By weakness (CWE)
CWE-119: related vulnerabilities
CVEs classified under CWE-119. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
141 published vulnerabilities · page 1 of 2
- CVE-2026-0139HIGH 8.8
CVE-2026-0139 is a critical vulnerability in Android's Modem component that allows an authenticated attacker to execute arbitrary code remotely without needing any special system privileges. The flaw stems from missing bounds validation in memory write operations, permitting an out-of-bounds write that can be weaponized for complete system compromise. No user action is required to trigger the vulnerability—an attacker with valid credentials can initiate the exploit automatically.
- CVE-2026-10062HIGH 8.8
A stack-based buffer overflow vulnerability was discovered in the TRENDnet TEW-432BRP router (firmware version 3.10B20) affecting the route configuration function. An authenticated attacker can send specially crafted requests containing oversized IP, netmask, or gateway parameters to the /goform/formSetRoute endpoint, causing a buffer overflow that enables complete compromise of the device. The vulnerability requires valid login credentials but has been publicly disclosed. Critically, this device reached end-of-life in 2009—over 15 years ago—and the vendor has confirmed no patches or fixes will be developed.
- CVE-2026-10063HIGH 8.8
A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) that allows authenticated attackers to remotely crash the device or potentially execute arbitrary code. The flaw is in the WPS (Wi-Fi Protected Setup) configuration function and can be triggered by sending a specially crafted request with an oversized PIN parameter. Critically, this router model reached end-of-life in 2009—over 15 years ago—and TRENDnet has confirmed they will not be providing patches or fixes.
- CVE-2026-10065HIGH 8.8
Shibby Tomato 1.28 contains a stack-based buffer overflow vulnerability in the UPS data retrieval function of its web interface. An authenticated attacker can manipulate the Date parameter to overflow a buffer on the stack, potentially executing arbitrary code on the affected device. Since Shibby Tomato is no longer maintained and has been superseded by FreshTomato, this vulnerability affects legacy installations that have not migrated to the actively supported successor.
- CVE-2026-10066HIGH 8.8
A stack-based buffer overflow vulnerability exists in Shibby Tomato firmware versions up to 1.28, specifically in the UPS Service component (tomatoups.cgi). An authenticated attacker with remote network access can trigger this flaw to potentially execute arbitrary code, compromise confidentiality and integrity, or cause denial of service. Notably, Shibby Tomato is no longer maintained; the project has been superseded by FreshTomato. Organizations still running unsupported Shibby Tomato instances face ongoing risk from this flaw without vendor patching.
- CVE-2026-10067HIGH 8.8
Shibby Tomato version 1.28 contains a stack-based buffer overflow vulnerability in the multimon.cgi component that allows authenticated attackers to execute arbitrary code remotely. The vulnerability exists in the sub_90F0 function and can be triggered through network requests without user interaction. Since Shibby Tomato is no longer maintained and has been superseded by FreshTomato, patches are not available from the original maintainers.
- CVE-2026-10119HIGH 8.8
A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP router (firmware version 3.10B20) in the MAC filter configuration function. An authenticated attacker can send a specially crafted request to overflow the stack via the filter_name parameter, potentially allowing code execution on the device. This affects only legacy hardware that has been end-of-life since 2009—the vendor has explicitly stated no patches will be released due to the product's age and lack of ongoing support.
- CVE-2026-10120HIGH 8.8
A stack-based buffer overflow exists in the TRENDnet TEW-432BRP wireless router running firmware version 3.10B20. An attacker with network access and valid credentials can send a specially crafted request to the firewall configuration function, causing a buffer overflow that crashes the device or potentially executes arbitrary code. The vendor has confirmed the product reached end-of-life in 2009 and will not issue patches. Public exploit code is available.
