Vulnerability index

Browse CVEs

744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
Chrome MEDIUM 6.5
CVE-2026-11089

Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain poten…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Libxls MEDIUM 5.3
CVE-2026-26825

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() a…

No fix yet
Fix from $1,600 2026-06-03
Linux Kernel MEDIUM 5.5
CVE-2026-46257

In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sp804: Fix an Oops when read_current_timer is called o…

Fix: 6.19.4+
Fix from $1,600 2026-06-03
Linux Kernel MEDIUM 5.5
CVE-2026-46186

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: validate rx pkt_type header length virtbt_rx_handle() rea…

Fix: 5.15.209 / 6.1+
Fix from $1,600 2026-05-28
Linux Kernel MEDIUM 5.5
CVE-2026-46167

In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl Just like in a pr…

Fix: 5.10.258 / 5.15.209+
Fix from $1,600 2026-05-28
Linux Kernel MEDIUM 5.5
CVE-2026-46169

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value by validating catalog record size Syzbot reported a K…

Fix: 6.6.140 / 6.12.88+
Fix from $1,600 2026-05-28
Linux Kernel MEDIUM 5.5
CVE-2026-46139

In the Linux kernel, the following vulnerability has been resolved: smb: client: use kzalloc to zero-initialize security descriptor buffer Commit 6…

Fix: 6.12.88 / 6.14+
Fix from $1,600 2026-05-28
Linux Kernel MEDIUM 5.5
CVE-2026-46132

In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfin…

Fix: 5.10.258 / 5.15.209+
Fix from $1,600 2026-05-28
Unclassified HIGH 7.1
CVE-2026-47272

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only …

Mitigation only
Fix from $1,950 2026-05-27
Linux Kernel MEDIUM 5.5
CVE-2026-45886

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_xdp_store_bytes proto for read-only arg While making some maps in …

Fix: 6.1.165 / 6.6.128+
Fix from $1,600 2026-05-27
Linux Kernel MEDIUM 5.5
CVE-2025-71311

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value…

Fix: 6.12.75 / 6.18.14+
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.5
CVE-2026-32814

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false …

Mitigation only
Fix from $1,600 2026-05-19
Ws HIGH 7.5
CVE-2026-45736

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized me…

Fix: 8.20.1+
Fix from $1,950 2026-05-15
Unclassified MEDIUM 6.9
CVE-2025-48513

Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory result…

Mitigation only
Fix from $1,600 2026-05-15
365 Apps HIGH 8.4
CVE-2026-40364

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-05-12
Linux Kernel MEDIUM 5.5
CVE-2026-43472

In the Linux kernel, the following vulnerability has been resolved: unshare: fix unshare_fs() handling There's an unpleasant corner case in unshare…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43474

In the Linux kernel, the following vulnerability has been resolved: fs: init flags_valid before calling vfs_fileattr_get syzbot reported a uninit-v…

Fix: 6.18.19 / 6.19.9+
Fix from $1,600 2026-05-08
Linux Kernel HIGH 7.8
CVE-2026-43456

In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave() kernel BUG at net/core/skb…

Fix: 6.12.78 / 6.18.19+
Fix from $1,950 2026-05-08
Linux Kernel HIGH 7.5
CVE-2026-43405

In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fix…

Fix: 5.15.203 / 6.1.167+
Fix from $1,950 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43349

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid uninit-value access in f2fs_sanity_check_node_footer syzbot …

Fix: 6.18.25 / 7.0+
Fix from $1,600 2026-05-08
Linux Kernel HIGH 8.3
CVE-2026-43291

In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Fix parameter validation for packet data Since commit 9c328f5474…

Fix: 5.15.202 / 6.1.165+
Fix from $1,950 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43288

In the Linux kernel, the following vulnerability has been resolved: ext4: move ext4_percpu_param_init() before ext4_mb_init() When running `kvm-xfs…

Fix: 6.6.128 / 6.12.75+
Fix from $1,600 2026-05-08
Linux Kernel MEDIUM 5.5
CVE-2026-43221

In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: initialise event handler read bytes IPMB doesn't use i2c reads, but…

Fix: 6.1.165 / 6.6.128+
Fix from $1,600 2026-05-06
Linux Kernel MEDIUM 5.5
CVE-2026-43160

In the Linux kernel, the following vulnerability has been resolved: mfd: macsmc: Initialize mutex Initialize struct apple_smc's mutex in apple_smc_…

Fix: 6.18.16 / 6.19.6+
Fix from $1,600 2026-05-06
Linux Kernel HIGH 8.6
CVE-2026-43139

In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not …

Fix: 5.10.252 / 5.15.202+
Fix from $1,950 2026-05-06
Linux Kernel MEDIUM 5.5
CVE-2026-43035

In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to pr…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-05-01
Linux Kernel MEDIUM 5.5
CVE-2026-43036

In the Linux kernel, the following vulnerability has been resolved: net: use skb_header_pointer() for TCPv4 GSO frag_off check Syzbot reported a KM…

Fix: 6.12.81 / 6.18.22+
Fix from $1,600 2026-05-01
Linux Kernel HIGH 7.8
CVE-2026-31693

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we …

Fix: 6.6.128 / 6.12.75+
Fix from $1,950 2026-04-30
Vllm MEDIUM 5.6
CVE-2026-7141

A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of th…

Fix: after 0.19.0
Fix from $1,600 2026-04-27
Linux Kernel MEDIUM 5.5
CVE-2026-31621

In the Linux kernel, the following vulnerability has been resolved: bnge: return after auxiliary_device_uninit() in error path When auxiliary_devic…

Fix: 6.19.14 / 7.0.1+
Fix from $1,600 2026-04-24