VulnSea

CWE-190

CVEs classified under CWE-190, newest first.

387 CVEsRSS

CVE-2026-62357None
1mo ago

Dragonfly is an in-memory data store built for modern application workloads

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) overflows in src/core/cms.cc, allocating an un…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-50142High· 7.5PoC
1mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequen…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-65346High· 8.8
1mo ago

An integer overflow was addressed with improved input validation

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary co…

▾ Twilightapple · ipadosEPSS 0.59%via NVD
CVE-2026-71479Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio…

▾ MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.65%via NVD
CVE-2026-73645None
1mo ago

OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM

OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential total supply with an euint64 value, and an overflowing internal _mint…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-73558Medium· 5.3
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a reque…

▾ Sunlitvllm · vllmEPSS 0.40%via NVD
CVE-2026-70462Medium· 6.5
1mo ago

rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero…

rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-55400Medium· 6.5
1mo ago

CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57

CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denia…

▾ Sunlitabsolute · secure_accessEPSS 0.37%via NVD
CVE-2026-15742High· 8.8
1mo ago

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or l…

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or l…

▾ Twilightpostgresql · postgresqlEPSS 0.56%via NVD
CVE-2026-14677High· 8.8
1mo ago

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the opera…

▾ Twilightpostgresql · postgresqlEPSS 0.42%via NVD
CVE-2026-14662High· 8.8PoC
1mo ago

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary …

▾ Midnightpostgresql · postgresqlEPSS 0.46%via NVD
CVE-2026-73564High
1mo ago

frp is a fast reverse proxy

frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF ma…

▾ Twilightfatedier · github.com/fatedier/frpEPSS 0.52%via NVD
CVE-2026-19001Critical· 9.8
1mo ago

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruptio…

▾ Midnightmongodb · bi_connector_odbc_driverEPSS 0.54%via NVD
CVE-2026-15562High· 7.5
1mo ago

A flaw was found in EAP's jboss-remoting

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to den…

▾ TwilightRed Hat · org.jboss.remoting/jboss-remotingEPSS 0.55%via NVD
CVE-2026-73074None
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copyin…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-70329High· 8.8
1mo ago

Microsoft Outlook Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.82%via CVEORG
CVE-2026-71331High· 8.1
1mo ago

Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.71%via CVEORG
CVE-2026-62735High· 7.8PoC
1mo ago

Windows HTTP.sys Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-62816High· 8.8
1mo ago

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.53%via CVEORG
CVE-2026-65814High· 7.8
1mo ago

Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-58641High· 7.8
1mo ago

.NET Elevation of Privilege Vulnerability

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · SkiaSharpEPSS 0.47%via CVEORG
CVE-2026-62751High· 7.8
1mo ago

Windows Projected File System Elevation of Privilege Vulnerability

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.33%via CVEORG
CVE-2026-63532High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-62822High· 8.8
1mo ago

Windows GDI+ Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.82%via CVEORG
CVE-2026-64911High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-64903High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-64898High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-65799Medium· 6.7
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.34%via CVEORG
CVE-2026-73086High· 7.4
1mo ago

nanoid is a secure, URL-friendly, unique string ID generator for JavaScript

nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, …

▾ Twilightnanoid · nanoidEPSS 0.30%via NVD
CVE-2026-62699Medium· 6.8
1mo ago

Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally.

Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.44%via NVD
CWE-190 vulnerabilities (CVEs) — page 7 · VulnSea