Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
HIGH 7.0 CVE-2025-68119 Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading… Go 1.24.12 / 1.25.6+ Fix from $1,9502026-01-28 CRITICAL 9.8 CVE-2020-36964 YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing s… Mitigation only Fix from $2,3002026-01-28 HIGH 8.8 CVE-2025-58150 Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest co… Xen Patch available Fix from $1,9502026-01-28 CRITICAL 9.8 CVE-2026-22262 Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14,… Suricata 7.0.14 / 8.0.3+ Fix from $2,3002026-01-27 HIGH 7.5 CVE-2026-22260 Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Versio… Suricata 8.0.3+ Fix from $1,9502026-01-27 CRITICAL 9.8 CVE-2026-24832 Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. Ix Ray Engine 1.6 1.3+ Fix from $2,3002026-01-27 MEDIUM 6.3 CVE-2026-0648 The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_… Threadx 6.4.5+ Fix from $1,6002026-01-27 HIGH 7.4 CVE-2025-69419 Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing … OpenSSL 1.1.1ze / 3.0.19+ Fix from $1,9502026-01-27 CRITICAL 9.8 CVE-2025-68670 xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from im… Debian Linux 0.10.5+ Fix from $2,3002026-01-27 MEDIUM 6.1 CVE-2025-11187 Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL poi… OpenSSL 3.4.4 / 3.5.5+ Fix from $1,6002026-01-27 HIGH 8.8 CVE-2025-15467EPSS 48% Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. … OpenSSL 3.0.19 / 3.3.6+ Fix from $1,9502026-01-27 HIGH 7.0 CVE-2025-55095 The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended… Threadx Usbx after 6.4.2 Fix from $1,9502026-01-27 MEDIUM 5.4 CVE-2026-1489 A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processin… Mitigation only Fix from $1,6002026-01-27 CRITICAL 10.0 CVE-2026-24826 Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability i… Patch available Fix from $2,3002026-01-27 HIGH 7.5 CVE-2026-24827 Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs/pull/358/merge. Patch available Fix from $1,9502026-01-27 MEDIUM 6.5 CVE-2026-24829 Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4. Patch available Fix from $1,6002026-01-27 CRITICAL 10.0 CVE-2026-24823 Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X-TRACK (Software/X-Track/USER… Patch available Fix from $2,3002026-01-27 HIGH 8.7 CVE-2026-24817 Out-of-bounds Write vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C… Patch available Fix from $1,9502026-01-27 CRITICAL 10.0 CVE-2026-24822 Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files… Patch available Fix from $2,3002026-01-27 MEDIUM 6.9 CVE-2026-24809 An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflo… Patch available Fix from $1,6002026-01-27 CRITICAL 9.8 CVE-2026-24811 Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root. Root after 6.34.08 Fix from $2,3002026-01-27 MEDIUM 5.1 CVE-2026-24795 Out-of-bounds Write vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Oniguruma modules). This vulnerab… Patch available Fix from $1,6002026-01-27 MEDIUM 6.9 CVE-2026-24797 Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerability is associated with program… Patch available Fix from $1,6002026-01-27 MEDIUM 5.2 CVE-2026-24799 Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in davisking dlib (dlib/external/zlib modul… Patch available Fix from $1,6002026-01-27 CRITICAL 10.0 CVE-2026-24800 Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow furnace (extern/zlib modules)… Patch available Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-24793 Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in azerothcore azerothcore-wotlk (deps/zlib… Azerothcore after 4.0.0 Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-1361 ASDA-Soft Stack-based Buffer Overflow Vulnerability Asda Soft after 7.2.2.0 Fix from $2,3002026-01-27 HIGH 7.8 CVE-2026-1284 An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through R… Mitigation only Fix from $1,9502026-01-26 HIGH 7.3 CVE-2025-27821 Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recomme… Hadoop 3.4.2+ Fix from $1,9502026-01-26 HIGH 7.8 CVE-2026-1418 A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_… Gpac after 2.4.0 Fix from $1,9502026-01-26