- CVE-2026-10121HIGH 8.8
A stack-based buffer overflow vulnerability has been discovered in the TRENDnet TEW-432BRP wireless router running firmware version 3.10B20. The flaw exists in the URL filter configuration function and can be triggered by sending a specially crafted request containing an oversized keyword list parameter. An attacker with network access and valid credentials can exploit this remotely to crash the device or potentially execute arbitrary code. TRENDnet has confirmed the product reached end-of-life in 2009 and will not be issuing patches.
- CVE-2026-10122HIGH 8.8
A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) within the protocol filter configuration function. An attacker with network access and valid login credentials can send a specially crafted request to overflow a buffer on the router's stack, potentially executing arbitrary code. TRENDnet has confirmed this product reached end-of-life 15 years ago and will not provide patches. While the exploit details are publicly available, this vulnerability poses limited enterprise risk due to the device's age and likely scarcity in production environments.
- CVE-2026-10123HIGH 8.8
A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) affecting the domain filtering function. An authenticated attacker can exploit this by manipulating domain filter parameters to overflow the stack, potentially gaining control of the device. Notably, this product reached end-of-life in 2009 and is no longer supported by the vendor, meaning no patches will be issued.
- CVE-2026-10124HIGH 8.8
A stack-based buffer overflow has been discovered in Shibby Tomato, a Linux router distribution, affecting versions up to 1.28. The vulnerability exists in the RIP (Routing Information Protocol) daemon's IPv4 handling function and allows authenticated attackers to overflow memory on the system stack, potentially leading to code execution. The flaw has been publicly disclosed, and exploit code is available. Critically, Shibby Tomato is no longer maintained by its original developers, having been superseded by FreshTomato. This means no security patches will be released for affected installations.
- CVE-2026-10125HIGH 8.8
A stack-based buffer overflow exists in Edimax BR-6478AC version 1.23 routers when processing PPPoE setup requests. An authenticated attacker can send a crafted request with an oversized username parameter to the formPPPoESetup endpoint, causing the router to crash or potentially execute arbitrary code. The vulnerability requires login credentials but poses significant risk since routers are often accessible from the internet and public exploit code is available.
- CVE-2026-10126HIGH 8.8
A buffer overflow vulnerability exists in Edimax BR-6478AC version 1.23 that allows authenticated users to crash the device or potentially execute arbitrary code. The flaw is in the QoS settings handler and can be triggered by sending a specially crafted request with an oversized value in the selSSID parameter. An attacker with valid router credentials can exploit this remotely without user interaction. Public exploit code is available, elevating the practical risk.
- CVE-2026-10158HIGH 8.8
A stack-based buffer overflow has been discovered in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20). An authenticated attacker can send a specially crafted request to the port forwarding configuration interface, exploiting improper input validation on the server_name parameter. This can lead to remote code execution on the device. The vulnerability is particularly concerning because exploit code has already been released publicly. However, the affected product reached end-of-life in 2009 and the vendor has stated they cannot provide patches.
- CVE-2026-10159HIGH 8.8
A stack-based buffer overflow vulnerability has been discovered in the TRENDnet TEW-432BRP wireless router (version 3.10B20), specifically in the system log configuration function. An attacker with network access and valid credentials can send a specially crafted request to trigger a memory overflow, potentially executing arbitrary code on the device. The vendor has confirmed the product reached end-of-life in 2009 and will not be patching this issue.
- CVE-2026-10160HIGH 8.8
A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20). An authenticated attacker can exploit this flaw by manipulating the 'start_wizard' parameter sent to the router's web interface, potentially allowing remote code execution. The vendor has confirmed this product reached end-of-life in 2009 and will not issue patches.
- CVE-2026-10161HIGH 8.8
A stack-based buffer overflow exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) in a network-accessible configuration function. An authenticated attacker can send a specially crafted request to the `/goform/formResetStatistic` endpoint with a malicious `status_statistic` parameter that overflows memory and corrupts the stack, potentially leading to code execution or denial of service. The device has been out of support since 2009, and the vendor has explicitly stated they cannot patch this issue.
