Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
CRITICAL 9.8 CVE-2026-42484 A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly … Hashcat Mitigation only Fix from $2,3002026-05-01 HIGH 8.3 CVE-2026-31712 In the Linux kernel, the following vulnerability has been resolved: ksmbd: require minimum ACE size in smb_check_perm_dacl() Both ACE-walk loops in… Linux Kernel 6.12.84 / 6.18.25+ Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-31716 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate rec->used in journal-replay file record check check_file_rec… Linux Kernel 6.6.136 / 6.12.84+ Fix from $1,9502026-05-01 CRITICAL 9.8 CVE-2026-31705 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment smb2_get_ea() appl… Linux Kernel 5.16 / 6.2+ Fix from $2,3002026-05-01 HIGH 7.1 CVE-2026-31707 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate response sizes in ipc_validate_msg() ipc_validate_msg() compute… Linux Kernel 6.12.84 / 6.18.25+ Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-31696 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix missing validation of ticket length in non-XDR key preparsing In rxr… Linux Kernel 6.6.136 / 6.12.84+ Fix from $1,9502026-05-01 HIGH 7.1 CVE-2026-31697 In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed When r… Linux Kernel 6.6.136 / 6.12.84+ Fix from $1,9502026-05-01 HIGH 7.1 CVE-2026-31698 In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed … Linux Kernel 6.6.136 / 6.12.84+ Fix from $1,9502026-05-01 HIGH 7.1 CVE-2026-31699 In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed When … Linux Kernel 6.6.136 / 6.12.84+ Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-5403 SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution Wireshark 4.4.15 / 4.6.5+ Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-5405 RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution Wireshark 4.4.15 / 4.6.5+ Fix from $1,9502026-05-01 CRITICAL 9.8 CVE-2026-40685 In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrus… Exim 4.99.2+ Fix from $2,3002026-04-30 HIGH 7.8 CVE-2026-31786 In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERV… Linux Kernel 5.10.254 / 5.15.204+ Fix from $1,9502026-04-30 HIGH 8.1 CVE-2026-7426 Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an ad… Freertos Plus Tcp 4.2.6 / 4.4.1+ Fix from $1,9502026-04-29 HIGH 7.8 CVE-2026-41220 Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.9… Mitigation only Fix from $1,9502026-04-29 HIGH 8.8 CVE-2026-7354 Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via … Chrome 147.0.7727.138+ Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7322 Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum… Firefox 115.35.1 / 140.10.1+ Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7323 Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum… Firefox 140.10.1 / 150.0.1+ Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-5435 The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer … Glibc Mitigation only Fix from $1,9502026-04-28 HIGH 7.8 CVE-2026-31690 In the Linux kernel, the following vulnerability has been resolved: firmware: thead: Fix buffer overflow and use standard endian macros Addresses t… Linux Kernel 6.18.23 / 6.19.13+ Fix from $1,9502026-04-27 HIGH 7.5 CVE-2026-6785 Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showe… Firefox 115.35.0 / 140.10.0+ Fix from $1,9502026-04-26 HIGH 7.5 CVE-2026-6786 Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory… Firefox 140.10.0 / 150.0+ Fix from $1,9502026-04-26 HIGH 7.5 CVE-2026-41907 uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of… Uuid 11.1.1+ Fix from $1,9502026-04-24 HIGH 7.5 CVE-2026-41676 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) se… Rust Openssl 0.10.78+ Fix from $1,9502026-04-24 HIGH 8.1 CVE-2026-41678 rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion… Rust Openssl 0.10.78+ Fix from $1,9502026-04-24 HIGH 8.2 CVE-2026-31631 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify… Linux Kernel 6.18.23 / 6.19.13+ Fix from $1,9502026-04-24 CRITICAL 9.8 CVE-2026-31607 In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP clie… Linux Kernel 6.6.136 / 6.12.83+ Fix from $2,3002026-04-24 HIGH 8.7 CVE-2026-33317 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone… Op Tee after 4.10.0 Fix from $1,9502026-04-24 MEDIUM 6.7 CVE-2026-41989 Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt. Libgcrypt 1.10.4 / 1.11.3+ Fix from $1,6002026-04-23 CRITICAL 9.8 CVE-2026-26354 Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 t… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.60+ Fix from $2,3002026-04-22