Skip to main content

CWE archive

CWE-226 CVEs

Programmatic archive

33 CVEs tagged with CWE-2260 Critical, 11 High, 17 Medium, 5 Low, 0 Unrated.

CVE-2026-47247

Published Jul 21, 2026

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13585

Published Jul 15, 2026

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business…

CVSS 8.2 · High
evidence mentions
2
Buzz score
26.5
Public PoC observed

CVE-2026-48984

Published Jun 18, 2026

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfree() memory release helper in calls free() without first zer…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-5795

Published Apr 8, 2026

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditi…

CVSS 7.4 · High
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2025-14858

Published Apr 7, 2026

The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability in its firmware validation functionality. When a host issu…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2019-25657

Published Apr 5, 2026

AnyBurn 4.3 x86 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the image conversion fun…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2019-25645

Published Mar 24, 2026

WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attacker…

CVSS 6.9 · Medium

CVE-2019-25617

Published Mar 22, 2026

Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows local attackers to crash the application by processing malformed MP4…

CVSS 6.9 · Medium

CVE-2019-25571

Published Mar 21, 2026

MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessivel…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25563

Published Mar 21, 2026

PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying a malformed image file. Attackers can trigger the…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25560

Published Mar 21, 2026

Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25553

Published Mar 21, 2026

CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers ca…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13108

Published Feb 17, 2026

IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-33200

Published Nov 25, 2025

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this vulnerability might lead to i…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-33198

Published Nov 25, 2025

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this vulnerability might lead to i…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-33196

Published Nov 25, 2025

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this vulnerability might lead to i…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20622

Published Nov 11, 2025

Sensitive information uncleared in resource before release for reuse for some Intel(R) NPU Drivers for Windows before version 32.0.100.4023 within Ring 3: User Applications may al…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2025-11602

Published Oct 31, 2025

Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The a…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-2522

Published Jul 10, 2025

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentiall…

CVSS 6.5 · Medium

CVE-2025-48066

Published May 22, 2025

wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the c…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21850

Published Nov 13, 2024

Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1.5.02.00 may allow a privileged user to potentially enable…

CVSS 8.3 · High

CVE-2024-38275

Published Jun 18, 2024

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2