Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Zephyr MEDIUM 6.1
CVE-2026-1681

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path …

Fix: after 4.3.0
Fix from $1,600 2026-05-12
Unclassified HIGH 7.8
CVE-2026-42046

libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows …

Patch available
Fix from $1,950 2026-05-11
Ipados HIGH 7.3
CVE-2026-43656

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 2…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Ipados MEDIUM 6.2
CVE-2026-43666

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26…

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Ipados MEDIUM 6.5
CVE-2026-28972

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 2…

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Ipados MEDIUM 6.5
CVE-2026-28956

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS …

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Ipados MEDIUM 6.5
CVE-2026-28918

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26…

Fix: 26.5+
Fix from $1,600 2026-05-11
Ipados MEDIUM 5.4
CVE-2026-28819EPSS 7%

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, …

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Jq MEDIUM 5.5
CVE-2026-41257

jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack…

Fix: after 1.8.1
Fix from $1,600 2026-05-11
Linux Kernel HIGH 7.8
CVE-2026-43500EPSS 93%

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA…

Fix: 6.18.29 / 7.0.6+
Fix from $1,950 2026-05-11
Ac10u Firmware CRITICAL 9.8
CVE-2026-8263

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtr…

Mitigation only
Fix from $2,300 2026-05-11
Pillow HIGH 7.8
CVE-2026-42311

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, po…

Fix: 12.2.0+
Fix from $1,950 2026-05-09
Linux Kernel HIGH 8.1
CVE-2026-43362

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encryption corruption in SMB2_write() SMB2_write() pl…

Fix: 6.6.130 / 6.12.78+
Fix from $1,950 2026-05-08
Linux Kernel HIGH 7.8
CVE-2026-43330

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - fix overflow on long hmac keys When a key longer than block size…

Fix: 6.6.134 / 6.12.81+
Fix from $1,950 2026-05-08
Go MEDIUM 5.9
CVE-2026-39817

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extr…

Fix: 1.25.10 / 1.26.3+
Fix from $1,600 2026-05-07
Firefox HIGH 8.1
CVE-2026-8092

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption…

Fix: 115.35.2 / 140.10.2+
Fix from $1,950 2026-05-07
Libreoffice HIGH 7.8
CVE-2026-4430

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. Thi…

Fix: 25.8.7.0 / 26.2.3.0+
Fix from $1,950 2026-05-07
Zx297520v3 Firmware MEDIUM 6.8
CVE-2026-40003

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validat…

Mitigation only
Fix from $1,600 2026-05-07
Chrome HIGH 8.8
CVE-2026-7957

Out of bounds write in Media in Google Chrome on Mac, iOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process t…

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Chrome MEDIUM 5.4
CVE-2026-7950

Out of bounds read and write in GFX in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary read/write via malicious n…

Fix: 148.0.7778.96+
Fix from $1,600 2026-05-06
Chrome HIGH 8.8
CVE-2026-7951

Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a craf…

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Chrome HIGH 8.3
CVE-2026-7923

Out of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially…

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Chrome HIGH 8.8
CVE-2026-7899

Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Chrome HIGH 8.8
CVE-2026-7902

Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Pan Os CRITICAL 9.8
CVE-2026-0300 KEVEPSS 32%

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an un…

Mitigation only
Fix from $2,300 2026-05-06
C Driver HIGH 7.8
CVE-2026-6691

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before…

Fix: 2.1.2+
Fix from $1,950 2026-05-06
Linux Kernel HIGH 7.8
CVE-2026-43279

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at silencing At silencing the …

Fix: 5.15.202 / 6.1.165+
Fix from $1,950 2026-05-06
Linux Kernel HIGH 7.8
CVE-2026-43258

In the Linux kernel, the following vulnerability has been resolved: alpha: fix user-space corruption during memory compaction Alpha systems can suf…

Fix: 6.12.75 / 6.18.16+
Fix from $1,950 2026-05-06
Linux Kernel HIGH 7.8
CVE-2026-43248

In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolid…

Fix: 6.12.75 / 6.18.16+
Fix from $1,950 2026-05-06
Linux Kernel HIGH 7.8
CVE-2026-43250

In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke() The ChipIdea UDC drive…

Fix: 6.12.75 / 6.18.16+
Fix from $1,950 2026-05-06