160 CVEs — updated 2026-09-21 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-54333 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Pri | CRITICAL | 9.8 | 37%ile | NVD | 2026-09-14 |
| CVE-2026-54334 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Pri | CRITICAL | 9.8 | 37%ile | NVD | 2026-09-14 |
| CVE-2026-65414 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | CRITICAL | 9.8 | 61%ile | NVD | 2026-09-14 |
| CVE-2026-11928 | IBM Verify Identity Access is vulnerable to a buffer overflow attack. | CRITICAL | 9.8 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-19773 | libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili | CRITICAL | 9.8 | 50%ile | NVD | 2026-09-15 |
| CVE-2026-89783 | In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr( | CRITICAL | 9.8 | 52%ile | NVD | 2026-09-16 |
| CVE-2026-89969 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving a | CRITICAL | 9.8 | 52%ile | NVD | 2026-09-16 |
| CVE-2026-90048 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create | CRITICAL | 9.8 | 42%ile | NVD | 2026-09-16 |
| CVE-2026-54626 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I | CRITICAL | 9.8 | 44%ile | NVD | 2026-09-17 |
| CVE-2026-54627 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I | CRITICAL | 9.8 | 38%ile | NVD | 2026-09-17 |
| CVE-2026-84383 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item | CRITICAL | 9.8 | 49%ile | NVD | 2026-09-18 |
| CVE-2025-1744 | Out-of-bounds Write in radare2 | CRITICAL | 9.8 | 42%ile | Microsoft | 2025-02-11 |
| CVE-2026-93393 | A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platf | CRITICAL | 9.2 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-43790 | The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, | CRITICAL | 9.1 | 51%ile | NVD | 2026-09-14 |
| CVE-2026-73194 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the | CRITICAL | 9.1 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-43815 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma | HIGH | 8.8 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-65374 | A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | HIGH | 8.8 | 33%ile | NVD | 2026-09-14 |
| CVE-2026-65391 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6 | HIGH | 8.8 | 33%ile | NVD | 2026-09-14 |
| CVE-2026-0159 | In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-0170 | In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This c | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-0171 | In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remo | HIGH | 8.8 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-0200 | In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote esca | HIGH | 8.8 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-55331 | In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-56920 | In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code. | HIGH | 8.8 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-56942 | In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-56974 | In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. Th | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-56997 | In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This c | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-58683 | In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-58710 | In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. Th | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-91711 | Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitr | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-15579 | An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usern | HIGH | 8.8 | 38%ile | NVD | 2026-09-18 |
| CVE-2026-93452 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wr | HIGH | 8.7 | 41%ile | NVD | 2026-09-18 |
| CVE-2026-92786 | LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to wr | HIGH | 8.5 | 3%ile | NVD | 2026-09-16 |
| CVE-2026-84546 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | HIGH | 8.4 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-55301 | In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead t | HIGH | 8.4 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-63388 | Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX accept | HIGH | 8.4 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-63638 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | HIGH | 8.3 | 15%ile | NVD | 2026-09-18 |
| CVE-2026-86107 | The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments betwee | HIGH | 8.2 | 29%ile | NVD | 2026-09-16 |
| CVE-2026-86145 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursiv | HIGH | 8.2 | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-70456 | rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() | HIGH | 8.2 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-70458 | rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling | HIGH | 8.2 | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-70461 | rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry | HIGH | 8.2 | 46%ile | Microsoft | 2026-08-11 |
| CVE-2026-11728 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.1 | 47%ile | NVD | 2026-09-15 |
| CVE-2026-10027 | IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow whe | HIGH | 8.1 | 31%ile | NVD | 2026-09-18 |
| CVE-2026-55200 | libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c | HIGH | 8.1 | 90%ile | Microsoft | 2026-06-09 |
| CVE-2024-53427 | decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which ha | HIGH | 8.1 | 29%ile | Microsoft | 2025-02-11 |
| CVE-2026-55343 | In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This cou | HIGH | 8.0 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-56967 | In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (pro | HIGH | 8.0 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-90948 | A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer ove | HIGH | 7.8 | 14%ile | NVD | 2026-09-14 |
| CVE-2026-90949 | A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-base | HIGH | 7.8 | 14%ile | NVD | 2026-09-14 |
| CVE-2026-90947 | A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not | HIGH | 7.8 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-65344 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | HIGH | 7.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-84505 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, m | HIGH | 7.8 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-84511 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, m | HIGH | 7.8 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-84515 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, m | HIGH | 7.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-84575 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, m | HIGH | 7.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-0199 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This | HIGH | 7.8 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-19885 | OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability al | HIGH | 7.8 | 7%ile | NVD | 2026-09-15 |
