Skip to main content

CWE archive

CWE-129 CVEs

Programmatic archive

601 CVEs tagged with CWE-12957 Critical, 404 High, 133 Medium, 7 Low, 0 Unrated.

CVE-2026-45799

Published Jul 17, 2026

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in w…

CVSS 7.5 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-63308

Published Jul 17, 2026

Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-46377

Published Jul 16, 2026

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRu…

CVSS 6.2 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-50144

Published Jul 15, 2026

ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows an out…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-24238

Published Jul 14, 2026

NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code exe…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-15685

Published Jul 13, 2026

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affec…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57272

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57271

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57270

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57269

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57268

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57267

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57266

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57265

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57264

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-13132

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-13131

Published Jul 2, 2026

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-14193

Published Jul 1, 2026

DVP80ES300T with Improper Validation of Array Index Vulnerability

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14191

Published Jul 1, 2026

An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when t…

CVSS 7.8 · High
evidence mentions
5
Buzz score
37.9

CVE-2026-22879

Published Jun 25, 2026

vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

CVSS 8.1 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-56770

Published Jun 25, 2026

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote a…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-52969

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() kvm_reset_dirty_gfn() guards the gfn range with if (!me…

CVSS 7.8 · High
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-56111

Published Jun 24, 2026

Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handler that…

CVSS 8.3 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-52915

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option lists struct ip6t_opts stores at most IP6T_OPTS_OPTSNR option de…

CVSS 7.1 · High
evidence mentions
9
Buzz score
33.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 601 CVEsPage 1 of 25