VulnSea

CWE-126

CVEs classified under CWE-126, newest first.

89 CVEsRSS

CVE-2026-76885Low· 3.1
1mo ago

Buffer Over-read in Wireshark

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ SunlitWireshark Foundation · WiresharkEPSS 0.33%via CVEORG
CVE-2026-76884Low· 3.1PoC
1mo ago

Buffer Over-read in Wireshark

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ TwilightWireshark Foundation · WiresharkEPSS 0.33%via CVEORG
CVE-2026-69550Medium· 6.5
1mo ago

Windows App for Mac Information Disclosure Vulnerability

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows App for MacEPSS 0.92%via CVEORG
CVE-2026-65936None
1mo ago

A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.  See vulnerability B-E4 in the related paper below.

A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.  See vulnerability B-E4 in the related paper below.

▾ SunlitEPSS 0.25%via NVD
CVE-2026-65933None
1mo ago

A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information

A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.

▾ SunlitEPSS 0.25%via NVD
CVE-2026-18024Medium· 4.3
1mo ago

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instanc…

▾ Sunlitpostgresql · postgresqlEPSS 0.19%via NVD
CVE-2026-14678Medium· 4.3
1mo ago

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQ…

▾ Sunlitpostgresql · postgresqlEPSS 0.19%via NVD
CVE-2026-62746Medium· 5.5
1mo ago

Win32k Information Disclosure Vulnerability

Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-68819Medium· 5.9
1mo ago

Windows Network File System Denial of Service Vulnerability

Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.98%via CVEORG
CVE-2026-62793Medium· 5.5
1mo ago

Windows NTFS Information Disclosure Vulnerability

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-62730Medium· 5.5
1mo ago

Windows Wired AutoConfig Service Information Disclosure Vulnerability

Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-64905High· 7.8
1mo ago

Microsoft Office Word Remote Code Execution Vulnerability

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-65794Medium· 6.5
1mo ago

Windows SMB Client Information Disclosure Vulnerability

Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-61350Medium· 4.6
1mo ago

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.47%via NVD
CVE-2026-61347Medium· 5.5
1mo ago

Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.

Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.40%via NVD
CVE-2026-66312Medium· 6.5
1mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 1.1%via CVEORG
CVE-2026-50372High· 7.0
2mo ago

Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability

Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-50341Medium· 5.5
2mo ago

Windows NTFS Information Disclosure Vulnerability

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-50445Medium· 6.5
2mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-50435High· 7.8
2mo ago

Windows Overlay Filter Elevation of Privilege Vulnerability

Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50402High· 7.8PoC
2mo ago

NTFS Elevation of Privilege Vulnerability

Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50383Medium· 6.1
2mo ago

Windows Print Spooler Information Disclosure Vulnerability

Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.40%via CVEORG
CVE-2026-50475Medium· 5.5
2mo ago

Windows Kernel Information Disclosure Vulnerability

Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.38%via CVEORG
CVE-2026-50485Medium· 4.5
2mo ago

Windows Hyper-V Denial of Service Vulnerability

Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.66%via CVEORG
CVE-2026-50504Medium· 6.5
2mo ago

Windows Remote Desktop Client Information Disclosure Vulnerability

Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-55036High· 7.8
2mo ago

Microsoft Excel Remote Code Execution Vulnerability

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-50468Medium· 6.5
2mo ago

Microsoft SQL Server Information Disclosure Vulnerability

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft SQL Server 2025 (CU 6)EPSS 1.00%via CVEORG
CVE-2026-57968High· 7.8
2mo ago

Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability

Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows Subsystem for Linux (WSL2)EPSS 0.33%via CVEORG
CVE-2026-59840Medium· 4.3
2mo ago

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through…

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through…

▾ Sunlitfortinet · fortiproxyEPSS 0.31%via NVD
CVE-2025-43892Medium· 4.3
2mo ago

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a po…

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a po…

▾ Sunlitfortinet · fortiproxyEPSS 0.38%via NVD
CWE-126 vulnerabilities (CVEs) — page 2 · VulnSea