VulnSea

CWE-119

CVEs classified under CWE-119, newest first.

290 CVEsRSS

CVE-2026-54559Medium· 6.9
1w ago

PocketSphinx is a small speech recognizer

PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loader…

▾ Sunlitcmusphinx · pocketsphinxEPSS 0.55%via NVD
CVE-2026-90578Medium· 5.3PoC
2w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local e…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90577Medium· 5.3PoC
2w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffe…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-90572Medium· 4.7PoC
2w ago

A vulnerability was determined in davenardella snap7 up to 1.4.3

A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to mem…

▾ Twilightdavenardella · snap7EPSS 0.42%via NVD
CVE-2026-87931Critical· 9.6
2w ago

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation lead…

▾ MidnightBehavioral Technology Group · Pavlok Behavioral Conditioning WearableEPSS 0.60%via NVD
CVE-2026-87933High· 8.6PoC
2w ago

cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch (CVE-2026-87933)

A flaw was found in DaveGamble cJSON. The `cJSONUtils_MergePatch` function in `cJSON_Utils.c` is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information…

▾ MidnightRed Hat · Red Hat Satellite 6EPSS 0.53%via CSAF
CVE-2026-87444High· 8.8
2w ago

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-87489High· 8.8
2w ago

Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension

Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.38%via NVD
CVE-2026-86716High· 7.3PoC
2w ago

A vulnerability was determined in Cesanta mJS up to 1.26

A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. …

▾ MidnightCesanta · mJSEPSS 0.57%via NVD
CVE-2026-86510Critical· 9.9PoC
2w ago

A vulnerability has been found in D-Link DIR-822A A_101

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The ex…

▾ AbyssalD-Link · DIR-822AEPSS 0.51%via NVD
CVE-2026-79602High· 8.8⚖ disputed
2w ago

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

▾ TwilightXen · XenEPSS 0.17%via NVD
CVE-2026-86514Medium· 6.3PoC
2w ago

A weakness has been identified in vgmstream up to r2117

A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be ca…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-86509Critical· 9.6PoC
2w ago

A flaw has been found in D-Link DIR-895L A1_102b07

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be don…

▾ AbyssalD-Link · DIR-895LEPSS 0.72%via NVD
CVE-2026-86318Medium· 5.3PoC
2w ago

A flaw has been found in java-json-tools json-patch up to 1.13

A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack ma…

▾ Twilightjava-json-tools · json-patchEPSS 0.76%via NVD
CVE-2026-86303High· 7.3PoC
2w ago

A vulnerability was determined in 92181 markdown up to 058cab0cb7fb245a0ccc6b8446963ff8d573558f

A vulnerability was determined in 92181 markdown up to 058cab0cb7fb245a0ccc6b8446963ff8d573558f. Affected by this issue is the function lds of the file md.c. Executing a manipulation can lead to out-of-bounds read. The attack can be exec…

▾ Midnight92181 · markdownEPSS 0.54%via NVD
CVE-2026-86296Critical· 10.0PoC
2w ago

A vulnerability was determined in D-Link DIR-822A A_101

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is poss…

▾ AbyssalD-Link · DIR-822AEPSS 1.4%via NVD
CVE-2026-86288Medium· 6.3PoC
2w ago

A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0

A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argu…

▾ TwilightModelCloud · GPTQModelEPSS 0.51%via NVD
CVE-2026-86227Low· 3.1PoC
3w ago

A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1

A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read. It is possible to initiate t…

▾ Twilightvalkey-io · valkeyEPSS 0.52%via NVD
CVE-2026-86166High· 8.8PoC
3w ago

A vulnerability was determined in Tenda HG10 300001138

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer …

▾ MidnightTenda · HG10EPSS 0.85%via NVD
CVE-2026-86165Critical· 9.8PoC
3w ago

A vulnerability was found in Tenda HG10 300001138

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be …

▾ AbyssalTenda · HG10EPSS 1.1%via NVD
CVE-2026-85522Medium· 5.3
3w ago

A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0

A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argume…

▾ SunlitEPSS 0.86%via NVD
CVE-2026-76757Medium· 5.9
3w ago

Vulnerability in Drupal Gammu SMS Daemon

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

▾ SunlitDrupal · Gammu SMS DaemonEPSS 0.36%via NVD
CVE-2026-76755Medium· 5.9
3w ago

Vulnerability in Drupal Gammu SMS Daemon

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

▾ SunlitDrupal · Gammu SMS DaemonEPSS 0.36%via NVD
CVE-2026-76756Medium· 5.9
3w ago

Vulnerability in Drupal Gammu SMS Daemon

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

▾ SunlitDrupal · Gammu SMS DaemonEPSS 0.36%via NVD
CVE-2026-82587Medium· 4.3
4w ago

A vulnerability was determined in Open5GS up to 2.7.7

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_mm_context_list of the file src/amf/namf-handler.c of the component AMF. This manipulation of the argument ueContext.m…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-82542Critical· 10.0
4w ago

A weakness has been identified in Tenda HG10 300001138

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes b…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-82539Critical· 9.1PoC
4w ago

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory …

▾ AbyssalEPSS 0.83%via NVD
CVE-2026-82479Medium· 6.3
4w ago

A vulnerability was identified in NASA cFS up to 7.0.1

A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overf…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-82478High· 7.3
4w ago

A vulnerability was determined in NASA Trick 19.6.0

A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socke…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-77946Critical· 10.0
1mo ago

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulatio…

▾ MidnightEPSS 1.0%via NVD
CWE-119 vulnerabilities (CVEs) — page 4 · VulnSea