VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2026-64066Critical· 9.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause on subreq failure Fix netfs_read_to_pagecache() so that it pauses the generation of new subrequests if an already-issued …

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause on subreq failure Fix netfs_read_to_pagecache() so that it pauses the generation of new subrequests if an already-issued …

▾ Midnightlinux · linux_kernelEPSS 0.65%via NVD
CVE-2026-47729Medium· 6.5PoC
2mo ago

Squid is a caching proxy for the Web

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date i…

▾ Twilightsquid-cache · squidEPSS 2.4%via NVD
CVE-2026-15030Medium· 5.6
2mo ago

Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL reque…

Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL reque…

▾ SunlitASUS · System Control Interface v3EPSS 0.14%via NVD
CVE-2026-12478Medium· 4.8PoC
2mo ago

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked fram…

▾ TwilightRed Hat · libsoup3EPSS 0.39%via NVD
CVE-2026-54991High· 7.8
2mo ago

Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.21%via CVEORG
CVE-2026-54111High· 7.0
2mo ago

Universal Print Management Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-54996High· 7.0
2mo ago

Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-54988Medium· 6.1
2mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.46%via CVEORG
CVE-2026-57979Medium· 6.5
2mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-56193High· 7.1
2mo ago

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.50%via CVEORG
CVE-2026-58614Medium· 5.5
2mo ago

Windows Kernel Security Feature Bypass Vulnerability

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-58609High· 7.8
2mo ago

Windows Graphics Component Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-50300Medium· 5.5
2mo ago

Windows DWM Core Library Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-50377Medium· 5.5
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.41%via CVEORG
CVE-2026-50428High· 7.1
2mo ago

Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability

Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

▾ TwilightMicrosoft · Windows 11 version 26H1EPSS 0.41%via CVEORG
CVE-2026-50388High· 7.8
2mo ago

Windows NTFS Remote Code Execution Vulnerability

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-50463High· 7.5
2mo ago

Windows Kernel Information Disclosure Vulnerability

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 1.0%via CVEORG
CVE-2026-50437Medium· 5.5
2mo ago

Windows DWM Core Library Information Disclosure Vulnerability

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-50422High· 7.8
2mo ago

Windows NTFS Elevation of Privilege Vulnerability

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50401Medium· 5.5
2mo ago

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.40%via CVEORG
CVE-2026-50399High· 7.8
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.33%via CVEORG
CVE-2026-50470High· 7.5
2mo ago

Windows Network Policy Server SNMP Information Disclosure Vulnerability

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.0%via CVEORG
CVE-2026-50453Medium· 6.1
2mo ago

Windows USB Audio Class Driver Information Disclosure Vulnerability

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.51%via CVEORG
CVE-2026-50429High· 8.2
2mo ago

Windows Kernel Information Disclosure Vulnerability

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.1%via CVEORG
CVE-2026-50420Medium· 6.2
2mo ago

HTTP.sys Information Disclosure Vulnerability

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 11 Version 24H2EPSS 0.41%via CVEORG
CVE-2026-50498High· 7.8
2mo ago

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.36%via CVEORG
CVE-2026-50491High· 7.0
2mo ago

Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability

Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.28%via CVEORG
CVE-2026-50496High· 7.5
2mo ago

Windows Network Policy Server SNMP Information Disclosure Vulnerability

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-50670High· 8.8
2mo ago

Windows Win32k Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-55023Medium· 5.5
2mo ago

Microsoft Office Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.60%via CVEORG
CWE-125 vulnerabilities (CVEs) — page 21 · VulnSea