VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2026-87438Critical· 9.6
2w ago

Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-87621Critical· 9.6
2w ago

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-87500Critical· 9.6
2w ago

Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-87491High· 8.8CISA KEV0dayPoC
2w ago

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Abyssalgoogle · chromeEPSS 3.1%via NVD
CVE-2026-87638Critical· 9.6
2w ago

Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-53938High· 8.2
2w ago

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) do…

▾ TwilightOpenIDC · cjoseEPSS 0.39%via NVD
GHSA-26w7-cxv4-gfx2Critical· 9.8
2w ago

Astro: Remote code execution through AVIF image optimization

Astro: Remote code execution through AVIF image optimization

▾ Midnightastro · astrovia GHSA
CVE-2026-79908High· 7.8
2w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-30754High· 8.8
2w ago

A memory corruption vulnerability exists in FFmpeg before 8.1

A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC str…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-81983High· 7.8
2w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-81981High· 7.8
2w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-81980High· 7.8
2w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-81979High· 7.8
2w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-82005High· 7.8
2w ago

Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal…

▾ Twilightadobe · photoshopEPSS 0.26%via NVD
CVE-2026-75992High· 7.8
2w ago

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

▾ Twilightadobe · illustratorEPSS 0.26%via NVD
CVE-2026-75631High· 7.8
2w ago

Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal…

▾ Twilightadobe · photoshopEPSS 0.26%via NVD
CVE-2026-28583High· 7.8
2w ago

In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code

In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-28653High· 7.8
2w ago

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-28618High· 8.8PoC
2w ago

In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow

In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Midnightgoogle · androidEPSS 0.38%via NVD
CVE-2026-49918High· 7.8
2w ago

In multiple functions, there is a possible out of bounds write due to an integer overflow

In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-49879High· 8.8
2w ago

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitat…

▾ Twilightgoogle · androidEPSS 0.37%via NVD
CVE-2026-45515High· 7.8
2w ago

In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow

In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges nee…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-28662High· 8.0
2w ago

In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow

In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User …

▾ Twilightgoogle · androidEPSS 0.17%via NVD
CVE-2026-78524High· 8.8
2w ago

Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.

Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-71345High· 7.8
2w ago

Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.

Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-70296Critical· 9.8
2w ago

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.97%via NVD
CVE-2026-69819Critical· 9.8
2w ago

Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.

Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.97%via NVD
CVE-2026-86510Critical· 9.9PoC
2w ago

A vulnerability has been found in D-Link DIR-822A A_101

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The ex…

▾ AbyssalD-Link · DIR-822AEPSS 0.51%via NVD
CVE-2026-82071High· 8.1
2w ago

Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata

Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This re…

▾ Twilightmongodb · mongodbEPSS 0.54%via NVD
CVE-2026-62653Medium· 6.8
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode is not properly valid…

▾ SunlitSiemens · Reyrolle 7SR5EPSS 0.28%via NVD
CWE-787 vulnerabilities (CVEs) — page 9 · VulnSea