- CVE-2026-10162HIGH 8.8
TRENDnet's TEW-432BRP wireless router (version 3.10B20) contains a stack-based buffer overflow vulnerability in its password-setting function. An authenticated attacker can send specially crafted input to the formSetPassword endpoint to overflow memory and potentially execute code on the device. The device has been end-of-life since 2009, and the vendor explicitly will not release patches. While the attack requires login credentials, the high CVSS score reflects the severity of potential compromise.
- CVE-2026-10163HIGH 8.8
A buffer overflow vulnerability exists in Edimax BR-6478AC version 1.23 that allows authenticated users to crash the router or potentially execute code by sending specially crafted requests to the USB account configuration endpoint. An attacker with login credentials can exploit this flaw remotely without further user interaction. The vulnerability has already been publicly disclosed, increasing the likelihood of active exploitation.
- CVE-2026-10164HIGH 8.8
A buffer overflow vulnerability exists in Edimax BR-6478AC router firmware version 1.23 that allows authenticated users to execute arbitrary code on the device. The flaw resides in the USB folder sharing feature and can be triggered by sending a specially crafted request with an oversized ShareName or SelectName parameter. Because the vulnerability requires valid credentials and the exploit has already been disclosed publicly, the risk of active exploitation is elevated.
- CVE-2026-10165HIGH 8.8
Edimax BR-6478AC wireless routers running firmware version 1.23 contain a critical flaw in their network configuration interface. An authenticated attacker can send a specially crafted network request to overflow the device's memory, potentially gaining complete control over the router. The vulnerability requires an existing user account but no additional interaction from administrators, making it a practical concern for organizations deploying these devices.
- CVE-2026-10179HIGH 8.8
A stack-based buffer overflow vulnerability affects the TRENDnet TEW-432BRP wireless router running firmware version 3.10B20. An authenticated attacker can send a specially crafted request to the wireless encryption settings function, causing a memory overflow that could lead to remote code execution. The router has been end-of-life since 2009, and the vendor has stated they cannot fix the issue due to the product's age.
- CVE-2026-10181HIGH 8.8
A stack-based buffer overflow vulnerability affects the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20). An authenticated remote attacker can exploit this by manipulating the 'submit-url' parameter in the /goform/formSysCmd endpoint, potentially leading to code execution or system crash. However, this device has been end-of-life since 2009, and the vendor has stated it will not be patching the issue due to the product's age.
- CVE-2026-10183HIGH 8.8
A stack-based buffer overflow exists in the TRENDnet TEW-432BRP wireless router (firmware version 3.10B20) in the WLAN configuration handler. An authenticated attacker can send a specially crafted request to the `/goform/formWlanSetup` endpoint with an oversized 'enrollee' parameter, causing the application to crash or potentially execute arbitrary code on the device. The vendor confirms this product reached end-of-life in 2009 and will not issue patches.
- CVE-2026-10188HIGH 8.8
A stack-based buffer overflow vulnerability exists in Tenda W12 firmware version 3.0.0.7(4763). An authenticated remote attacker can exploit this flaw by manipulating the staMac parameter passed to the cgistaKickOff function in the HTTP daemon (/bin/httpd), potentially executing arbitrary code with elevated privileges. Public exploit code is available, elevating the practical risk of this vulnerability.
- CVE-2026-10189HIGH 8.8
A stack-based buffer overflow vulnerability exists in Tenda W12 firmware version 3.0.0.7(4763). The flaw is in the web server's time configuration function, which fails to properly validate user input in the 'sec' parameter. An authenticated attacker can exploit this over the network to crash the device or execute arbitrary code with the privileges of the web server process. Public exploit code is available, increasing practical risk.
- CVE-2026-10191HIGH 8.8
A stack-based buffer overflow exists in Tenda W12 firmware version 3.0.0.7(4763) within the Wi-Fi MAC filter configuration function. An authenticated attacker can exploit this by sending a specially crafted MAC address list parameter to the web interface, causing memory corruption that may lead to code execution, information disclosure, or service disruption. The vulnerability is reachable over the network and exploit code has been made publicly available.
