VulnSea

CWE-476

CVEs classified under CWE-476, newest first.

373 CVEsRSS

CVE-2026-76905High· 7.5⚖ disputed
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A …

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.61%via NVD
CVE-2026-47753Medium
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission …

▾ Sunlitlxc · github.com/lxc/incus/v7EPSS 0.15%via NVD
CVE-2026-48754Low
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volu…

▾ Sunlitlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.38%via NVD
CVE-2026-48756Low
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of…

▾ Sunlitlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.38%via NVD
CVE-2026-63380Medium· 4.7
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. ev…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.14%via NVD
CVE-2026-76922Medium· 5.5
1mo ago

NULL Pointer Dereference in Wireshark

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ SunlitWireshark Foundation · WiresharkEPSS 0.14%via CVEORG
CVE-2026-76927Medium· 4.7
1mo ago

NULL Pointer Dereference in Wireshark

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

▾ SunlitWireshark Foundation · WiresharkEPSS 0.26%via CVEORG
CVE-2026-68901Medium· 6.5
1mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/attachments/:attachmentId/export, /api/boards/:boardId/export/csv, and /api/boards/:boardId/exportExcel handlers in mode…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-50126Medium· 4.0
1mo ago

Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards

Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions prior to 7.2.2 crash with a memory-safe…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-73502Medium· 5.3
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose application/…

▾ SunlitRed Hat · Red Hat Edge Manager 1EPSS 0.51%via NVD
CVE-2026-59949Medium· 6.5
1mo ago

yawkat LZ4 Java provides LZ4 compression for Java

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.n…

▾ Sunlityawk · at.yawk.lz4:lz4-javaEPSS 0.47%via NVD
CVE-2026-55401Medium· 5.3
1mo ago

CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57

CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which res…

▾ Sunlitabsolute · secure_accessEPSS 0.40%via NVD
CVE-2026-62702Medium· 6.8
1mo ago

Windows Graphics Kernel Denial of Service Vulnerability

Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.98%via CVEORG
CVE-2026-65681High· 7.5
1mo ago

Windows iSCSI Target Service Denial of Service Vulnerability

Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-18699Medium· 6.5
1mo ago

An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index

An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. …

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-18638Medium· 6.5
1mo ago

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-61345Medium· 6.5
1mo ago

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 1.1%via NVD
CVE-2026-59138Medium· 6.5
1mo ago

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 1.1%via NVD
CVE-2026-59132High· 7.5
1mo ago

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.2%via NVD
CVE-2026-71967Medium· 5.5
1mo ago

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service when CFG_WIDEVINE_PTA is en…

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service when CFG_WIDEVINE_PTA is en…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-72582High· 7.5
1mo ago

A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request

A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The sendOTPEmail function in pkg/auth/local.go dereferences a pointe…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-17510None
1mo ago

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared b…

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared b…

▾ SunlitEPSS 0.61%via NVD
CVE-2026-48097High· 7.8
1mo ago

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely …

▾ TwilightEPSS 0.23%via NVD
CVE-2026-52878High· 7.5
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission c…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-70640High· 7.0
1mo ago

llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while…

llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while…

▾ Twilightggml · llama.cppEPSS 0.24%via NVD
CVE-2026-70639Medium· 5.5
1mo ago

llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it

llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it. Attackers can s…

▾ Sunlitggml · llama.cppEPSS 0.19%via NVD
CVE-2026-46334None
1mo ago

OpenSIPS is a Session Initiation Protocol (SIP) server implementation

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/…

▾ SunlitEPSS 0.67%via NVD
GHSA-3x6r-wxxg-53vvMedium· 5.3
1mo ago

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-45084None
1mo ago

OpenSIPS is a Session Initiation Protocol (SIP) server implementation

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the presence module's handle_publish() function processes a SIP PU…

▾ SunlitEPSS 0.66%via NVD
CVE-2026-67304High· 7.5
1mo ago

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncate…

▾ Twilightfreerdp · freerdpEPSS 0.65%via NVD
CWE-476 vulnerabilities (CVEs) — page 5 · VulnSea