VulnSea

GlavSoft has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was October 2026 with 5. The median CVSS is 7.1 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • TightVNC 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

GlavSoft vulnerabilities

CVEs affecting GlavSoft, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-107615High· 7.8
today

An uncontrolled search path element vulnerability in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to execute arbitrary code with SYSTEM privileges

An uncontrolled search path element vulnerability in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to execute arbitrary code with SYSTEM privileges. DynamicLibrary::init() (and ThemeLib) load screen…

▾ TwilightGlavSoft · TightVNCvia NVD
CVE-2026-107614Medium· 6.1
today

An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor sh…

An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor sh…

▾ SunlitGlavSoft · TightVNCvia NVD
CVE-2026-107613Medium· 5.9
today

A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service

A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desk…

▾ SunlitGlavSoft · TightVNCvia NVD
CVE-2026-107612High· 7.8
today

Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to read or overwrite the inter-process communication handles used between the TightVNC service and its desktop server…

Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to read or overwrite the inter-process communication handles used between the TightVNC service and its desktop server…

▾ TwilightGlavSoft · TightVNCvia NVD
CVE-2026-107611High· 7.1
today

An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending …

An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending …

▾ TwilightGlavSoft · TightVNCvia NVD
GlavSoft vulnerabilities (CVEs) · VulnSea