Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-53382
In the Linux kernel, the following vulnerability has been resolved:
media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
syzbot reported…
Linux Kernel
5.10.260 / 5.15.211+
HIGH 7.5
CVE-2026-62309
CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is ena…
Coredns
1.14.4+
MEDIUM 5.3
CVE-2026-62299
CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two…
Coredns
1.14.5+
HIGH 7.5
CVE-2026-15352
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segme…
No fix yet
MEDIUM 6.5
CVE-2026-52865
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify I…
Nginx Ingress Controller
5.5.2+
HIGH 7.5
CVE-2025-56363
A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used i…
Matter
1.4.0.0+
MEDIUM 6.5
CVE-2026-56168
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
Windows 10 21h2
10.0.19044.7548 / 10.0.19045.7548+
HIGH 7.8
CVE-2026-50673
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 6.5
CVE-2026-50366
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-50315
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.8875 / 10.0.26100.33158+
MEDIUM 6.5
CVE-2026-57976
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 5.5
CVE-2026-10670
The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thread.c) calls k_object_fi…
Zephyr
4.5.0+
HIGH 7.5
CVE-2026-58101
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference.
X509V3_EXT_d2i(ext) returns NULL when an e…
Crypt\
2.1.3+
HIGH 7.5
CVE-2026-60109
Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to…
Zeek
8.0.9+
MEDIUM 5.5
CVE-2026-56288
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive e…
Patch
after 2.8.0
MEDIUM 5.5
CVE-2026-15171
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Wireshark
4.4.17 / 4.6.7+
HIGH 7.5
CVE-2026-58250
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated pee…
Nats Server
2.11.17 / 2.12.8+
MEDIUM 5.5
CVE-2026-44512
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.conve…
Onnx
1.22.0+
MEDIUM 5.5
CVE-2026-50812
A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attack…
Patch available
MEDIUM 6.5
CVE-2026-56401
Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolle…
Wazuh
5.0.0+
MEDIUM 5.5
CVE-2026-50810
A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2e…
Patch available
HIGH 7.5
CVE-2026-38976
mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-leve…
Patch available
MEDIUM 5.5
CVE-2026-48267
DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-servic…
Dng Software Development Kit
1.7.1.2611+
HIGH 7.5
CVE-2026-13084
A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) co…
Fireware
11.12.4 / 12.5.19+
MEDIUM 6.2
CVE-2026-36909
A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial…
Mitigation only
HIGH 7.5
CVE-2026-36912
A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a …
Mitigation only
MEDIUM 6.5
CVE-2026-14324
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Mitigation only
MEDIUM 5.5
CVE-2026-53350
In the Linux kernel, the following vulnerability has been resolved:
ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
In wm_adsp_…
Linux Kernel
6.1.176 / 6.6.143+
CRITICAL 9.8
CVE-2026-53355
In the Linux kernel, the following vulnerability has been resolved:
net: rds: clear i_sends on setup unwind
The RDS IB connection teardown path is …
Linux Kernel
3.19 / 4.2+
MEDIUM 5.5
CVE-2026-53348
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions
sdca_…
Linux Kernel
7.0.13+