Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Go HIGH 7.0
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading…

Fix: 1.24.12 / 1.25.6+
Fix from $1,950 2026-01-28
Unclassified CRITICAL 9.8
CVE-2020-36964

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing s…

Mitigation only
Fix from $2,300 2026-01-28
Xen HIGH 8.8
CVE-2025-58150

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest co…

Patch available
Fix from $1,950 2026-01-28
Suricata CRITICAL 9.8
CVE-2026-22262

Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14,…

Fix: 7.0.14 / 8.0.3+
Fix from $2,300 2026-01-27
Suricata HIGH 7.5
CVE-2026-22260

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Versio…

Fix: 8.0.3+
Fix from $1,950 2026-01-27
Ix Ray Engine 1.6 CRITICAL 9.8
CVE-2026-24832

Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

Fix: 1.3+
Fix from $2,300 2026-01-27
Threadx MEDIUM 6.3
CVE-2026-0648

The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_…

Fix: 6.4.5+
Fix from $1,600 2026-01-27
OpenSSL HIGH 7.4
CVE-2025-69419

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing …

Fix: 1.1.1ze / 3.0.19+
Fix from $1,950 2026-01-27
Debian Linux CRITICAL 9.8
CVE-2025-68670

xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from im…

Fix: 0.10.5+
Fix from $2,300 2026-01-27
OpenSSL MEDIUM 6.1
CVE-2025-11187

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL poi…

Fix: 3.4.4 / 3.5.5+
Fix from $1,600 2026-01-27
OpenSSL HIGH 8.8
CVE-2025-15467EPSS 48%

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. …

Fix: 3.0.19 / 3.3.6+
Fix from $1,950 2026-01-27
Threadx Usbx HIGH 7.0
CVE-2025-55095

The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended…

Fix: after 6.4.2
Fix from $1,950 2026-01-27
Unclassified MEDIUM 5.4
CVE-2026-1489

A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processin…

Mitigation only
Fix from $1,600 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24826

Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability i…

Patch available
Fix from $2,300 2026-01-27
Unclassified HIGH 7.5
CVE-2026-24827

Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs/pull/358/merge.

Patch available
Fix from $1,950 2026-01-27
Unclassified MEDIUM 6.5
CVE-2026-24829

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.

Patch available
Fix from $1,600 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24823

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X-TRACK (Software/X-Track/USER…

Patch available
Fix from $2,300 2026-01-27
Unclassified HIGH 8.7
CVE-2026-24817

Out-of-bounds Write vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C…

Patch available
Fix from $1,950 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24822

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files…

Patch available
Fix from $2,300 2026-01-27
Unclassified MEDIUM 6.9
CVE-2026-24809

An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflo…

Patch available
Fix from $1,600 2026-01-27
Root CRITICAL 9.8
CVE-2026-24811

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root.

Fix: after 6.34.08
Fix from $2,300 2026-01-27
Unclassified MEDIUM 5.1
CVE-2026-24795

Out-of-bounds Write vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Oniguruma modules). This vulnerab…

Patch available
Fix from $1,600 2026-01-27
Unclassified MEDIUM 6.9
CVE-2026-24797

Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerability is associated with program…

Patch available
Fix from $1,600 2026-01-27
Unclassified MEDIUM 5.2
CVE-2026-24799

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in davisking dlib (dlib/external/zlib modul…

Patch available
Fix from $1,600 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24800

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow furnace (extern/zlib modules)…

Patch available
Fix from $2,300 2026-01-27
Azerothcore CRITICAL 9.8
CVE-2026-24793

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in azerothcore azerothcore-wotlk (deps/zlib…

Fix: after 4.0.0
Fix from $2,300 2026-01-27
Asda Soft CRITICAL 9.8
CVE-2026-1361

ASDA-Soft Stack-based Buffer Overflow Vulnerability

Fix: after 7.2.2.0
Fix from $2,300 2026-01-27
Unclassified HIGH 7.8
CVE-2026-1284

An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through R…

Mitigation only
Fix from $1,950 2026-01-26
Hadoop HIGH 7.3
CVE-2025-27821

Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recomme…

Fix: 3.4.2+
Fix from $1,950 2026-01-26
Gpac HIGH 7.8
CVE-2026-1418

A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_…

Fix: after 2.4.0
Fix from $1,950 2026-01-26