Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

810 CVEs tagged with CWE-90880 Critical, 216 High, 484 Medium, 30 Low, 0 Unrated.

CVE-2026-66038

Published Jul 24, 2026

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap me…

CVSS 7.1 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-66034

Published Jul 24, 2026

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds…

CVSS 7.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-47247

Published Jul 21, 2026

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-16386

Published Jul 21, 2026

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-16385

Published Jul 21, 2026

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-16384

Published Jul 21, 2026

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-60005

Published Jul 15, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-49165

Published Jul 14, 2026

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

CVSS 7.1 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-40422

Published Jul 14, 2026

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1
Showing 1-25 of 810 CVEsPage 1 of 33