VulnSea

CWE-120

CVEs classified under CWE-120, newest first.

283 CVEsRSS

CVE-2026-58823High· 7.8
2w ago

In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check

In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-55290Low· 3.3
2w ago

In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check

In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for …

▾ Sunlitgoogle · androidEPSS 0.09%via NVD
CVE-2026-55285High· 7.8
2w ago

In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check

In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-55277High· 8.0
2w ago

In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check

In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. Use…

▾ Twilightgoogle · androidEPSS 0.16%via NVD
CVE-2026-49895Low· 3.5
2w ago

In get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check

In get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privile…

▾ Sunlitgoogle · androidEPSS 0.13%via NVD
CVE-2026-49884High· 7.8
2w ago

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58839High· 7.8
2w ago

In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow

In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-44756Critical· 10.0
2w ago

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentiall…

▾ MidnightSAP_SE · SAP Extended Passport (EPP) ProcessingEPSS 0.68%via NVD
CVE-2026-86318Medium· 5.3PoC
2w ago

A flaw has been found in java-json-tools json-patch up to 1.13

A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack ma…

▾ Twilightjava-json-tools · json-patchEPSS 0.76%via NVD
CVE-2026-86166High· 8.8PoC
3w ago

A vulnerability was determined in Tenda HG10 300001138

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer …

▾ MidnightTenda · HG10EPSS 0.85%via NVD
CVE-2026-86165Critical· 9.8PoC
3w ago

A vulnerability was found in Tenda HG10 300001138

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be …

▾ AbyssalTenda · HG10EPSS 1.1%via NVD
CVE-2026-86140High· 8.0
3w ago

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

▾ Twilightxmlsoft · libxml2EPSS 0.21%via NVD
CVE-2026-75438High· 7.5PoC
3w ago

Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function

Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function

▾ MidnightEPSS 0.82%via NVD
CVE-2026-52295Low· 2.9
3w ago

FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.

FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.18%via NVD
CVE-2026-83596High· 8.8
3w ago

A flaw was found in WebKitGTK

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

▾ TwilightWebKit · webkitEPSS 0.29%via NVD
CVE-2026-82542Critical· 10.0
4w ago

A weakness has been identified in Tenda HG10 300001138

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes b…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-82479Medium· 6.3
4w ago

A vulnerability was identified in NASA cFS up to 7.0.1

A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overf…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-75124High· 7.5
1mo ago

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteei…

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteei…

▾ TwilightEPSS 0.71%via NVD
CVE-2026-71399High· 7.8
1mo ago

Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue …

▾ Twilightadobe · xdEPSS 0.34%via NVD
CVE-2026-64705Medium· 5.5PoC
1mo ago

A buffer overflow was addressed with improved bounds checking

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or wri…

▾ Twilightapple · macosEPSS 0.17%via NVD
CVE-2026-52491High· 8.4
1mo ago

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

▾ TwilightRed Hat · Red Hat Enterprise Linux 7EPSS 0.19%via NVD
CVE-2026-52489High· 7.8
1mo ago

Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function

Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function

▾ TwilightEPSS 0.19%via NVD
CVE-2026-68768Medium· 6.1
1mo ago

hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c

hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the usernam…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-55194Critical· 9.8PoC
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint …

▾ Abyssalfreerdp · freerdpEPSS 0.62%via NVD
CVE-2026-63633Critical· 9.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM…

▾ Midnightfreerdp · freerdpEPSS 0.62%via NVD
CVE-2026-55193High· 8.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.47%via NVD
CVE-2026-70415High· 8.1
1mo ago

Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC

Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-65332Medium· 4.3⚖ disputed
1mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content m…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-65338Medium· 4.3⚖ disputed
1mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may le…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-65334Medium· 4.3⚖ disputed
1mo ago

A memory corruption issue was addressed with improved state management

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted w…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CWE-120 vulnerabilities (CVEs) — page 4 · VulnSea