Vulnerability index

Browse CVEs

5,193 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Linux Kernel MEDIUM 5.5
CVE-2026-53382

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si syzbot reported…

Fix: 5.10.260 / 5.15.211+
Fix from $1,600 2026-07-19
Coredns HIGH 7.5
CVE-2026-62309

CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is ena…

Fix: 1.14.4+
Fix from $1,950 2026-07-16
Coredns MEDIUM 5.3
CVE-2026-62299

CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two…

Fix: 1.14.5+
Fix from $1,600 2026-07-16
Unclassified HIGH 7.5
CVE-2026-15352

A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segme…

No fix yet
Fix from $1,950 2026-07-16
Nginx Ingress Controller MEDIUM 6.5
CVE-2026-52865

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify I…

Fix: 5.5.2+
Fix from $1,600 2026-07-15
Matter HIGH 7.5
CVE-2025-56363

A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used i…

Fix: 1.4.0.0+
Fix from $1,950 2026-07-14
Windows 10 21h2 MEDIUM 6.5
CVE-2026-56168

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-50673

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 6.5
CVE-2026-50366

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 11 24h2 HIGH 7.8
CVE-2026-50315

Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 6.5
CVE-2026-57976

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Zephyr MEDIUM 5.5
CVE-2026-10670

The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thread.c) calls k_object_fi…

Fix: 4.5.0+
Fix from $1,600 2026-07-14
Crypt\ HIGH 7.5
CVE-2026-58101

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an e…

Fix: 2.1.3+
Fix from $1,950 2026-07-13
Zeek HIGH 7.5
CVE-2026-60109

Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to…

Fix: 8.0.9+
Fix from $1,950 2026-07-09
Patch MEDIUM 5.5
CVE-2026-56288

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive e…

Fix: after 2.8.0
Fix from $1,600 2026-07-09
Wireshark MEDIUM 5.5
CVE-2026-15171

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Fix: 4.4.17 / 4.6.7+
Fix from $1,600 2026-07-08
Nats Server HIGH 7.5
CVE-2026-58250

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated pee…

Fix: 2.11.17 / 2.12.8+
Fix from $1,950 2026-07-08
Onnx MEDIUM 5.5
CVE-2026-44512

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.conve…

Fix: 1.22.0+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.5
CVE-2026-50812

A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attack…

Patch available
Fix from $1,600 2026-07-08
Wazuh MEDIUM 6.5
CVE-2026-56401

Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolle…

Fix: 5.0.0+
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.5
CVE-2026-50810

A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2e…

Patch available
Fix from $1,600 2026-07-07
Unclassified HIGH 7.5
CVE-2026-38976

mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-leve…

Patch available
Fix from $1,950 2026-07-06
Dng Software Development Kit MEDIUM 5.5
CVE-2026-48267

DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-servic…

Fix: 1.7.1.2611+
Fix from $1,600 2026-07-06
Fireware HIGH 7.5
CVE-2026-13084

A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) co…

Fix: 11.12.4 / 12.5.19+
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.2
CVE-2026-36909

A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-36912

A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-14324

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

Mitigation only
Fix from $1,600 2026-07-01
Linux Kernel MEDIUM 5.5
CVE-2026-53350

In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_…

Fix: 6.1.176 / 6.6.143+
Fix from $1,600 2026-07-01
Linux Kernel CRITICAL 9.8
CVE-2026-53355

In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is …

Fix: 3.19 / 4.2+
Fix from $2,300 2026-07-01
Linux Kernel MEDIUM 5.5
CVE-2026-53348

In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions sdca_…

Fix: 7.0.13+
Fix from $1,600 2026-07-01