VulnSea

CWE-123

CVEs classified under CWE-123, newest first.

13 CVEsRSS

CVE-2026-94146High· 8.8
today

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in writ…

TwilightBioStar · BIOS Update UtilityEPSS 0.12%via NVD
CVE-2026-94142High· 8.8
today

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of…

TwilightBioStar · Temperature Monitor UtilityEPSS 0.13%via NVD
CVE-2026-94129High· 8.8PoC
today

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results…

MidnightBioStar · VALKYRIE AURORAEPSS 0.12%via NVD
CVE-2026-94128High· 8.8
today

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-…

TwilightBioStar · VIVID LED DJEPSS 0.13%via NVD
CVE-2026-48977High· 7.7
4d ago

OpenSlide is a C library for reading whole slide image files

OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF fi…

Twilightopenslide · openslideEPSS 0.30%via NVD
CVE-2026-20469None
1mo ago

In trusted_mem, there is a possible escalation of privilege due to improper input validation

In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for…

SunlitEPSS 0.11%via NVD
CVE-2026-30121Critical· 9.1
3mo ago

Remotion: arbitrary file write vulnerability

Remotion: arbitrary file write vulnerability

Midnightremotion · remotionEPSS 0.32%via GHSA
CVE-2026-46323High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the…

In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the…

Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-46300High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the result…

Midnightlinux · linux_kernelEPSS 9.3%via NVD
CVE-2026-43284High· 8.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG afte…

Midnightlinux · linux_kernelEPSS 93%via NVD
CVE-2025-14857NonePoC
5mo ago

An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the pro…

An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the pro…

TwilightEPSS 0.24%via NVD
CVE-2025-9900High· 8.8
12mo ago

A flaw was found in Libtiff

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an …

TwilightEPSS 0.79%via NVD
CVE-2025-22225High· 8.2CISA KEV0day
1y ago

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

Abyssalvmware · cloud_foundationEPSS 1.00%via NVD
CWE-123 vulnerabilities (CVEs) · VulnSea