Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Hashcat CRITICAL 9.8
CVE-2026-42484

A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly …

Mitigation only
Fix from $2,300 2026-05-01
Linux Kernel HIGH 8.3
CVE-2026-31712

In the Linux kernel, the following vulnerability has been resolved: ksmbd: require minimum ACE size in smb_check_perm_dacl() Both ACE-walk loops in…

Fix: 6.12.84 / 6.18.25+
Fix from $1,950 2026-05-01
Linux Kernel HIGH 7.8
CVE-2026-31716

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate rec->used in journal-replay file record check check_file_rec…

Fix: 6.6.136 / 6.12.84+
Fix from $1,950 2026-05-01
Linux Kernel CRITICAL 9.8
CVE-2026-31705

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment smb2_get_ea() appl…

Fix: 5.16 / 6.2+
Fix from $2,300 2026-05-01
Linux Kernel HIGH 7.1
CVE-2026-31707

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate response sizes in ipc_validate_msg() ipc_validate_msg() compute…

Fix: 6.12.84 / 6.18.25+
Fix from $1,950 2026-05-01
Linux Kernel HIGH 7.8
CVE-2026-31696

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix missing validation of ticket length in non-XDR key preparsing In rxr…

Fix: 6.6.136 / 6.12.84+
Fix from $1,950 2026-05-01
Linux Kernel HIGH 7.1
CVE-2026-31697

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed When r…

Fix: 6.6.136 / 6.12.84+
Fix from $1,950 2026-05-01
Linux Kernel HIGH 7.1
CVE-2026-31698

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed …

Fix: 6.6.136 / 6.12.84+
Fix from $1,950 2026-05-01
Linux Kernel HIGH 7.1
CVE-2026-31699

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed When …

Fix: 6.6.136 / 6.12.84+
Fix from $1,950 2026-05-01
Wireshark HIGH 7.8
CVE-2026-5403

SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Fix: 4.4.15 / 4.6.5+
Fix from $1,950 2026-05-01
Wireshark HIGH 7.8
CVE-2026-5405

RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Fix: 4.4.15 / 4.6.5+
Fix from $1,950 2026-05-01
Exim CRITICAL 9.8
CVE-2026-40685

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrus…

Fix: 4.99.2+
Fix from $2,300 2026-04-30
Linux Kernel HIGH 7.8
CVE-2026-31786

In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERV…

Fix: 5.10.254 / 5.15.204+
Fix from $1,950 2026-04-30
Freertos Plus Tcp HIGH 8.1
CVE-2026-7426

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an ad…

Fix: 4.2.6 / 4.4.1+
Fix from $1,950 2026-04-29
Unclassified HIGH 7.8
CVE-2026-41220

Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.9…

Mitigation only
Fix from $1,950 2026-04-29
Chrome HIGH 8.8
CVE-2026-7354

Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via …

Fix: 147.0.7727.138+
Fix from $1,950 2026-04-28
Firefox HIGH 7.3
CVE-2026-7322

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum…

Fix: 115.35.1 / 140.10.1+
Fix from $1,950 2026-04-28
Firefox HIGH 7.3
CVE-2026-7323

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum…

Fix: 140.10.1 / 150.0.1+
Fix from $1,950 2026-04-28
Glibc HIGH 7.3
CVE-2026-5435

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer …

Mitigation only
Fix from $1,950 2026-04-28
Linux Kernel HIGH 7.8
CVE-2026-31690

In the Linux kernel, the following vulnerability has been resolved: firmware: thead: Fix buffer overflow and use standard endian macros Addresses t…

Fix: 6.18.23 / 6.19.13+
Fix from $1,950 2026-04-27
Firefox HIGH 7.5
CVE-2026-6785

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showe…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-26
Firefox HIGH 7.5
CVE-2026-6786

Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-26
Uuid HIGH 7.5
CVE-2026-41907

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of…

Fix: 11.1.1+
Fix from $1,950 2026-04-24
Rust Openssl HIGH 7.5
CVE-2026-41676

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) se…

Fix: 0.10.78+
Fix from $1,950 2026-04-24
Rust Openssl HIGH 8.1
CVE-2026-41678

rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion…

Fix: 0.10.78+
Fix from $1,950 2026-04-24
Linux Kernel HIGH 8.2
CVE-2026-31631

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify…

Fix: 6.18.23 / 6.19.13+
Fix from $1,950 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31607

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP clie…

Fix: 6.6.136 / 6.12.83+
Fix from $2,300 2026-04-24
Op Tee HIGH 8.7
CVE-2026-33317

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,950 2026-04-24
Libgcrypt MEDIUM 6.7
CVE-2026-41989

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

Fix: 1.10.4 / 1.11.3+
Fix from $1,600 2026-04-23
Powerprotect Dp Series Appliance CRITICAL 9.8
CVE-2026-26354

Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 t…

Fix: 2.7.9 / 7.13.1.60+
Fix from $2,300 2026-04-22