Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-16868
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length pr…
I
No fix yet
MEDIUM 5.3
CVE-2026-70459
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daem…
No fix yet
MEDIUM 5.5
CVE-2026-70317
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-68799
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-62740
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.5
CVE-2026-62709
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.5
CVE-2026-59136
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.5
CVE-2026-59137
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.3
CVE-2026-58247
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensi…
No fix yet
MEDIUM 5.5
CVE-2026-70629
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec…
No fix yet
MEDIUM 5.5
CVE-2026-70630
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (li…
No fix yet
MEDIUM 5.5
CVE-2026-70631
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in li…
No fix yet
MEDIUM 6.5
CVE-2026-66038
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers t…
Ffmpeg
after 8.1.2
HIGH 7.5
CVE-2026-66034
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbit…
Libssh2
after 1.11.1
MEDIUM 5.5
CVE-2026-64220
In the Linux kernel, the following vulnerability has been resolved:
device property: set fwnode->secondary to NULL in fwnode_init()
If a firmware n…
Linux Kernel
5.15.209 / 6.1.175+
HIGH 7.5
CVE-2026-47247
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible…
Libheif
1.22.0+
HIGH 7.5
CVE-2026-16384
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
153.0 / 153.0.0+
HIGH 7.5
CVE-2026-16385
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
153.0 / 153.0.0+
HIGH 7.5
CVE-2026-16386
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
153.0 / 153.0.0+
MEDIUM 5.5
CVE-2026-64130
In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_fr…
Linux Kernel
6.18.34 / 7.0.11+
MEDIUM 5.5
CVE-2026-53379
In the Linux kernel, the following vulnerability has been resolved:
media: i2c: ov8856: free control handler on error in ov8856_init_controls()
The…
Linux Kernel
5.15.209 / 6.1.175+
HIGH 8.2
CVE-2026-60005
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are co…
Nginx Gateway Fabric
1.30.4 / 2.6.7+
MEDIUM 6.5
CVE-2026-58546
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.5
CVE-2026-58533
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.5
CVE-2026-58535
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 6.5
CVE-2026-57982
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 5.5
CVE-2026-57083
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 5.5
CVE-2026-57084
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-56190
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-55949
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20175+