VulnSea

CWE-122

CVEs classified under CWE-122, newest first.

870 CVEsRSS

CVE-2026-42992High· 7.5
3mo ago

Remote Desktop Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.61%via CVEORG
CVE-2026-44811High· 7.8
3mo ago

Windows DWM Core Library Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 26H1EPSS 0.33%via CVEORG
CVE-2026-44808High· 7.8
3mo ago

Windows DWM Core Library Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 26H1EPSS 0.33%via CVEORG
CVE-2026-44799High· 7.5
3mo ago

Remote Desktop Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Remote Desktop client for Windows DesktopEPSS 0.61%via CVEORG
CVE-2026-42993High· 7.5
3mo ago

Remote Desktop Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.61%via CVEORG
CVE-2026-44814Medium· 5.5
3mo ago

Windows DWM Core Library Information Disclosure Vulnerability

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 11 version 26H1EPSS 0.40%via CVEORG
CVE-2026-42980High· 7.8PoC
3mo ago

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-42536High· 7.5PoC
3mo ago

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

▾ Midnightapache · http_serverEPSS 2.7%via NVD
CVE-2026-34355High· 7.5
3mo ago

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

▾ Twilightapache · http_serverEPSS 2.7%via NVD
CVE-2026-0100High· 7.8
3mo ago

In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow

In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit…

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-44421High· 8.8
4mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it …

▾ Twilightfreerdp · freerdpEPSS 0.72%via NVD
CVE-2026-44420High· 8.8
4mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a t…

▾ Twilightfreerdp · freerdpEPSS 0.85%via NVD
CVE-2026-25713High· 7.8
4mo ago

A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01)

A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted media file that contains ID3v2 tags can lead to arbitrary code execution. An attacker can provi…

▾ Twilightmediaarea · mediainfolibEPSS 0.22%via NVD
CVE-2026-40033High· 8.8
4mo ago

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16…

▾ Twilightfreerdp · freerdpEPSS 1.1%via NVD
CVE-2026-9149Medium· 6.5
4mo ago

A flaw was found in libsolv

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allo…

▾ Sunlitopensuse · libsolvEPSS 0.57%via NVD
CVE-2026-8631Critical· 9.8
4mo ago

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups p…

▾ Midnighthp · linux_imaging_and_printingEPSS 1.1%via NVD
CVE-2026-22554High· 7.8
4mo ago

A heap-based buffer overflow vulnerability exists in the Channel Splitting functionality of MediaInfoLib (version(s): 26.01)

A heap-based buffer overflow vulnerability exists in the Channel Splitting functionality of MediaInfoLib (version(s): 26.01). A specially crafted .riff file can lead to arbitrary code execution. An attacker can provide a malicious file t…

▾ Twilightmediaarea · mediainfolibEPSS 0.25%via NVD
CVE-2026-45584High· 8.1PoC
4mo ago

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · malware_protection_engineEPSS 0.71%via NVD
CVE-2026-8711High· 8.1
4mo ago

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGIN…

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGIN…

▾ Twilightf5 · njsEPSS 0.79%via NVD
CVE-2026-42945High· 8.1PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…

▾ Midnightf5 · dosEPSS 3.4%via NVD
CVE-2026-34687High· 7.8
4mo ago

Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti…

▾ Twilightadobe · illustratorEPSS 0.34%via NVD
CVE-2026-34642High· 7.8
4mo ago

After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac…

▾ Twilightadobe · after_effectsEPSS 0.34%via NVD
CVE-2026-8261Medium· 5.9
4mo ago

A vulnerability was determined in Squirrel up to 3.2

A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. Th…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-4892High· 8.4
4mo ago

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

▾ TwilightEPSS 0.31%via NVD
CVE-2026-6210None
4mo ago

A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* wi…

A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* wi…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-28780Critical· 9.8
4mo ago

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker …

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker …

▾ Midnightapache · http_serverEPSS 1.6%via NVD
CVE-2026-25243High· 8.8PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted seri…

▾ Midnightredis · redisEPSS 3.7%via NVD
CVE-2026-6846High· 7.8
5mo ago

A flaw was found in binutils

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this…

▾ Twilightgnu · binutilsEPSS 0.20%via NVD
CVE-2026-26180High· 7.8
5mo ago

Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-32093High· 7.0
5mo ago

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CWE-122 vulnerabilities (CVEs) — page 26 · VulnSea