| CVE-2026-55323 | In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This | HIGH | 7.8 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-55351 | In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privi | HIGH | 7.8 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-56945 | In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privile | HIGH | 7.8 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-57014 | In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing | HIGH | 7.8 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-92177 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo | HIGH | 7.8 | 7%ile | NVD | 2026-09-15 |
| CVE-2026-92179 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo | HIGH | 7.8 | 7%ile | NVD | 2026-09-15 |
| CVE-2026-89894 | In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: reject geometry changes while the V | HIGH | 7.8 | 6%ile | NVD | 2026-09-16 |
| CVE-2026-89965 | In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: reject an arena whose nfree is below th | HIGH | 7.8 | 6%ile | NVD | 2026-09-16 |
| CVE-2026-89967 | In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: avoid out-of-bounds writes for c | HIGH | 7.8 | 5%ile | NVD | 2026-09-16 |
| CVE-2026-24073 | Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. | HIGH | 7.8 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-24074 | Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operat | HIGH | 7.8 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-25280 | Memory corruption when processing escape handling flow with insufficient user buffer sizes. | HIGH | 7.8 | 2%ile | NVD | 2026-09-17 |
| CVE-2026-90118 | In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one page overflow in ntfs_decompre | HIGH | 7.8 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-90133 | In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix index_root heap OOB write in ntfs_ir_to_i | HIGH | 7.8 | 9%ile | NVD | 2026-09-17 |
| CVE-2026-90295 | cpufreq: imx6q: fix out-of-bounds write when probed more than once | HIGH | 7.8 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-54692 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P | HIGH | 7.8 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-63419 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | HIGH | 7.8 | 12%ile | NVD | 2026-09-18 |
| CVE-2026-63422 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | HIGH | 7.8 | 4%ile | NVD | 2026-09-18 |
| CVE-2026-61714 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth. | HIGH | 7.8 | 4%ile | NVD | 2026-09-18 |
| CVE-2026-13732 | Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf | HIGH | 7.8 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2025-68973 | In GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leadi | HIGH | 7.8 | 4%ile | Microsoft | 2025-12-09 |
| CVE-2026-55693 | Vim: Out-of-bounds Write in Spell File Word Count | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-57455 | Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument | HIGH | 7.8 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2025-38183 | net: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get() | HIGH | 7.8 | 6%ile | Microsoft | 2025-07-08 |
| CVE-2025-21785 | arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array | HIGH | 7.8 | 19%ile | Microsoft | 2025-02-11 |
| CVE-2025-26598 | Xorg: xwayland: out-of-bounds write in createpointerbarrierclient() | HIGH | 7.8 | 34%ile | Microsoft | 2025-02-11 |
| CVE-2026-91948 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handli | HIGH | 7.7 | 50%ile | NVD | 2026-09-15 |
| CVE-2026-67549 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | HIGH | 7.6 | 18%ile | NVD | 2026-09-18 |
| CVE-2025-0624 | Grub2: net: out-of-bounds write in grub_net_search_config_file() | HIGH | 7.6 | 71%ile | Microsoft | 2025-02-11 |
| CVE-2026-6507 | Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing | HIGH | 7.5 | 41%ile | Microsoft | 2026-04-14 |
| CVE-2026-55958 | Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage | HIGH | 7.5 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-6325 | Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list | HIGH | 7.5 | 22%ile | Microsoft | 2026-06-09 |
| CVE-2026-84444 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, he | HIGH | 7.4 | 33%ile | NVD | 2026-09-18 |
| CVE-2026-64752 | A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, ma | HIGH | 7.3 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-84611 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | HIGH | 7.3 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-54634 | Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld | HIGH | 7.3 | 17%ile | NVD | 2026-09-17 |
| CVE-2026-64736 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS | HIGH | 7.1 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-86901 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. M | HIGH | 7.1 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-91951 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_curr | HIGH | 7.1 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-31505 | iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() | HIGH | 7.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2025-24528 | In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update | HIGH | 7.1 | 43%ile | Microsoft | 2026-01-13 |
| CVE-2026-58701 | In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could l | HIGH | 7.0 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-58734 | In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could | HIGH | 7.0 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-91097 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 7.0 | 51%ile | NVD | 2026-09-16 |
| CVE-2026-93015 | BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream | HIGH | 7.0 | 16%ile | NVD | 2026-09-17 |
| CVE-2026-94054 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. | HIGH | 7.0 | 20%ile | NVD | 2026-09-19 |
| CVE-2026-71220 | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit | HIGH | 7.0 | 3%ile | Microsoft | 2026-09-08 |
