Vulnerability index

Browse CVEs

5,193 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Unclassified HIGH 8.7
CVE-2026-45084

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the …

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67304

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails.…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67288

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupN…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-18064

An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer derefer…

No fix yet
Fix from $1,950 2026-07-30
Traffic Server HIGH 7.5
CVE-2026-58161

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: fr…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Unclassified HIGH 7.5
CVE-2026-67184

TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sen…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.5
CVE-2026-66749

Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid…

No fix yet
Fix from $1,600 2026-07-28
Mcp Server HIGH 7.5
CVE-2026-47427

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref withou…

Fix: 1.1.0+
Fix from $1,950 2026-07-28
Hdf5 MEDIUM 5.5
CVE-2026-17574

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length dataty…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.3
CVE-2026-17500

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-gramma…

No fix yet
Fix from $1,600 2026-07-27
Linux Kernel MEDIUM 5.5
CVE-2026-64295

In the Linux kernel, the following vulnerability has been resolved: mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN acces…

Fix: 6.18.39 / 7.1.4+
Fix from $1,600 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64297

In the Linux kernel, the following vulnerability has been resolved: module: decompress: check return value of module_extend_max_pages() module_exte…

Fix: 6.1.178 / 6.6.145+
Fix from $1,600 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64288

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB VNCR TLB invalidation …

Fix: 6.18.39 / 7.1.4+
Fix from $1,600 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64258

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref …

Fix: 6.18.39 / 7.1.4+
Fix from $1,600 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64253

In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() PF_BLOCK_TS is only set in blk…

Fix: 6.12.95 / 6.18.38+
Fix from $1,600 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64229

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Disable broadcast TLB flush when PCID is disabled Booting with "nopcid"…

Fix: 6.18.35 / 7.0.11+
Fix from $1,600 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64230

In the Linux kernel, the following vulnerability has been resolved: regulator: tps65219: fix irq_data.rdev not being assigned Commit 64a6b577490c (…

Fix: 6.18.34 / 7.0.11+
Fix from $1,600 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64234

In the Linux kernel, the following vulnerability has been resolved: tty: serial: pch_uart: add check for dma_alloc_coherent() Add a check for dma_a…

Fix: 5.10.259 / 5.15.210+
Fix from $1,600 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64227

In the Linux kernel, the following vulnerability has been resolved: ACPI: driver: Check ACPI_COMPANION() against NULL during probe Since every plat…

Fix: 6.12.97 / 6.18.40+
Fix from $1,600 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64228

In the Linux kernel, the following vulnerability has been resolved: net: ethtool: phy: avoid NULL deref when PHY driver is unbound phydev->drv can …

Fix: 6.18.34 / 7.0.11+
Fix from $1,600 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64214

In the Linux kernel, the following vulnerability has been resolved: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work…

Fix: 6.1.175 / 6.6.142+
Fix from $1,600 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64215

In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table Check the return…

Fix: 7.0.11+
Fix from $1,600 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64212

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it In iwl_…

Fix: 6.18.34 / 7.0.11+
Fix from $1,600 2026-07-24
Nimble HIGH 7.5
CVE-2026-45816

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would tr…

Fix: 1.10.0+
Fix from $1,950 2026-07-24
Unclassified HIGH 7.5
CVE-2026-50032

A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a…

No fix yet
Fix from $1,950 2026-07-23
MongoDB MEDIUM 5.3
CVE-2026-13070

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during t…

Fix: 7.0.39 / 8.0.28+
Fix from $1,600 2026-07-22
MongoDB MEDIUM 6.5
CVE-2026-13065

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expre…

Fix: 7.0.39 / 8.0.28+
Fix from $1,600 2026-07-22
Unbound MEDIUM 5.9
CVE-2026-55717

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Libheif MEDIUM 5.5
CVE-2026-47709

libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling(…

Fix: 1.22.0+
Fix from $1,600 2026-07-21
Zephyr HIGH 8.1
CVE-2026-10678

The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes from an I2C bus master byt…

Fix: after 4.4.1
Fix from $1,950 2026-07-21