VulnSea

CWE-190

CVEs classified under CWE-190, newest first.

387 CVEsRSS

CVE-2026-69373Medium· 6.7
2w ago

Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.35%via NVD
CVE-2026-69329High· 7.5
2w ago

Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.

Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via NVD
CVE-2026-69298High· 7.8
2w ago

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-69266High· 8.8
2w ago

Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.82%via NVD
CVE-2026-68889High· 7.1
2w ago

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.57%via NVD
CVE-2026-68832High· 7.8
2w ago

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-67641Medium· 6.5
2w ago

Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.

Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.

▾ Sunlitmicrosoft · sql_server_2022EPSS 1.1%via NVD
CVE-2026-67384High· 8.8
2w ago

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.91%via NVD
CVE-2026-67376High· 7.5
2w ago

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 1.2%via NVD
CVE-2026-82076Medium· 6.5
2w ago

An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal resource limit

An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal resource limit. Submitting a specially crafted query causes th…

▾ Sunlitmongodb · mongodbEPSS 0.41%via NVD
CVE-2026-86314Medium· 6.2
2w ago

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module…

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module…

▾ SunlitSamsung Opensource · WalrusEPSS 0.18%via NVD
CVE-2026-84732High· 8.7
2w ago

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

▾ TwilightOpenVPN · OpenVPNEPSS 0.54%via NVD
CVE-2026-86289Medium· 4.3PoC
2w ago

A vulnerability was found in Ollama up to 0.31.1

A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible t…

▾ TwilightRed Hat · OllamaEPSS 0.69%via NVD
CVE-2026-86143Medium· 6.9
3w ago

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security rele…

▾ Sunlitxmlsoft · libxml2EPSS 0.19%via NVD
CVE-2026-86139Medium· 6.9
3w ago

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

▾ Sunlitxmlsoft · libxml2EPSS 0.17%via NVD
CVE-2026-86138Medium· 6.9
3w ago

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

▾ Sunlitxmlsoft · libxml2EPSS 0.13%via NVD
CVE-2026-18078Medium· 4.3
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.

▾ Sunlitibm · iEPSS 0.29%via NVD
CVE-2026-81666Medium· 6.5
3w ago

An integer overflow was found in Corosync's handling of membership commit token messages

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected mess…

▾ SunlitRed Hat · corosyncEPSS 0.19%via NVD
CVE-2026-84965Medium· 5.1
3w ago

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits,…

▾ Sunlitmongodb · c_driverEPSS 0.13%via NVD
CVE-2026-48486High· 7.5
3w ago

Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm

Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() allowed a miner to receive an arbit…

▾ TwilightEPSS 0.33%via NVD
CVE-2026-85438Critical· 9.8
3w ago

MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation

MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers …

▾ Midnightmoos-ivp · moos-ivpEPSS 0.88%via NVD
CVE-2026-75538High· 8.2
3w ago

An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond …

An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond …

▾ TwilightErlang · otpEPSS 0.85%via NVD
CVE-2026-38350High· 7.5
1mo ago

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-38349High· 7.5
1mo ago

An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-38348High· 7.5
1mo ago

An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-38346High· 7.5
1mo ago

An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-38343Medium· 6.5
1mo ago

An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

▾ SunlitEPSS 0.36%via NVD
CVE-2026-19313Critical· 9.3
1mo ago

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

▾ MidnightWatchGuard · Fireware OSEPSS 0.47%via NVD
CVE-2026-55764High
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finite per-nonce MaxSupply on the semi-fungible token add-quantity path. In core/kapp/systemAccount/sy…

▾ Twilightklever-io · github.com/klever-io/klever-goEPSS 0.54%via NVD
CVE-2026-54755Critical· 9.6
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go a…

▾ Midnightklever-io · github.com/klever-io/klever-goEPSS 0.56%via NVD
CWE-190 vulnerabilities (CVEs) — page 5 · VulnSea