VulnSea

CWE-122

CVEs classified under CWE-122, newest first.

870 CVEsRSS

CVE-2026-68844High· 7.8
2w ago

Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.

Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-68841High· 7.8
2w ago

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-68839Critical· 9.8
2w ago

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 1.0%via NVD
CVE-2026-68833Medium· 6.8
2w ago

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.44%via NVD
CVE-2026-68828High· 8.8
2w ago

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.84%via NVD
CVE-2026-68827High· 8.0
2w ago

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.77%via NVD
CVE-2026-68787High· 7.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.33%via NVD
CVE-2026-68786High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.91%via NVD
CVE-2026-68785Medium· 4.9
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Sunlitmicrosoft · sql_server_2017EPSS 1.1%via NVD
CVE-2026-68775High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.91%via NVD
CVE-2026-67643Critical· 9.8
2w ago

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · sql_server_2022EPSS 0.97%via NVD
CVE-2026-67642High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2025EPSS 0.91%via NVD
CVE-2026-67639High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.91%via NVD
CVE-2026-67638High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2025EPSS 0.91%via NVD
CVE-2026-67631Critical· 9.8
2w ago

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · sql_server_2017EPSS 0.97%via NVD
CVE-2026-67388High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.91%via NVD
CVE-2026-67384High· 8.8
2w ago

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.91%via NVD
CVE-2026-67381High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.91%via NVD
CVE-2026-67380High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.91%via NVD
CVE-2026-67373High· 8.8
2w ago

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2025EPSS 0.91%via NVD
CVE-2026-62744High· 8.8
2w ago

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.84%via NVD
CVE-2026-58600High· 7.8
2w ago

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · HEVC Video ExtensionsEPSS 0.48%via NVD
CVE-2026-62810High· 7.8
2w ago

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.34%via NVD
CVE-2026-58599High· 7.8
2w ago

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · HEVC Video ExtensionsEPSS 0.48%via NVD
CVE-2026-79377High· 7.5
2w ago

A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.

A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.

▾ TwilightEPSS 0.53%via NVD
CVE-2026-77102High· 7.5
2w ago

CommServe contained a heap-based buffer overflow issue affecting service availability

CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

▾ Twilightcommvault · commvaultEPSS 0.46%via NVD
CVE-2026-20502High· 8.4
2w ago

In vdec, there is a possible out of bounds write due to a missing bounds check

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…

▾ Twilightmediatek · mt2718_firmwareEPSS 0.13%via NVD
CVE-2026-20501High· 8.4
2w ago

In vdec, there is a possible out of bounds write due to a heap buffer overflow

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…

▾ Twilightmediatek · mt2718_firmwareEPSS 0.13%via NVD
CVE-2026-86142Medium· 6.9
3w ago

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

▾ Sunlitxmlsoft · libxml2EPSS 0.16%via NVD
CVE-2026-81665High· 7.5
3w ago

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds.…

▾ TwilightRed Hat · corosyncEPSS 0.35%via NVD
CWE-122 vulnerabilities (CVEs) — page 14 · VulnSea