- CVE-2026-10192HIGH 8.8
A stack-based buffer overflow vulnerability exists in Tenda W12 firmware version 3.0.0.7(4763). An authenticated attacker can send a specially crafted time-setting request to the web interface that causes a memory corruption condition, potentially allowing arbitrary code execution on the affected device. Public exploit code is available, increasing the practical risk.
- CVE-2026-10206HIGH 8.8
D-Link DI-8400 routers contain a stack-based buffer overflow vulnerability in the /dbsrv.asp file that can be exploited by authenticated attackers to gain complete control of the device. By manipulating a specific parameter, an attacker with valid credentials can overflow memory on the router and execute arbitrary code remotely. This vulnerability affects firmware versions up to 16.07.26A1, and proof-of-concept code is publicly available, raising the risk of active exploitation.
- CVE-2026-10259HIGH 8.8
H3C Magic B0 devices running firmware up to version 100R002 contain a remotely exploitable vulnerability in their web interface. An authenticated attacker can send a specially crafted request to the SetMobileAPInfoById function that causes a stack-based buffer overflow, potentially allowing them to execute arbitrary code on the affected device. Public exploit details are already available, elevating the practical risk.
- CVE-2026-10270HIGH 8.8
D-Link DI-7001 MINI routers running firmware version 19.09.19A1 and earlier contain a stack-based buffer overflow in the web API debug interface. An attacker with valid login credentials can send a specially crafted request to the /httpd_debug.asp endpoint that overflows a buffer, potentially allowing arbitrary code execution on the device. Exploit code has been publicly disclosed, elevating near-term risk.
- CVE-2026-10292HIGH 8.8
A stack-based buffer overflow exists in UTT HiPER 1200GW network devices running firmware version 2.5.3-170306 and earlier. The vulnerability resides in the task editing form handler and is exploitable by authenticated remote attackers. An attacker with valid credentials can send a specially crafted request that overflows a buffer, potentially allowing arbitrary code execution on the device. Public exploit code is available, increasing the risk of active exploitation.
- CVE-2026-10293HIGH 8.8
A stack-based buffer overflow vulnerability exists in UTT HiPER 1200GW networking devices (versions up to 2.5.3-170306). An attacker with valid login credentials can send a specially crafted request to the firewall configuration endpoint that causes the device to overflow its memory, potentially leading to code execution, data theft, or denial of service. Public exploit code is available, elevating the practical risk.
- CVE-2026-10904HIGH 8.8
Google Chrome versions prior to 149.0.7827.53 contain a flaw in the V8 JavaScript engine that allows attackers to break out of the browser sandbox and run malicious code with full privileges. An attacker can exploit this by tricking a user into visiting a specially crafted website. Once triggered, the vulnerability bypasses Chrome's security boundary—the sandbox that normally isolates web content from the rest of the system—giving an attacker direct access to execute arbitrary code on the victim's machine.
- CVE-2026-11413HIGH 8.8
A stack-based buffer overflow vulnerability exists in JingDong JD Cloud Box AX6600 running firmware version 4.5.3.r4546. An authenticated attacker can send a specially crafted request to the set_macfilter function in the device's web RPC service to overflow the stack and potentially execute arbitrary code. The vulnerability is remotely exploitable and exploit code has already been publicly disclosed, making it a concrete risk for organizations using this router model.
- CVE-2026-11498HIGH 8.8
Tenda wireless routers (models HG7, HG9, and HG10) contain a critical flaw in their web-based management interface. An authenticated attacker can send a specially crafted request to the VoIP settings page that overwrites memory on the router, leading to complete compromise of the device. The vulnerability requires a valid login but can be exploited over the network without user interaction. Once exploited, an attacker gains full control over the router's functions, including potential interception of network traffic and manipulation of connected devices.
