Vulnerability index

Browse CVEs

744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
365 Apps MEDIUM 5.5
CVE-2026-55042

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-50690

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-50497

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-50455

Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 6.5
CVE-2026-50376

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 6.5
CVE-2026-55003

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-54997

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-49801

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.1
CVE-2026-49165

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-40422

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Imagemagick MEDIUM 5.3
CVE-2026-53467

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG deco…

Fix: 6.9.13-51 / 7.1.2-26+
Fix from $1,600 2026-07-01
Linux Kernel MEDIUM 5.5
CVE-2026-53344

In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init Regmap …

Fix: 7.0.13+
Fix from $1,600 2026-07-01
Linux Kernel MEDIUM 5.5
CVE-2026-53347

In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting are…

Fix: 6.6.143 / 6.12.94+
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.3
CVE-2026-54500

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uniniti…

Mitigation only
Fix from $1,600 2026-07-01
Libssh2 MEDIUM 6.5
CVE-2026-58051

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse …

Fix: after 1.11.1
Fix from $1,600 2026-06-28
Linux Kernel MEDIUM 5.5
CVE-2026-53311

In the Linux kernel, the following vulnerability has been resolved: fuse: fix uninit-value in fuse_dentry_revalidate() fuse_dentry_revalidate() may…

Fix: 6.18.34 / 7.0.10+
Fix from $1,600 2026-06-26
Linux Kernel MEDIUM 5.5
CVE-2026-53243

In the Linux kernel, the following vulnerability has been resolved: rseq: Fix using an uninitialized stack variable in rseq_exit_user_update() Ther…

Fix: 7.0.13+
Fix from $1,600 2026-06-25
Linux Kernel CRITICAL 9.1
CVE-2026-53225

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup()…

Fix: 5.10.259 / 5.15.210+
Fix from $2,300 2026-06-25
Linux Kernel MEDIUM 5.5
CVE-2026-53218

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag nft_exthdr_init…

Fix: 5.10.259 / 5.15.210+
Fix from $1,600 2026-06-25
Linux Kernel MEDIUM 5.5
CVE-2026-53167

In the Linux kernel, the following vulnerability has been resolved: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios FUSE_NOTIFY_RETRIEVE must b…

Fix: 6.18.36 / 7.0.13+
Fix from $1,600 2026-06-25
Linux Kernel HIGH 8.8
CVE-2026-53170

In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialized length cmd_state_init() in…

Fix: 7.0.13+
Fix from $1,950 2026-06-25
Linux Kernel MEDIUM 5.5
CVE-2026-53142

In the Linux kernel, the following vulnerability has been resolved: drm/xe/display: fix oops in suspend/shutdown without display The xe driver keep…

Fix: 6.12.95 / 6.18.36+
Fix from $1,600 2026-06-25
Linux Kernel MEDIUM 5.5
CVE-2026-53082

In the Linux kernel, the following vulnerability has been resolved: net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf sixpack_receive_b…

Fix: 5.10.258 / 5.15.209+
Fix from $1,600 2026-06-24
Linux Kernel MEDIUM 5.5
CVE-2026-53029

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: prevent uninitialized lcn caused by zero len syzbot reported a uninit…

Fix: 7.0.10+
Fix from $1,600 2026-06-24
Linux Kernel MEDIUM 5.5
CVE-2026-52985

In the Linux kernel, the following vulnerability has been resolved: netdevsim: zero initialize struct iphdr in dummy sk_buff Syzbot reports a KMSAN…

Fix: 5.10.258 / 5.15.209+
Fix from $1,600 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-52989

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currentl…

Fix: 5.11 / 5.16+
Fix from $2,300 2026-06-24
Debian Linux MEDIUM 5.3
CVE-2026-56968

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure …

Fix: 2.2.4+
Fix from $1,600 2026-06-23
Threadx Netx Duo HIGH 7.5
CVE-2026-11576

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label,…

Fix: after 6.5.0.202601
Fix from $1,950 2026-06-19
Windows 10 1607 MEDIUM 5.5
CVE-2026-42969

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
7 Zip MEDIUM 6.5
CVE-2026-48101

7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in th…

Fix: 26.01+
Fix from $1,600 2026-06-05