CVE & CISA-KEV Catalog

403,896 CVEs1,740 actively exploited (KEV)

Want to know which of these are on your machines? Scan your endpoints with the free CVE scanner, 200 endpoints free.

Active:
  • CVSS 2.9 v3·EPSS -·No fix yet

    The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory in the rendered thumbnail or preview image, or cause the thumbnail or preview extension to crash.

    Published 2026-10-09

  • CVSS 3.6 v3·EPSS -·No fix yet

    The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing arrays of strings in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.

    Published 2026-10-09

  • CVSS 3.6 v3·EPSS -·No fix yet

    The Affinity by Canva application before 3.3.1 (October 2026 release) did not correctly handle incomplete UTF-8 character sequences when parsing text in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.

    Published 2026-10-09

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Transient DOS when processing a continuous receive command with a zero-sized global configuration override.

    Published 2026-10-06

  • CVSS 7.8 v3·EPSS 0.3%·Fix available

    Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

    Published 2026-10-06

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8911.

    Published 2026-10-05

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8912.

    Published 2026-10-05

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8913.

    Published 2026-10-05

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8914.

    Published 2026-10-05

  • CVSS 3.7 v3·EPSS 0.3%·Fix available

    The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.

    Published 2026-09-30

  • CVSS 7.5 v3·EPSS 0.2%·No fix yet

    The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake. The function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer. code: nx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c ``` UINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,

    Published 2026-09-29

  • CVSS 7.5 v3·EPSS 0.2%·No fix yet

    Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard.

    Published 2026-09-29

  • CVSS 4.7 v3·EPSS 0.1%·Fix available

    Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

    Published 2026-09-29

  • CVSS 5.5 v3·EPSS 0.2%·Fix available

    MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

    Published 2026-09-29

  • CVSS 7.1 v3·EPSS 0.2%·No fix yet

    An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.

    Published 2026-09-29

  • CVSS 7.5 v3·EPSS 0.6%·Fix available

    Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.

    Published 2026-09-23

  • CVSS 7.4 v3·EPSS 0.1%·No fix yet

    Transient DOS while parsing frame during channel usage.

    Published 2026-09-17

  • CVSS 7.3 v3·EPSS 0.1%·No fix yet

    Information Disclosure when a pointer is reused after being deallocated.

    Published 2026-09-17

  • CVSS 7.5 v3·EPSS 0.2%·No fix yet

    Transient DOS when processing authentication frames with invalid FILS information element header lengths.

    Published 2026-09-17

  • CVSS 7.4 v3·EPSS 0.1%·No fix yet

    Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

    Published 2026-09-17

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

    Published 2026-09-17

  • CVSS 3.3 v3·EPSS 0.2%·No fix yet

    A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 mitigates this issue. The patch is named afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.

    Published 2026-09-14

  • CVSS 5.3 v4·EPSS 0.5%·No fix yet

    A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.

    Published 2026-09-10

  • CVSS 5.5 v3·EPSS 0.5%·Fix available

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.5%·Fix available

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.5%·Fix available

    Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 4.3 v3·EPSS 0.5%·Fix available

    Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 1.0%·Fix available

    Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 0.9%·Fix available

    Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 7.5 v3·EPSS 1.0%·Fix available

    Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.4%·Fix available

    Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 0.9%·Fix available

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 0.9%·Fix available

    Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 7.0 v3·EPSS 0.3%·Fix available

    Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.

    Published 2026-09-08

  • CVSS 4.8 v3·EPSS 0.7%·Fix available

    Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 5.7 v3·EPSS 0.6%·Fix available

    Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

    Published 2026-09-08

  • CVSS 4.7 v3·EPSS 0.3%·Fix available

    Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 7.8 v3·EPSS 0.3%·Fix available

    Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.4%·Fix available

    Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 1.0%·Fix available

    Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 1.0%·Fix available

    Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 5.0 v3·EPSS 0.2%·Fix available

    The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.

    Published 2026-09-07

  • CVSS 7.5 v3·EPSS 0.3%·Fix available

    A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

    Published 2026-09-01

  • CVSS 7.8 v3·EPSS 0.3%·Fix available

    Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

    Published 2026-08-27

  • CVSS 2.0 v4·EPSS 0.1%·Fix available

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.

    Published 2026-08-20

  • CVSS 7.5 v3·EPSS 0.5%·Fix available

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

    Published 2026-08-20

  • CVSS 3.1 v3·EPSS 0.2%·Fix available

    Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

    Published 2026-08-19

  • CVSS 3.1 v3·EPSS 0.2%·Fix available

    ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

    Published 2026-08-19

  • CVSS 4.3 v3·EPSS 0.2%·Fix available

    Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

    Published 2026-08-14

  • CVSS 4.3 v3·EPSS 0.2%·Fix available

    Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

    Published 2026-08-14

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.