64 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-31705 | ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment | CRITICAL | 9.8 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-17675 | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the r | CRITICAL | 9.6 | 24%ile | NVD | 2026-07-30 |
| CVE-2026-17691 | Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially | CRITICAL | 9.6 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-17721 | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a | CRITICAL | 9.6 | 24%ile | NVD | 2026-07-30 |
| CVE-2026-17727 | Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially | CRITICAL | 9.6 | 24%ile | NVD | 2026-07-30 |
| CVE-2026-47876 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with | CRITICAL | 9.3 | 20%ile | NVD | 2026-07-30 |
| CVE-2026-58154 | Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affe | CRITICAL | 9.2 | 30%ile | NVD | 2026-07-29 |
| CVE-2026-18022 | Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, w | HIGH | 8.8 | 27%ile | NVD | 2026-07-29 |
| CVE-2026-65423 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to t | HIGH | 8.7 | 46%ile | NVD | 2026-07-30 |
| CVE-2026-68579 | FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_ | HIGH | 8.7 | 19%ile | NVD | 2026-08-02 |
| CVE-2026-58188 | Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apach | HIGH | 8.4 | 45%ile | NVD | 2026-07-29 |
| CVE-2026-12927 | CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut | HIGH | 8.4 | 10%ile | NVD | 2026-07-29 |
| CVE-2026-58177 | The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This is | HIGH | 8.3 | 43%ile | NVD | 2026-07-29 |
| CVE-2026-58184 | The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition | HIGH | 8.3 | 37%ile | NVD | 2026-07-29 |
| CVE-2026-10849 | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update ser | HIGH | 8.2 | 18%ile | NVD | 2026-08-03 |
| CVE-2026-17544 | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions | HIGH | 8.1 | 35%ile | NVD | 2026-07-30 |
| CVE-2026-48392 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context | HIGH | 7.8 | 4%ile | NVD | 2026-07-28 |
| CVE-2026-48393 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context | HIGH | 7.8 | 4%ile | NVD | 2026-07-28 |
| CVE-2026-48394 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context | HIGH | 7.8 | 4%ile | NVD | 2026-07-28 |
| CVE-2026-18220 | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. T | HIGH | 7.8 | 8%ile | NVD | 2026-07-29 |
| CVE-2026-34641 | Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co | HIGH | 7.8 | 4%ile | NVD | 2026-07-31 |
| CVE-2025-38685 | fbdev: Fix vmalloc out-of-bounds write in fast_imageblit | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2026-55693 | Vim: Out-of-bounds Write in Spell File Word Count | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-57455 | Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2025-38183 | net: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get() | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2023-0054 | Out-of-bounds Write in vim/vim | HIGH | 7.8 | 38%ile | Microsoft | 2023-01-10 |
| CVE-2026-15057 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontr | HIGH | 7.5 | 18%ile | NVD | 2026-07-28 |
| CVE-2026-6507 | Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing | HIGH | 7.5 | 39%ile | Microsoft | 2026-04-14 |
| CVE-2026-37457 | An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of F | HIGH | 7.5 | 32%ile | Microsoft | 2026-05-12 |
| CVE-2026-35226 | An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same n | HIGH | 7.1 | 7%ile | NVD | 2026-07-29 |
| CVE-2026-54715 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b | HIGH | 7.1 | 18%ile | NVD | 2026-07-30 |
| CVE-2026-31505 | iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2026-11771 | OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the | HIGH | 7.0 | 27%ile | NVD | 2026-07-30 |
| CVE-2026-10848 | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j | HIGH | 7.0 | 10%ile | NVD | 2026-08-02 |
| CVE-2025-7519 | Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write | MEDIUM | 6.7 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2026-20464 | In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalatio | MEDIUM | 6.5 | 28%ile | NVD | 2026-08-03 |
| CVE-2022-25147 | Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functions | MEDIUM | 6.5 | 70%ile | Microsoft | 2023-01-10 |
| CVE-2026-58187 | The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of serv | MEDIUM | 6.3 | 37%ile | NVD | 2026-07-29 |
| CVE-2026-20466 | In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalat | MEDIUM | 6.1 | 6%ile | NVD | 2026-08-03 |
| CVE-2026-20468 | In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of | MEDIUM | 6.0 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-20475 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o | MEDIUM | 6.0 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-20477 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o | MEDIUM | 6.0 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-20481 | In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation | MEDIUM | 6.0 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-20485 | In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p | MEDIUM | 6.0 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-20497 | In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation | MEDIUM | 6.0 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-20476 | In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servic | MEDIUM | 5.5 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-20478 | In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of | MEDIUM | 5.5 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-20491 | In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of ser | MEDIUM | 5.5 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-6695 | A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA ( | MEDIUM | 5.5 | 5%ile | NVD | 2026-08-03 |
| CVE-2026-55892 | Vim: Out-of-bounds Write in Spell File Prefix Dump | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2025-7546 | GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds write | MEDIUM | 5.3 | 7%ile | Microsoft | 2025-07-08 |
| CVE-2026-62363 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1. | MEDIUM | 5.0 | 3%ile | NVD | 2026-07-30 |
| CVE-2026-20471 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service | MEDIUM | 4.6 | 6%ile | NVD | 2026-08-03 |
| CVE-2026-20472 | In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servic | MEDIUM | 4.4 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-20493 | In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servi | MEDIUM | 4.4 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-18739 | A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when | LOW | 2.5 | 1%ile | NVD | 2026-08-04 |
| CVE-2026-45784 | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-5503 | out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName | UNKNOWN | — | 32%ile | Microsoft | 2026-04-14 |
| CVE-2026-5187 | Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-3298 | Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes | UNKNOWN | — | 30%ile | Microsoft | 2026-04-14 |
| CVE-2026-42250 | Off-by-One Leading to Out-of-Bounds Write in bzip2 | UNKNOWN | — | 3%ile | Microsoft | 2026-05-12 |
| CVE-2022-28331 | Apache Portable Runtime (APR): Windows out-of-bounds write in apr_socket_sendv function | UNKNOWN | — | 73%ile | Microsoft | 2023-01-10 |
| FG-IR-26-123 | Out-of-bounds access in CAPWAP daemon | UNKNOWN | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-127 | Out-Of-Bounds Write in administrative interface | UNKNOWN | — | — | Fortinet | 2026-04-15 |