Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Firefox CRITICAL 9.8
CVE-2026-14241

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of…

Mitigation only
Fix from $2,300 2026-06-30
Safari MEDIUM 6.5
CVE-2026-43745

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS …

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Ipados MEDIUM 6.5
CVE-2026-43703

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43712

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 2…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43676

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS …

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-28979

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS …

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13592

A vulnerability was detected in liftoff-sr CIPster up to e8e9dba09bf56962807d3504b783ccdb6287f3e4. Affected by this issue is the function BufWriter::…

Patch available
Fix from $1,950 2026-06-29
Tl Wr841n Firmware MEDIUM 6.5
CVE-2026-9105

An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated a…

Fix: 14_260518+
Fix from $1,600 2026-06-29
Unclassified HIGH 8.6
CVE-2026-58049

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary c…

Mitigation only
Fix from $1,950 2026-06-28
Zephyr HIGH 7.8
CVE-2026-10643

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_cont…

Fix: after 4.4.1
Fix from $1,950 2026-06-28
FreeBSD HIGH 7.8
CVE-2026-45258

dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition …

Mitigation only
Fix from $1,950 2026-06-27
Tiff HIGH 7.5
CVE-2026-46604

The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.

Fix: 0.43.0+
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-57876

An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability …

Mitigation only
Fix from $1,950 2026-06-26
Wolfssl HIGH 7.5
CVE-2026-6325

Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destinati…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Wolfssl HIGH 7.5
CVE-2026-6679

A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to…

Fix: 5.9.1+
Fix from $1,950 2026-06-25
Wolfssl MEDIUM 5.3
CVE-2026-6681

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provi…

Fix: 5.9.1+
Fix from $1,600 2026-06-25
Wolfssl HIGH 7.5
CVE-2026-55958

Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_S…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Rtklib CRITICAL 9.8
CVE-2026-56786

RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buf…

Fix: after 2.4.3
Fix from $2,300 2026-06-25
Jq HIGH 7.1
CVE-2026-49839

jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real hea…

Fix: 1.8.2+
Fix from $1,950 2026-06-25
Vim HIGH 7.8
CVE-2026-57455

Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word…

Fix: 9.2.0698+
Fix from $1,950 2026-06-25
Vim HIGH 7.8
CVE-2026-55693

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields…

Fix: 9.2.0653+
Fix from $1,950 2026-06-25
Vim MEDIUM 5.5
CVE-2026-55892

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iterat…

Fix: 9.2.0662+
Fix from $1,600 2026-06-25
Unclassified HIGH 7.5
CVE-2026-12844

List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() collects the values returned by t…

Patch available
Fix from $1,950 2026-06-25
Emberznet HIGH 7.1
CVE-2026-47150

In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The…

Fix: after 9.0.2
Fix from $1,950 2026-06-25
Emberznet HIGH 7.1
CVE-2026-47151

In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and…

Fix: after 9.0.2
Fix from $1,950 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53246

In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a l…

Fix: 6.18.36 / 7.0.13+
Fix from $2,300 2026-06-25
Linux Kernel HIGH 7.1
CVE-2026-53205

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log indices Add validation that read…

Fix: 6.12.94 / 6.18.36+
Fix from $1,950 2026-06-25
Linux Kernel HIGH 7.8
CVE-2026-53209

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing a…

Fix: 6.1.176 / 6.6.143+
Fix from $1,950 2026-06-25
Linux Kernel MEDIUM 6.8
CVE-2026-53196

In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() read…

Fix: 5.10.259 / 5.15.210+
Fix from $1,600 2026-06-25
Linux Kernel HIGH 7.8
CVE-2026-53202

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix signed integer truncation in IPC receive Fix potential buffer o…

Fix: 6.12.94 / 6.18.36+
Fix from $1,950 2026-06-25