VulnSea

CWE-122

CVEs classified under CWE-122, newest first.

870 CVEsRSS

CVE-2026-62886High· 7.8
1mo ago

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · visual_studio_2022EPSS 0.47%via NVD
CVE-2026-62871High· 7.8
1mo ago

.NET Elevation of Privilege Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · .NET 8.0EPSS 0.47%via CVEORG
CVE-2026-19259Medium· 5.3
1mo ago

A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1

A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workf…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-18497High· 7.1
1mo ago

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb…

▾ TwilightEPSS 0.19%via NVD
CVE-2026-70638High· 7.8PoC
1mo ago

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflo…

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflo…

▾ Midnightggml · llama.cppEPSS 0.23%via NVD
CVE-2026-19156High· 7.5
1mo ago

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security sev…

▾ Twilightgoogle · chromeEPSS 0.25%via NVD
CVE-2026-10849High· 8.2
1mo ago

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c)

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the receive…

▾ Twilightzephyrproject · zephyrEPSS 0.51%via NVD
CVE-2026-20480None
1mo ago

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS1096002…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-20465None
1mo ago

In wlan AP driver, there is a possible out of bounds write due to a missing bounds check

In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not neede…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-68580High· 7.5
1mo ago

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attack…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-67305High· 8.8
1mo ago

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination b…

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination b…

▾ Twilightfreerdp · freerdpEPSS 0.77%via NVD
CVE-2026-54715None
1mo ago

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing ver…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-17680Critical· 9.6
1mo ago

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security seve…

▾ Midnightgoogle · chromeEPSS 0.37%via NVD
CVE-2026-14266High· 7.80dayPoC
2mo ago

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this …

▾ Abyssal7-zip · 7-zipEPSS 0.74%via NVD
CVE-2026-16463High· 7.8
2mo ago

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in th…

▾ TwilightEPSS 0.28%via NVD
GHSA-76q6-2p6h-xjqrLow· 1.8
2mo ago

ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title

ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-56165Critical· 9.8
2mo ago

Microsoft Account Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Microsoft AccountEPSS 0.97%via CVEORG
CVE-2026-54696Low· 3.7
2mo ago

Ruby json: JSON generator heap buffer overflow when streaming to an IO

Ruby json: JSON generator heap buffer overflow when streaming to an IO

▾ Sunlitjson · jsonEPSS 0.38%via GHSA
CVE-2026-53994High· 7.5
2mo ago

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of …

▾ TwilightEPSS 0.75%via NVD
CVE-2026-11826High· 8.8
2mo ago

OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp

OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. I…

▾ TwilightEPSS 0.75%via NVD
CVE-2026-16118High· 7.1PoC
2mo ago

A flaw was found in xdgmime

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data …

▾ Midnightxdg · xdgmimeEPSS 0.27%via NVD
CVE-2026-44251Medium· 6.5
2mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to cras…

▾ Sunlitwazuh · wazuhEPSS 0.44%via NVD
CVE-2026-40106Medium· 4.7
2mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Wi…

▾ Sunlitwazuh · wazuhEPSS 0.13%via NVD
CVE-2026-50012Medium· 5.5
2mo ago

Squid is a caching proxy for the Web

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest'…

▾ Sunlitsquid-cache · squidEPSS 2.7%via NVD
CVE-2026-54993High· 7.8
2mo ago

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.47%via CVEORG
CVE-2026-54992High· 8.4PoC
2mo ago

Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.34%via CVEORG
CVE-2026-54990Critical· 9.8
2mo ago

Remote Desktop Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows 11 Version 24H2EPSS 0.82%via CVEORG
CVE-2026-54987High· 7.8
2mo ago

Windows Overlay Filter Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-54986High· 7.8
2mo ago

Windows Win32k Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-54132Medium· 6.8
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.44%via CVEORG
CWE-122 vulnerabilities (CVEs) — page 20 · VulnSea