- CVE-2026-11503HIGH 8.8
Tenda's CX12L router model 16.03.53.12 contains a critical flaw in its Wi-Fi configuration interface that allows authenticated attackers to crash the device or execute arbitrary code by sending specially crafted requests with oversized network names (SSIDs). The vulnerability exists in the fast_setting_wifi_set function and has been publicly disclosed, increasing the risk of active exploitation.
- CVE-2026-11504HIGH 8.8
A stack-based buffer overflow vulnerability exists in Tenda CX12L routers running firmware version 16.03.53.12. The flaw is in the Wi-Fi scheduling feature and can be exploited by authenticated users to corrupt memory and potentially execute arbitrary code. An attacker with valid login credentials can send specially crafted scheduling parameters that overflow a buffer, compromising the router's confidentiality, integrity, and availability. Public exploit code has emerged, increasing active risk.
- CVE-2026-11517HIGH 8.8
A buffer overflow vulnerability exists in UTT HiPER 2610G network devices running firmware version 3.0.0-171107 and earlier. An authenticated user can send a specially crafted request to the DNS filter configuration page that overwrites memory and crashes the device or potentially executes malicious code. The flaw has been publicly disclosed, meaning attackers have visibility into exploitation techniques.
- CVE-2026-11522HIGH 8.8
Tenda W20E routers running firmware version 15.11.0.6 contain a stack-based buffer overflow vulnerability in the port mirroring configuration feature. An attacker with valid network access can send a specially crafted request to the router's web interface that causes a buffer overflow when processing the portMirrorMirroredPorts parameter. This flaw allows remote code execution with full system privileges, potentially giving attackers complete control over the router and any network traffic passing through it. Public exploit code is now available, elevating the practical risk.
- CVE-2026-11523HIGH 8.8
A stack-based buffer overflow vulnerability has been discovered in Tenda W20E firmware version 15.11.0.6. An authenticated attacker can manipulate the 'gotoUrl' parameter in the web management interface's portal authentication function to overflow a stack buffer, potentially gaining full control of the device. Public exploits for this vulnerability are available, elevating the risk of active exploitation.
- CVE-2026-11524HIGH 8.8
A stack-based buffer overflow vulnerability exists in Tenda W20E version 15.11.0.6, specifically in the web management interface's WiFi filter rule modification function. An authenticated attacker can exploit this by sending a specially crafted request with an oversized remark parameter, allowing them to overwrite stack memory and potentially execute arbitrary code on the device. The vulnerability requires valid credentials but no user interaction, making it a practical post-authentication attack vector for network administrators or compromised accounts.
- CVE-2026-11528HIGH 8.8
A stack-based buffer overflow vulnerability affects Tenda AC18 running firmware version 15.03.05.05. An attacker with valid login credentials can send a specially crafted request to the web management interface's reboot status endpoint, causing a buffer overflow that could lead to arbitrary code execution on the device. The vulnerability has been publicly disclosed and exploit code is available, increasing the practical risk.
- CVE-2026-11553HIGH 8.8
Tenda HG7, HG9, and HG10 routers contain a dangerous flaw in their web interface that allows an authenticated attacker to crash the device or take control of it by sending a specially crafted request. The vulnerability resides in how the router processes user input for a specific configuration parameter, failing to properly validate the length of data before storing it in memory. An attacker with login credentials can exploit this remotely without any user interaction.
- CVE-2026-11557HIGH 8.8
A stack-based buffer overflow vulnerability has been discovered in Tenda F451 wireless router firmware versions 1.0.0.7 and 1.0.0.9. An authenticated attacker can exploit this flaw by manipulating the 'page' parameter in the Natlimit web management interface to overflow the stack memory, potentially allowing them to execute arbitrary code or crash the device. Public exploit code is available, elevating the practical risk. The vulnerability requires valid login credentials but no user interaction, making it exploitable in environments where network access and authentication are possible.
