Skip to main content

CWE archive

CWE-476 CVEs

Programmatic archive

5,449 CVEs tagged with CWE-476119 Critical, 1,298 High, 3,819 Medium, 212 Low, 1 Unrated.

CVE-2026-67184

Published Jul 28, 2026

TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-66749

Published Jul 28, 2026

Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid 24-character hex string room…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-47427

Published Jul 28, 2026

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-17574

Published Jul 27, 2026

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the ap…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-17500

Published Jul 27, 2026

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation result…

CVSS 6.9 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-45816

Published Jul 24, 2026

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference)…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-50032

Published Jul 23, 2026

A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty li…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13070

Published Jul 22, 2026

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP staplin…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13065

Published Jul 22, 2026

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55717

Published Jul 22, 2026

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' r…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-47709

Published Jul 21, 2026

libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompress…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-10678

Published Jul 21, 2026

The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes from an I2C bus master byte-by-byte in mctp_i2c_gpio_tar…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-47143

Published Jul 21, 2026

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-16353

Published Jul 21, 2026

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-47276

Published Jul 20, 2026

In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broker by sending a POST request to…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47275

Published Jul 20, 2026

In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicious MQTT broker to crash any connecting NanoMQ MQTTv5 client…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-63762

Published Jul 20, 2026

SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripti…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-62309

Published Jul 16, 2026

CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyp…

CVSS 7.5 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-62299

Published Jul 16, 2026

CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetRespo…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-15352

Published Jul 16, 2026

A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing…

CVSS 8.2 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-52865

Published Jul 15, 2026

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer reso…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-56363

Published Jul 14, 2026

A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel,…

CVSS 7.5 · High
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 5,449 CVEsPage 1 of 218