Skip to main content

CWE archive

CWE-122 CVEs

Programmatic archive

2,545 CVEs tagged with CWE-122232 Critical, 1,756 High, 420 Medium, 137 Low, 0 Unrated.

CVE-2026-54715

Published Jul 30, 2026

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matche…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-17951

Published Jul 30, 2026

Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium securit…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-17935

Published Jul 30, 2026

Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium secu…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-17758

Published Jul 30, 2026

Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-17680

Published Jul 30, 2026

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandb…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-13307

Published Jul 29, 2026

Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14266

Published Jul 29, 2026

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

CVSS 7.0 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-67191

Published Jul 29, 2026

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-16463

Published Jul 29, 2026

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a c…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-48372

Published Jul 28, 2026

Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this iss…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55971

Published Jul 27, 2026

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, whic…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-66040

Published Jul 24, 2026

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap m…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-66039

Published Jul 24, 2026

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplyin…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-66036

Published Jul 24, 2026

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying…

CVSS 7.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-66035

Published Jul 24, 2026

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in an…

CVSS 7.7 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-56392

Published Jul 24, 2026

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplica…

CVSS 1.8 · Low
evidence mentions
3
Buzz score
23.9

CVE-2026-56165

Published Jul 24, 2026

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49035

Published Jul 23, 2026

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; mem…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-13072

Published Jul 22, 2026

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory c…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-64830

Published Jul 22, 2026

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-40691

Published Jul 22, 2026

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the d…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-61390

Published Jul 22, 2026

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8987

Published Jul 21, 2026

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44178

Published Jul 20, 2026

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding da…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-41252

Published Jul 20, 2026

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 2,545 CVEsPage 1 of 102