- CVE-2026-12174HIGH 8.8
D-Link DCS-935L cameras running firmware version 1.10.01 contain a format string vulnerability in their web interface. An attacker with valid login credentials can send specially crafted requests to a specific CGI handler to read sensitive memory, modify system behavior, or execute code on the device. The vulnerability requires authentication but offers no other barriers; it can be exploited over the network without user interaction.
- CVE-2026-12192HIGH 8.8
GALAYOU Y4 version 1.0.0 contains a buffer overflow vulnerability in its web server component that allows attackers on the same local network to crash the service or potentially execute code with full system privileges. No user interaction is required to trigger the vulnerability, and exploit code has already been made public. The vendor has not responded to early disclosure attempts, leaving affected users without an official patch path.
- CVE-2026-12806HIGH 8.8
A buffer overflow vulnerability affects Edimax BR-6478AC V2 running firmware version 1.23. The flaw exists in a wireless site survey function accessible via HTTP POST requests and can be exploited by an authenticated attacker to corrupt memory and potentially execute arbitrary code on the router. The vendor has not responded to early disclosure attempts, and proof-of-concept details are now public, elevating the risk posture for exposed instances.
- CVE-2026-13515HIGH 8.8
Tenda JD12L router version 16.03.53.23 contains a stack-based buffer overflow vulnerability in its PPTP server configuration function. An authenticated attacker can exploit this flaw by sending a specially crafted request with an oversized startIp parameter, potentially causing the application to crash or allowing arbitrary code execution. The vulnerability is reachable over the network and has been publicly disclosed.
- CVE-2026-13516HIGH 8.8
Tenda JD12L routers running firmware version 16.03.53.23 contain a stack-based buffer overflow vulnerability in the guest Wi-Fi configuration function. An authenticated attacker can exploit this by sending a specially crafted request to manipulate the 'shareSpeed' parameter, potentially allowing arbitrary code execution or device compromise. Public exploit code is available, elevating the practical risk.
- CVE-2026-13517HIGH 8.8
A stack-based buffer overflow vulnerability exists in Tenda JD12L firmware version 16.03.53.23. An authenticated remote attacker can exploit this flaw by sending a specially crafted request to the Wi-Fi configuration endpoint, potentially allowing them to execute arbitrary code or crash the device. The vulnerability affects the security_5g parameter handling in the Wi-Fi basic settings function. Public exploit code is available, increasing the practical risk of exploitation.
- CVE-2026-13518HIGH 8.8
Tenda JD12L routers running firmware version 16.03.53.23 contain a stack-based buffer overflow vulnerability in the network address translation (NAT) settings interface. An authenticated attacker can overflow a buffer by sending a specially crafted request to the `/goform/addressNat` endpoint with a malicious `page` parameter, leading to code execution on the device. The vulnerability requires valid login credentials but poses a significant risk because exploitation is straightforward and public proof-of-concept code is available.
- CVE-2026-13519HIGH 8.8
A stack-based buffer overflow vulnerability exists in Tenda JD12L routers running firmware version 16.03.53.23. An authenticated attacker can trigger the overflow by sending a specially crafted request to the NAT Static Setting function, potentially allowing them to execute arbitrary code or crash the device. Public exploit code is available, increasing the practical risk.
- CVE-2026-13539HIGH 8.8
A stack-based buffer overflow vulnerability exists in Wavlink WL-NU516U1-A routers running firmware M16U1_V240425. An authenticated attacker can send a malicious POST request to the wireless configuration endpoint with an oversized Guest_ssid parameter, causing the application to write beyond allocated memory. This memory corruption can lead to unauthorized access, data theft, or complete device compromise. The vulnerability is remotely exploitable and public exploits are available, though the vendor has released a patched firmware version.
- CVE-2026-13562HIGH 8.8
A buffer overflow vulnerability has been discovered in Edimax EW-7478APC wireless extender running firmware version 1.04. An authenticated attacker can exploit this flaw by sending a specially crafted request to the device's web interface, specifically by manipulating the selSSID parameter in the NIC site survey function. Successful exploitation allows the attacker to execute arbitrary code with full device privileges, potentially compromising network traffic and allowing lateral movement into the network.
