VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-68779Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · sql_server_2017EPSS 1.00%via NVD
CVE-2026-68778Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · sql_server_2017EPSS 1.00%via NVD
CVE-2026-68777Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · sql_server_2017EPSS 1.00%via NVD
CVE-2026-67645Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · sql_server_2017EPSS 1.00%via NVD
CVE-2026-67636Critical· 9.0
2w ago

Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.

Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · sql_server_2019EPSS 0.71%via NVD
CVE-2026-67633Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.

▾ Sunlitmicrosoft · sql_server_2017EPSS 1.1%via NVD
CVE-2026-67630Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft SQL Server 2017 (CU 31)EPSS 0.99%via NVD
CVE-2026-67629Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft SQL Server 2017 (CU 31)EPSS 0.99%via NVD
CVE-2026-67624Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft SQL Server 2019 (CU 32)EPSS 0.99%via NVD
CVE-2026-67389Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · sql_server_2022EPSS 1.00%via NVD
CVE-2026-67369Medium· 6.5
2w ago

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · sql_server_2025EPSS 1.00%via NVD
CVE-2026-62706High· 8.8
2w ago

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.82%via NVD
CVE-2026-56198High· 7.8
2w ago

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.34%via NVD
CVE-2026-82066Medium· 4.3
2w ago

A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server

A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can trigger the security issue through crafted query operations, causing the…

▾ Sunlitmongodb · mongodbEPSS 0.39%via NVD
CVE-2026-86714Medium· 5.4
2w ago

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read be…

▾ SunlitPX4 · PX4-AutopilotEPSS 0.33%via NVD
CVE-2026-86303High· 7.3PoC
2w ago

A vulnerability was determined in 92181 markdown up to 058cab0cb7fb245a0ccc6b8446963ff8d573558f

A vulnerability was determined in 92181 markdown up to 058cab0cb7fb245a0ccc6b8446963ff8d573558f. Affected by this issue is the function lds of the file md.c. Executing a manipulation can lead to out-of-bounds read. The attack can be exec…

▾ Midnight92181 · markdownEPSS 0.54%via NVD
CVE-2026-86288Medium· 6.3PoC
2w ago

A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0

A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argu…

▾ TwilightModelCloud · GPTQModelEPSS 0.51%via NVD
CVE-2026-20518Medium· 4.4
2w ago

In geniezone, there is a possible information disclosure due to a missing bounds check

In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploi…

▾ SunlitEPSS 0.12%via NVD
CVE-2026-86227Low· 3.1PoC
3w ago

A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1

A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read. It is possible to initiate t…

▾ Twilightvalkey-io · valkeyEPSS 0.52%via NVD
CVE-2026-31912Medium· 5.5
3w ago

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular …

▾ SunlitThe Tcpdump Group · libpcapEPSS 0.14%via NVD
CVE-2026-18238Medium· 5.0
3w ago

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process…

▾ SunlitThe Tcpdump Group · libpcapEPSS 0.18%via NVD
CVE-2026-0799High· 8.7
3w ago

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use c…

▾ TwilightThe Tcpdump Group · libpcapEPSS 0.11%via NVD
CVE-2025-15647Medium· 5.5PoC
3w ago

CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles

CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles. Attackers can supply nearly-degenera…

▾ Twilightartem-ogre · CDTEPSS 0.28%via NVD
CVE-2025-15614Low· 3.3
3w ago

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated h…

▾ SunlitGenivia · ugrepEPSS 0.12%via NVD
CVE-2026-86137Low· 2.9
3w ago

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

▾ Sunlitxmlsoft · libxml2EPSS 0.18%via NVD
CVE-2026-85698Medium· 5.5
3w ago

Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation

Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modifi…

▾ Sunlittursodatabase · tursoEPSS 0.17%via NVD
CVE-2026-85769Medium· 6.5PoC
3w ago

A flaw was found in libtpms, a library that provides software TPM 2.0 emulation

A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized sk…

▾ TwilightRed Hat · libtpmsEPSS 0.42%via NVD
CVE-2026-16660Medium· 5.3
3w ago

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

▾ Sunlitibm · db2_mirror_for_iEPSS 0.36%via NVD
CVE-2026-85522Medium· 5.3
3w ago

A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0

A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argume…

▾ SunlitEPSS 0.86%via NVD
CVE-2026-85505High· 7.5
3w ago

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which h…

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which h…

▾ TwilightFreeIPMI · FreeIPMIEPSS 0.35%via NVD
CWE-125 vulnerabilities (CVEs) — page 14 · VulnSea