VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-55402Medium· 5.9
1mo ago

CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57

CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.

▾ Sunlitabsolute · secure_accessEPSS 0.40%via NVD
CVE-2026-73434Medium· 6.1
1mo ago

A flaw was found in GStreamer gst-plugins-good (avidemux)

A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled …

▾ Sunlitgstreamer · gstreamerEPSS 0.15%via NVD
CVE-2026-19654High· 7.5
1mo ago

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confide…

▾ Twilightrsyslog · rsyslogEPSS 0.47%via NVD
GHSA-jwjp-4649-v8jpHigh· 7.5
1mo ago

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

▾ TwilightSIPSorcery · SIPSorceryvia GHSA
CVE-2026-50062High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing speciall…

▾ Twilightsiemens · solid_edge_se2025EPSS 0.15%via NVD
CVE-2026-50058High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing speciall…

▾ Twilightsiemens · solid_edge_se2025EPSS 0.15%via NVD
CVE-2026-50063High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing speciall…

▾ Twilightsiemens · solid_edge_se2025EPSS 0.15%via NVD
CVE-2026-73242Critical· 9.1⚖ disputed
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using …

▾ Midnightfreerdp · freerdpEPSS 0.40%via NVD
CVE-2026-73075None
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-73067None
1mo ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run, after which…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-70328Medium· 6.5
1mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.92%via CVEORG
CVE-2026-70327Medium· 6.5
1mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.92%via CVEORG
CVE-2026-70315Medium· 5.5
1mo ago

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.43%via CVEORG
CVE-2026-70310Medium· 5.5
1mo ago

Microsoft Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.43%via CVEORG
CVE-2026-61933Medium· 5.5
1mo ago

Windows DWM Core Library Information Disclosure Vulnerability

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 11 Version 24H2EPSS 0.40%via CVEORG
CVE-2026-62745Medium· 6.5
1mo ago

Windows DHCP Server Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ SunlitMicrosoft · Windows Server 2012EPSS 0.54%via CVEORG
CVE-2026-62742Medium· 6.5
1mo ago

Windows DHCP Server Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ SunlitMicrosoft · Windows Server 2012EPSS 0.54%via CVEORG
CVE-2026-62876High· 7.8
1mo ago

Windows Win32k Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62796Medium· 5.5
1mo ago

Windows NTFS Information Disclosure Vulnerability

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-63521Medium· 5.5
1mo ago

Microsoft Office Word Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.43%via CVEORG
CVE-2026-63517Medium· 5.5
1mo ago

Microsoft Office Graphics Component Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-63515High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-68808Medium· 5.5
1mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-68802Medium· 5.5
1mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-68793High· 7.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-65787High· 7.8
1mo ago

Desktop Window Manager Elevation of Privilege Vulnerability

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-65786High· 7.8
1mo ago

Desktop Window Manager Elevation of Privilege Vulnerability

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-65784Medium· 5.5
1mo ago

Windows NTFS Information Disclosure Vulnerability

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-65662Medium· 5.5
1mo ago

Windows GDI Information Disclosure Vulnerability

Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-68813Medium· 5.5
1mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CWE-125 vulnerabilities (CVEs) — page 17 · VulnSea