- CVE-2026-13563HIGH 8.8
A stack-based buffer overflow vulnerability exists in Edimax EW-7478APC wireless extender firmware version 1.04. The vulnerability is triggered when an attacker sends a specially crafted POST request to the L2TP setup endpoint, with an oversized username parameter that overwrites the call stack. An authenticated attacker can exploit this remotely to execute arbitrary code or crash the device. The vendor has not responded to early disclosure attempts, and the vulnerability details are now public.
- CVE-2026-13564HIGH 8.8
A stack-based buffer overflow vulnerability exists in Edimax EW-7478APC wireless access point model running firmware version 1.04. An authenticated remote attacker can exploit this flaw by sending a specially crafted POST request with an oversized username parameter to the PPPoE setup interface, allowing them to execute arbitrary code with full system privileges. Public exploit code is available, elevating the practical risk.
- CVE-2026-13580HIGH 8.8
A buffer overflow vulnerability exists in Edimax EW-7478APC wireless access point (firmware 1.04) that allows an authenticated attacker to crash the device or execute arbitrary code. The flaw resides in the QoS configuration endpoint and can be triggered by sending a specially crafted POST request with an oversized value in the selSSID parameter. An attacker with valid login credentials can exploit this remotely without user interaction.
- CVE-2026-13582HIGH 8.8
A buffer overflow vulnerability exists in Edimax EW-7478APC wireless access point firmware version 1.04. An authenticated attacker can send a specially crafted network request to the device's USB account management function, causing a memory overflow that leads to code execution with full device privileges. Public exploit code is available, and the vendor has not responded to responsible disclosure attempts, leaving affected devices at active risk.
- CVE-2026-13583HIGH 8.8
A buffer overflow vulnerability exists in Edimax EW-7478APC wireless access point (version 1.04) that allows authenticated attackers to crash the device or potentially execute arbitrary code. The flaw is in how the device processes user-supplied input when handling USB folder sharing requests. Because exploit code has already been released publicly and the vendor has not provided a patch despite early notification, the risk is elevated. Attackers who can log into the device can trigger this vulnerability remotely without user interaction.
- CVE-2026-14383HIGH 8.8
A flaw in Chrome's V8 JavaScript engine allows attackers to break out of the sandbox and run malicious code on a victim's computer by tricking them into visiting a specially crafted webpage. The vulnerability affects Chrome versions before 150.0.7871.46 and requires user interaction (clicking a link or visiting a site), but once exploited, gives an attacker full control over the browser process and potentially the underlying system.
- CVE-2026-14407HIGH 8.8
A flaw in Google Chrome's V8 JavaScript engine allows attackers to run malicious code inside the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special privileges. Once exploited, an attacker gains the ability to read sensitive data, modify information, or disrupt browser functionality from within the sandboxed environment.
- CVE-2026-14721HIGH 8.8
A stack-based buffer overflow vulnerability exists in UTT HiPER 1250GW wireless gateway devices up to firmware version 3.2.7-210907-180535. An authenticated attacker can overflow a buffer in the 5GHz wireless configuration endpoint by supplying a specially crafted SSID parameter, potentially achieving remote code execution. Public exploit code is available, elevating the practical risk.
- CVE-2026-12290HIGH 8.1
Mozilla has fixed a memory safety vulnerability in Firefox and Thunderbird that could allow attackers to compromise user confidentiality and data integrity. An attacker can exploit this flaw remotely over the network by tricking a user into visiting a malicious webpage or opening a specially crafted file. The vulnerability does not enable attackers to crash applications or cause denial of service, but it does create pathways to steal sensitive information or manipulate user data. Updates are available across Firefox, Firefox ESR (Extended Support Release), and Thunderbird versions.
