Total
521 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-50383 | 1 Microsoft | 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more | 2026-07-22 | N/A | 6.1 MEDIUM |
| Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-50372 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-22 | N/A | 7.0 HIGH |
| Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-50485 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-21 | N/A | 4.5 MEDIUM |
| Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | |||||
| CVE-2026-57968 | 1 Microsoft | 1 Windows Subsystem For Linux | 2026-07-20 | N/A | 7.8 HIGH |
| Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-50341 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-20 | N/A | 5.5 MEDIUM |
| Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | |||||
| CVE-2024-30069 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more | 2026-07-20 | N/A | 4.7 MEDIUM |
| Windows Remote Access Connection Manager Information Disclosure Vulnerability | |||||
| CVE-2026-47088 | 2026-07-17 | N/A | 3.1 LOW | ||
| An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user. | |||||
| CVE-2026-55036 | 1 Microsoft | 7 365 Apps, Excel, Microsoft 365 and 4 more | 2026-07-16 | N/A | 7.8 HIGH |
| Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-62353 | 2026-07-15 | N/A | 5.4 MEDIUM | ||
| TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server and possibly leak adjacent memory. This issue is fixed in version 3.4.1.14. | |||||
| CVE-2026-49854 | 2026-07-15 | N/A | 5.3 MEDIUM | ||
| Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6. | |||||
| CVE-2026-41898 | 1 Rust-openssl Project | 1 Rust-openssl | 2026-07-15 | N/A | 5.3 MEDIUM |
| rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in 0.10.78. | |||||
| CVE-2026-4371 | 1 Mozilla | 1 Thunderbird | 2026-07-15 | N/A | 7.4 HIGH |
| A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9. | |||||
| CVE-2026-28364 | 1 Ocaml | 1 Ocaml | 2026-07-15 | N/A | 7.9 HIGH |
| In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data. | |||||
| CVE-2026-6238 | 1 Gnu | 1 Glibc | 2026-07-14 | N/A | 6.5 MEDIUM |
| The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions. | |||||
| CVE-2026-50813 | 2026-07-09 | N/A | 6.1 MEDIUM | ||
| An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path | |||||
| CVE-2026-21379 | 1 Qualcomm | 94 Aqt1000, Aqt1000 Firmware, Cologne and 91 more | 2026-07-07 | N/A | 7.8 HIGH |
| Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. | |||||
| CVE-2025-60729 | 1 Perfree | 1 Perfreeblog | 2026-07-05 | N/A | 5.3 MEDIUM |
| PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function | |||||
| CVE-2025-32053 | 2026-06-30 | N/A | 6.5 MEDIUM | ||
| A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read. | |||||
| CVE-2025-32052 | 2026-06-30 | N/A | 6.5 MEDIUM | ||
| A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read. | |||||
| CVE-2026-40210 | 2026-06-25 | N/A | 4.8 MEDIUM | ||
| An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash. | |||||
