Vulnerability index

Browse CVEs

5,193 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
MEDIUM 5.5 CVE-2026-53382 In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si syzbot reported… Linux Kernel 5.10.260 / 5.15.211+ Fix from $1,6002026-07-19 HIGH 7.5 CVE-2026-62309 CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is ena… Coredns 1.14.4+ Fix from $1,9502026-07-16 MEDIUM 5.3 CVE-2026-62299 CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two… Coredns 1.14.5+ Fix from $1,6002026-07-16 HIGH 7.5 CVE-2026-15352 A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segme… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.5 CVE-2026-52865 When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify I… Nginx Ingress Controller 5.5.2+ Fix from $1,6002026-07-15 HIGH 7.5 CVE-2025-56363 A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used i… Matter 1.4.0.0+ Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-56168 Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-50673 Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-50366 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-50315 Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.8875 / 10.0.26100.33158+ Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-57976 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-10670 The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thread.c) calls k_object_fi… Zephyr 4.5.0+ Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-58101 Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an e… Crypt\ 2.1.3+ Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-60109 Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to… Zeek 8.0.9+ Fix from $1,9502026-07-09 MEDIUM 5.5 CVE-2026-56288 GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive e… Patch after 2.8.0 Fix from $1,6002026-07-09 MEDIUM 5.5 CVE-2026-15171 SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Wireshark 4.4.17 / 4.6.7+ Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-58250 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated pee… Nats Server 2.11.17 / 2.12.8+ Fix from $1,9502026-07-08 MEDIUM 5.5 CVE-2026-44512 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.conve… Onnx 1.22.0+ Fix from $1,6002026-07-08 MEDIUM 5.5 CVE-2026-50812 A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attack… Patch available Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-56401 Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolle… Wazuh 5.0.0+ Fix from $1,6002026-07-08 MEDIUM 5.5 CVE-2026-50810 A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2e… Patch available Fix from $1,6002026-07-07 HIGH 7.5 CVE-2026-38976 mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-leve… Patch available Fix from $1,9502026-07-06 MEDIUM 5.5 CVE-2026-48267 DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-servic… Dng Software Development Kit 1.7.1.2611+ Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-13084 A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) co… Fireware 11.12.4 / 12.5.19+ Fix from $1,9502026-07-03 MEDIUM 6.2 CVE-2026-36909 A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial… Mitigation only Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-36912 A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a … Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-14324 RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.5 CVE-2026-53350 In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_… Linux Kernel 6.1.176 / 6.6.143+ Fix from $1,6002026-07-01 CRITICAL 9.8 CVE-2026-53355 In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is … Linux Kernel 3.19 / 4.2+ Fix from $2,3002026-07-01 MEDIUM 5.5 CVE-2026-53348 In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions sdca_… Linux Kernel 7.0.13+ Fix from $1,6002026-07-01