Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Unclassified HIGH 8.8
CVE-2026-16870

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltrati…

No fix yet
Fix from $1,950 2026-07-24
Chrome HIGH 8.8
CVE-2026-16807

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafte…

Fix: 150.0.7871.186+
Fix from $1,950 2026-07-23
Ffmpeg HIGH 7.8
CVE-2026-65705

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap…

Fix: after 8.1.2
Fix from $1,950 2026-07-23
Ffmpeg HIGH 7.8
CVE-2026-65706

FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap …

Fix: after 8.1.2
Fix from $1,950 2026-07-23
Ffmpeg HIGH 7.8
CVE-2026-65703

FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap c…

Fix: after 8.1.2
Fix from $1,950 2026-07-23
Ffmpeg HIGH 7.8
CVE-2026-65704

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat fil…

Fix: after 8.1.2
Fix from $1,950 2026-07-23
Ffmpeg HIGH 8.8
CVE-2026-64835

FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allow…

Fix: after 8.1.2
Fix from $1,950 2026-07-22
Unbound HIGH 7.5
CVE-2026-40691

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound …

Fix: 1.25.2+
Fix from $1,950 2026-07-22
Chrome CRITICAL 9.6
CVE-2026-16419

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox …

Fix: 150.0.7871.182+
Fix from $2,300 2026-07-21
Chrome HIGH 8.3
CVE-2026-16413

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 150.0.7871.182+
Fix from $1,950 2026-07-21
Libheif HIGH 7.8
CVE-2026-47178

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled,…

Fix: 1.22.0+
Fix from $1,950 2026-07-21
Zephyr HIGH 8.1
CVE-2026-10678

The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes from an I2C bus master byt…

Fix: after 4.4.1
Fix from $1,950 2026-07-21
Unclassified HIGH 7.8
CVE-2026-59146

Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sp…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-59147

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach…

No fix yet
Fix from $2,300 2026-07-21
Firefox CRITICAL 10.0
CVE-2026-16367

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $2,300 2026-07-21
Fory CRITICAL 9.8
CVE-2026-64608

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa…

Fix: 1.4.0+
Fix from $2,300 2026-07-21
Chrome HIGH 8.8
CVE-2026-15903

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Fix: 150.0.7871.128+
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-15813

A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does no…

No fix yet
Fix from $1,600 2026-07-20
Linux Kernel HIGH 7.8
CVE-2026-64145

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix dma_buffer leak on bus acquire failure wilc_wlan_firmware_d…

Fix unknown
Fix from $1,950 2026-07-19
Linux Kernel HIGH 7.8
CVE-2026-64097

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate GPIO pin LUT table size before iterating [Why&How] Th…

Fix: 6.1.175 / 6.6.142+
Fix from $1,950 2026-07-19
Linux Kernel HIGH 7.8
CVE-2026-63794

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path In sev_dbg_cryp…

Fix: 5.10.260 / 5.15.211+
Fix from $1,950 2026-07-19
Linux Kernel HIGH 7.8
CVE-2026-53380

In the Linux kernel, the following vulnerability has been resolved: media: rzv2h-ivc: Fix concurrent buffer list access The list of buffers (`rzv2h…

Fix: 7.0.9+
Fix from $1,950 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16225

A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::NegotiatePDULength of the fil…

No fix yet
Fix from $1,600 2026-07-19
Unclassified HIGH 8.8
CVE-2026-16095

A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Exe…

No fix yet
Fix from $1,950 2026-07-18
OpenSSL HIGH 7.1
CVE-2026-45784

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/…

Fix: 0.10.80+
Fix from $1,950 2026-07-17
Quicly HIGH 7.5
CVE-2026-44436

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable t…

Fix: 2026-05-29+
Fix from $1,950 2026-07-16
Unclassified HIGH 7.0
CVE-2026-61389

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL requ…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.0
CVE-2026-60063

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL requ…

No fix yet
Fix from $1,950 2026-07-16
Unclassified CRITICAL 9.1
CVE-2026-15422

The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chu…

No fix yet
Fix from $2,300 2026-07-16
Unclassified MEDIUM 6.0
CVE-2026-10589

A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.

No fix yet
Fix from $1,600 2026-07-16