Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
OpenSSL HIGH 8.1
CVE-2026-7383

Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer ove…

Fix: 1.0.2zq / 1.1.1zh+
Fix from $1,950 2026-06-09
Freeswitch HIGH 7.5
CVE-2026-49475

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.11.0+
Fix from $1,950 2026-06-09
Freeswitch CRITICAL 9.1
CVE-2026-49840

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.11.1+
Fix from $2,300 2026-06-09
Windows 10 1809 HIGH 7.5
CVE-2026-48563

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 8.8
CVE-2026-47653

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows Server 2016 HIGH 7.5
CVE-2026-47654

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
365 Apps HIGH 7.8
CVE-2026-45645

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09
365 Apps HIGH 8.4
CVE-2026-45472

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09
365 Apps HIGH 8.4
CVE-2026-45474

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09
365 Apps HIGH 8.4
CVE-2026-45461

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09
Remote Desktop Client HIGH 7.5
CVE-2026-44801

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 1.2.7214 / 2.0.1193.0+
Fix from $1,950 2026-06-09
Remote Desktop Client HIGH 8.8
CVE-2026-42985

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 1.2.7214 / 2.0.1193.0+
Fix from $1,950 2026-06-09
Remote Desktop Client HIGH 7.5
CVE-2026-42913

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker …

Fix: 1.2.7214 / 10.0.20348.5256+
Fix from $1,950 2026-06-09
Remote Desktop Client HIGH 7.5
CVE-2026-42909

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker …

Fix: 1.2.7214 / 2.0.1193.0+
Fix from $1,950 2026-06-09
Windows 11 24h2 HIGH 7.8
CVE-2026-42910

Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8655 / 10.0.26100.32995+
Fix from $1,950 2026-06-09
Rbe970 Firmware MEDIUM 6.5
CVE-2026-3088

Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.

Fix: 7.2.7.15 / 9.10.1.4+
Fix from $1,600 2026-06-09
Zephyr HIGH 8.8
CVE-2026-5068

A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the applic…

Fix: after 4.4.0
Fix from $1,950 2026-06-09
Dbi CRITICAL 9.8
CVE-2026-9698

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleEr…

Fix: 1.648+
Fix from $2,300 2026-06-09
Zephyr CRITICAL 9.8
CVE-2026-5067

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Ke…

Fix: after 4.3.0
Fix from $2,300 2026-06-09
Chrome HIGH 7.5
CVE-2026-11690

Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer proc…

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Chrome HIGH 8.3
CVE-2026-11672

Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to…

Fix: 149.0.7827.102+
Fix from $1,950 2026-06-09
Chrome HIGH 8.8
CVE-2026-11645 KEV

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Linux Kernel HIGH 7.8
CVE-2026-46294

In the Linux kernel, the following vulnerability has been resolved: dm: fix a buffer overflow in ioctl processing Tony Asleson (using Claude) found…

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-06-08
Linux Kernel HIGH 7.8
CVE-2026-46281

In the Linux kernel, the following vulnerability has been resolved: vmalloc: fix buffer overflow in vrealloc_node_align() Commit 4c5d3365882d ("mm/…

Fix: 6.18.27 / 7.0.4+
Fix from $1,950 2026-06-08
7 Zip HIGH 8.8
CVE-2026-48095

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allo…

Fix: 26.01+
Fix from $1,950 2026-06-05
Dbi CRITICAL 9.8
CVE-2026-10879

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL pla…

Fix: 1.648+
Fix from $2,300 2026-06-05
Enterprise Linux HIGH 7.8
CVE-2026-50264

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DR…

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Chrome HIGH 8.8
CVE-2026-11173

Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbit…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-11091

Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory ac…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11090

Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chro…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04