| CVE-2026-71221 | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta | HIGH | 7.0 | 3%ile | Microsoft | 2026-09-08 |
| CVE-2025-40331 | sctp: Prevent TOCTOU out-of-bounds write | HIGH | 7.0 | 9%ile | Microsoft | 2025-12-09 |
| CVE-2025-68284 | libceph: prevent potential out-of-bounds writes in handle_auth_session_key() | HIGH | 7.0 | 47%ile | Microsoft | 2025-12-09 |
| CVE-2026-53059 | dm log: fix out-of-bounds write due to region_count overflow | HIGH | 7.0 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-93451 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allo | MEDIUM | 6.9 | 22%ile | NVD | 2026-09-18 |
| CVE-2026-77396 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser | MEDIUM | 6.9 | 3%ile | NVD | 2026-09-18 |
| CVE-2026-14986 | The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGE | MEDIUM | 6.8 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-89729 | HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature | MEDIUM | 6.8 | 29%ile | Microsoft | 2026-09-08 |
| CVE-2026-55317 | In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to loca | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-55332 | In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to loca | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-55365 | In multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could l | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-56972 | In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to loca | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-56989 | In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local e | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-57035 | In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local e | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-58773 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This co | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-81627 | A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem | MEDIUM | 6.7 | 10%ile | NVD | 2026-09-18 |
| CVE-2025-7519 | Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write | MEDIUM | 6.7 | 9%ile | Microsoft | 2025-07-08 |
| CVE-2026-74498 | ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set | MEDIUM | 6.6 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-43677 | An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27, | MEDIUM | 6.5 | 24%ile | NVD | 2026-09-14 |
| CVE-2026-43761 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, m | MEDIUM | 6.5 | 32%ile | NVD | 2026-09-14 |
| CVE-2026-65395 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 6.5 | 29%ile | NVD | 2026-09-14 |
| CVE-2026-84519 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 6.5 | 25%ile | NVD | 2026-09-14 |
| CVE-2026-84588 | A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. Mo | MEDIUM | 6.5 | 15%ile | NVD | 2026-09-14 |
| CVE-2026-86869 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 6.5 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-86882 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 6.5 | 28%ile | NVD | 2026-09-14 |
| CVE-2026-89158 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. | MEDIUM | 6.5 | 13%ile | Microsoft | 2026-09-08 |
| CVE-2026-70457 | rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() | MEDIUM | 6.5 | 32%ile | Microsoft | 2026-08-11 |
| CVE-2025-0677 | Grub2: ufs: integer overflow may lead to heap based out-of-bounds write when handling symlinks | MEDIUM | 6.4 | 26%ile | Microsoft | 2025-02-11 |
| CVE-2026-93841 | vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs ind | MEDIUM | 6.3 | 15%ile | NVD | 2026-09-18 |
| CVE-2026-74724 | ipvs: avoid out-of-bounds write in ip_vs_nat_icmp | MEDIUM | 6.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-84531 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, m | MEDIUM | 6.2 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-55093 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1 | MEDIUM | 6.1 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-84619 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, m | MEDIUM | 6.1 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-59181 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 6.1 | 10%ile | NVD | 2026-09-18 |
| CVE-2025-0690 | Grub2: read: integer overflow may lead to out-of-bounds write | MEDIUM | 6.1 | 52%ile | Microsoft | 2025-02-11 |
| CVE-2026-80852 | tls: device: fix out-of-bounds write in tls_append_frag() | MEDIUM | 6.0 | 6%ile | Microsoft | 2026-09-08 |
| CVE-2026-89157 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a | MEDIUM | 5.7 | 12%ile | Microsoft | 2026-09-08 |
| CVE-2026-28968 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-84523 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-84552 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadO | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-84567 | The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, | MEDIUM | 5.5 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-55892 | Vim: Out-of-bounds Write in Spell File Prefix Dump | MEDIUM | 5.5 | 2%ile | Microsoft | 2026-06-09 |
| CVE-2026-82782 | Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sen | MEDIUM | 5.3 | 19%ile | NVD | 2026-09-14 |
| CVE-2026-92880 | A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/c | MEDIUM | 5.3 | 16%ile | NVD | 2026-09-17 |
| CVE-2025-7546 | GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds write | MEDIUM | 5.3 | 8%ile | Microsoft | 2025-07-08 |
| CVE-2026-19280 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An auth | MEDIUM | 5.2 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-86876 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.2 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-28966 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 4.3 | 35%ile | NVD | 2026-09-14 |
| CVE-2026-84526 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 4.3 | 27%ile | NVD | 2026-09-14 |
| CVE-2026-91142 | A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offse | LOW | 3.6 | 1%ile | NVD | 2026-09-18 |
| CVE-2026-82327 | Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist da | LOW | 3.3 | 2%ile | Microsoft | 2026-08-11 |
| CVE-2026-93894 | In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type | LOW | 2.3 | 17%ile | NVD | 2026-09-18 |
| CVE-2026-73639 | Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tR | UNKNOWN | — | 7%ile | NVD | 2026-09-17 |
| CVE-2026-75892 | In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context | UNKNOWN | — | 4%ile | NVD | 2026-09-18 |
| FG-IR-26-123 | Out-of-bounds access in CAPWAP daemon | UNKNOWN | — | — | Fortinet | 2026-05-12 |