Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2026-7383
Issue summary: A signed integer overflow when sizing the destination
buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap
buffer ove…
OpenSSL
1.0.2zq / 1.1.1zh+
HIGH 7.5
CVE-2026-49475
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…
Freeswitch
1.11.0+
CRITICAL 9.1
CVE-2026-49840
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…
Freeswitch
1.11.1+
HIGH 7.5
CVE-2026-48563
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows 10 1809
10.0.17763.8880 / 10.0.19044.7417+
HIGH 8.8
CVE-2026-47653
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.5
CVE-2026-47654
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows Server 2016
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.8
CVE-2026-45645
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2026-45472
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2026-45474
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2026-45461
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.5
CVE-2026-44801
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Remote Desktop Client
1.2.7214 / 2.0.1193.0+
HIGH 8.8
CVE-2026-42985
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Remote Desktop Client
1.2.7214 / 2.0.1193.0+
HIGH 7.5
CVE-2026-42913
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker …
Remote Desktop Client
1.2.7214 / 10.0.20348.5256+
HIGH 7.5
CVE-2026-42909
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker …
Remote Desktop Client
1.2.7214 / 2.0.1193.0+
HIGH 7.8
CVE-2026-42910
Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.8655 / 10.0.26100.32995+
MEDIUM 6.5
CVE-2026-3088
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
Rbe970 Firmware
7.2.7.15 / 9.10.1.4+
HIGH 8.8
CVE-2026-5068
A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the applic…
Zephyr
after 4.4.0
CRITICAL 9.8
CVE-2026-9698
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleEr…
Dbi
1.648+
CRITICAL 9.8
CVE-2026-5067
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Ke…
Zephyr
after 4.3.0
HIGH 7.5
CVE-2026-11690
Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer proc…
Chrome
149.0.7827.103+
HIGH 8.3
CVE-2026-11672
Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to…
Chrome
149.0.7827.102+
HIGH 8.8
CVE-2026-11645 KEV
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via …
Chrome
149.0.7827.103+
HIGH 7.8
CVE-2026-46294
In the Linux kernel, the following vulnerability has been resolved:
dm: fix a buffer overflow in ioctl processing
Tony Asleson (using Claude) found…
Linux Kernel
5.10.258 / 5.15.209+
HIGH 7.8
CVE-2026-46281
In the Linux kernel, the following vulnerability has been resolved:
vmalloc: fix buffer overflow in vrealloc_node_align()
Commit 4c5d3365882d ("mm/…
Linux Kernel
6.18.27 / 7.0.4+
HIGH 8.8
CVE-2026-48095
7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allo…
7 Zip
26.01+
CRITICAL 9.8
CVE-2026-10879
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders.
The preparse method expands SQL pla…
Dbi
1.648+
HIGH 7.8
CVE-2026-50264
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DR…
Enterprise Linux
21.1.23 / 24.1.12+
HIGH 8.8
CVE-2026-11173
Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbit…
Chrome
149.0.7827.53+
HIGH 8.8
CVE-2026-11091
Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory ac…
Chrome
149.0.7827.53+
MEDIUM 6.5
CVE-2026-11090
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chro…
Chrome
149.0.7827.53+