VulnSea

CWE-122

CVEs classified under CWE-122, newest first.

870 CVEsRSS

CVE-2026-55194Critical· 9.8PoC
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint …

▾ Abyssalfreerdp · freerdpEPSS 0.62%via NVD
CVE-2026-63633Critical· 9.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM…

▾ Midnightfreerdp · freerdpEPSS 0.62%via NVD
CVE-2026-55193High· 8.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.47%via NVD
CVE-2026-55191Critical· 9.8
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c wit…

▾ Midnightfreerdp · freerdpEPSS 0.83%via NVD
CVE-2026-52834High· 7.3
1mo ago

jxl-oxide is a pure Rust implementation of a JPEG XL decoder

jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid…

▾ Twilightjxl-grid · jxl-gridEPSS 0.17%via NVD
CVE-2026-68765Medium· 6.1
1mo ago

hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field t…

hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field t…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-67868Critical· 9.8
1mo ago

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.

▾ MidnightEPSS 1.1%via NVD
CVE-2026-72970High· 8.3
1mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.73%via CVEORG
CVE-2026-18368None
1mo ago

In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data

In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthenticated attacker with access to the affected service could trigger a heap-based buffer ove…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-19385High· 8.8
1mo ago

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, …

▾ Twilightpostgresql · postgresqlEPSS 0.43%via NVD
CVE-2026-14676High· 8.8
1mo ago

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor ve…

▾ Twilightpostgresql · postgresqlEPSS 0.44%via NVD
CVE-2026-14670High· 8.8
1mo ago

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, …

▾ Twilightpostgresql · postgresqlEPSS 0.44%via NVD
CVE-2026-14669High· 8.8PoC
1mo ago

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreS…

▾ Midnightpostgresql · postgresqlEPSS 0.66%via NVD
CVE-2026-14664High· 8.8
1mo ago

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, bu…

▾ Twilightpostgresql · postgresqlEPSS 0.44%via NVD
CVE-2026-19004High· 8.1
1mo ago

An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure

An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database …

▾ Twilightmongodb · bi_connector_odbc_driverEPSS 0.50%via NVD
CVE-2026-73242Critical· 9.1⚖ disputed
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using …

▾ Midnightfreerdp · freerdpEPSS 0.40%via NVD
CVE-2026-73072High· 7.8PoC
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_S…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.13%via NVD
CVE-2026-70330Medium· 6.7
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.34%via CVEORG
CVE-2026-70304Medium· 6.7
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.34%via CVEORG
CVE-2026-70347High· 7.8
1mo ago

Windows Installer Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-70345High· 7.8
1mo ago

Windows Installer Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-71331High· 8.1
1mo ago

Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.71%via CVEORG
CVE-2026-70130High· 8.4
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.34%via CVEORG
CVE-2026-62695High· 7.8
1mo ago

Windows Storage Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.33%via CVEORG
CVE-2026-62688High· 7.8
1mo ago

Windows MIDI Service Module Elevation of Privileges Vulnerability

Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.33%via CVEORG
CVE-2026-62785High· 8.8
1mo ago

Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.82%via CVEORG
CVE-2026-62783High· 7.8
1mo ago

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-62758High· 7.8
1mo ago

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62754High· 7.8
1mo ago

Windows Kerberos Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62753High· 7.0
1mo ago

Windows HTTP.sys Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CWE-122 vulnerabilities (CVEs) — page 16 · VulnSea