrees The free space and …

Fix: 6.12.75 / 6.18.16+
Fix from $1,600 2026-03-18
Linux Kernel MEDIUM 5.5
CVE-2026-23250

In the Linux kernel, the following vulnerability has been resolved: xfs: check return value of xchk_scrub_create_subord Fix this function to return…

Fix: 6.12.75 / 6.18.16+
Fix from $1,600 2026-03-18
Linux Kernel HIGH 7.5
CVE-2026-23242

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in header processing If siw_ge…

Fix: 5.10.252 / 5.15.202+
Fix from $1,950 2026-03-18
Unclassified MEDIUM 6.8
CVE-2025-13406

NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects s…

Mitigation only
Fix from $1,600 2026-03-17
Libexpat MEDIUM 5.5
CVE-2026-32776

libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

Fix: 2.7.5+
Fix from $1,600 2026-03-16
Libexpat MEDIUM 5.5
CVE-2026-32778

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

Fix: 2.7.5+
Fix from $1,600 2026-03-16
Arduino Tuyaopen MEDIUM 6.5
CVE-2026-28522

arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area …

Fix: 1.2.1+
Fix from $1,600 2026-03-16
Vim MEDIUM 5.5
CVE-2026-32249

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containin…

Fix: 9.2.0137+
Fix from $1,600 2026-03-12
Substance 3d Painter MEDIUM 5.5
CVE-2026-27217

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-s…

Fix: 11.1.3+
Fix from $1,600 2026-03-10
Substance 3d Painter MEDIUM 5.5
CVE-2026-27218

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-s…

Fix: 11.1.3+
Fix from $1,600 2026-03-10