VulnSea

CWE-476

CVEs classified under CWE-476, newest first.

373 CVEsRSS

CVE-2026-77901High· 8.8
2w ago

Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-77489High· 7.8
2w ago

Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-72949High· 7.5
2w ago

Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.

Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_11_23h2EPSS 1.2%via NVD
CVE-2026-72939Medium· 6.5
2w ago

Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.

Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 1.1%via NVD
CVE-2026-70575Medium· 5.3
2w ago

Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.

Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.

▾ Sunlitmicrosoft · windows_11_23h2EPSS 0.95%via NVD
CVE-2026-69881High· 7.5
2w ago

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1809EPSS 1.2%via NVD
CVE-2026-69744High· 7.5
2w ago

Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.

Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_11_24h2EPSS 1.2%via NVD
CVE-2026-69587High· 7.5
2w ago

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_11_23h2EPSS 1.2%via NVD
CVE-2026-69384High· 7.1
2w ago

Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker to deny service locally.

Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker to deny service locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.43%via NVD
CVE-2026-84392Low· 2.7
2w ago

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.…

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.…

▾ SunlitFortinet · FortiOSEPSS 0.50%via NVD
CVE-2026-62762Medium· 6.5
2w ago

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 1.1%via NVD
CVE-2026-82055Medium· 6.5
2w ago

A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference

A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially crafted GeoJSON document is inserted into a collection with a 2dsphere index, an inconsi…

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18453High· 7.5
2w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests …

▾ TwilightRed Hat · redhat-ds:11EPSS 0.85%via NVD
CVE-2026-80118High· 7.1PoC
3w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users thr…

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users thr…

▾ MidnightPassMark Software · PerformanceTestEPSS 0.17%via NVD
CVE-2026-75439High· 7.5PoC
3w ago

An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component

An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component

▾ MidnightEPSS 0.76%via NVD
CVE-2026-19534High· 7.5
3w ago

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's …

▾ Twilightnodejs · undiciEPSS 0.39%via NVD
CVE-2026-86097Medium· 6.5PoC
3w ago

PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process

PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'param select' or…

▾ TwilightPX4 · PX4-AutopilotEPSS 0.40%via NVD
CVE-2026-17273Medium· 6.5
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.

▾ Sunlitibm · iEPSS 0.35%via NVD
CVE-2026-85150High· 7.5
3w ago

A NULL pointer dereference flaw was found in GStreamer's RTSP support library

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement aro…

▾ TwilightRed Hat · gstreamer1-plugins-baseEPSS 0.53%via NVD
CVE-2026-82926Medium· 5.5
3w ago

NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.

NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.

▾ SunlitSamsung Open Source · mTowerEPSS 0.15%via CVEORG
CVE-2026-77217Medium· 4.9
1mo ago

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. The web_radiusSrv*_post family of handlers copies the radKey, radK…

▾ SunlitEPSS 0.60%via NVD
CVE-2026-75125Medium· 4.9
1mo ago

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its…

▾ SunlitEPSS 0.56%via NVD
CVE-2026-54084Medium· 5.3
1mo ago

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.0.0 through 4.14.6, a malicious or man-in-the-middle enrollment manager can crash a Wazuh agent during e…

▾ Sunlitwazuh · wazuhEPSS 0.20%via NVD
CVE-2026-38344High· 7.5
1mo ago

A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-26456High· 7.5
1mo ago

A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5

A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition between the request dispatch thread and the session cl…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-14457High· 7.5
1mo ago

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solic…

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solic…

▾ Twilightopenssl · opensslEPSS 1.0%via NVD
CVE-2026-63076High· 7.5
1mo ago

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a d…

▾ Twilightopenssl · opensslEPSS 1.8%via NVD
CVE-2026-55371None
1mo ago

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore f…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-24263High· 8.2
1mo ago

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privile…

▾ Twilightnvidia · dgx_spark_uefiEPSS 0.15%via NVD
CVE-2023-54354Medium· 5.9
1mo ago

Rejected reason: This CVE ID has been rejected as a duplicate.

Rejected reason: This CVE ID has been rejected as a duplicate.

▾ SunlitRed Hat · Red Hat Satellite 6EPSS 0.35%via NVD
CWE-476 vulnerabilities (CVEs) — page 4 · VulnSea