- CVE-2026-12292HIGH 8.1
A boundary condition flaw in Firefox and Thunderbird's Web Audio component allows attackers to corrupt memory through specially crafted content. The vulnerability requires user interaction—such as visiting a malicious webpage or opening a hostile document—but once triggered, it can lead to information disclosure or arbitrary code execution. Mozilla has released patches across all affected product lines.
- CVE-2026-12326HIGH 8.1
Firefox and Thunderbird version 151 contain memory safety defects that could allow an attacker to run arbitrary code on an affected system. Mozilla patched these issues in version 152. While exploitation requires significant effort and specific conditions, the risk is serious because successful attacks could grant complete control over the affected application and potentially the underlying system.
- CVE-2026-12327HIGH 8.1
Mozilla has patched multiple memory safety flaws affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. These bugs can corrupt memory during program execution, and researchers believe they could potentially be exploited to execute arbitrary code on affected systems. The vulnerabilities have been fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- CVE-2026-42488HIGH 8.1
CVE-2026-42488 is a memory safety issue in hypervisor shadow paging logic where certain error handling paths fail to synchronize the active vCPU's page-table references with internal metadata structures. This desynchronization corrupts the mapcache—a critical component that tracks memory mappings—potentially allowing an attacker to read, modify, or crash the virtualized system. The flaw requires specific conditions to trigger (high complexity attack surface) but carries severe consequences if exploited.
- CVE-2026-12218HIGH 8.0
Yealink SIP-T46U IP phones running firmware version 108.87.50.1 contain a stack-based buffer overflow vulnerability in the web service. An attacker on the local network with user-level privileges can exploit this flaw by sending a specially crafted request to the `/api/inner/beforewifitest` endpoint, potentially executing arbitrary code or crashing the device. The vulnerability has been publicly disclosed, though the vendor is actively developing a patch.
- CVE-2026-12220HIGH 8.0
A stack-based buffer overflow vulnerability exists in Yealink SIP-T46U IP phones (firmware version 108.86.0.118 and potentially others) within the firmware upload mechanism. An authenticated attacker on the local network can exploit this by sending a specially crafted request to the firmware chunk upload endpoint, causing the application to write data beyond allocated buffer boundaries. This could lead to code execution or a device crash. The vulnerability requires local network access and valid credentials, which significantly constrains the attack surface but remains a serious risk in office environments where internal networks may not be fully trusted.
- CVE-2026-12221HIGH 8.0
Yealink SIP-T46U IP phones running firmware version 108.86.0.118 contain a stack-based buffer overflow in their firmware upgrade component. An attacker on the same local network who has valid credentials can send specially crafted upgrade requests with manipulated parameters to trigger the overflow, potentially allowing them to execute arbitrary code with the same privileges as the phone process. Proof-of-concept code has already been disclosed publicly, increasing immediate risk.
- CVE-2026-12222HIGH 8.0
A stack-based buffer overflow vulnerability exists in Yealink SIP-T46U IP phones running firmware version 108.86.0.118. The flaw is in the Web FastCGI Service's Bluetooth testing function, which fails to properly validate input parameters (btMac, pin, and reserved fields) when processing requests to the /api/inner/bttest endpoint. An attacker on the local network with user-level access can send specially crafted requests to overflow the stack and potentially execute arbitrary code on the phone. Public exploit code is available, increasing the practical risk.
- CVE-2026-0152HIGH 7.8
A memory management vulnerability exists in Android's OSMMapPMRGeneric function that allows a local attacker to manipulate virtual memory allocation beyond intended boundaries. By exploiting a logic error in the code, an authenticated user on the device can escalate their privileges to a higher level without needing any special system permissions or user interaction. This is a serious flaw because privilege escalation on mobile devices can grant attackers access to sensitive data and system-level controls.
- CVE-2026-12193HIGH 7.8
VS Revo RevoUninstaller versions 2.5.x and 2.6.x contain a heap-based buffer overflow flaw in the RevoDetector.sys driver's IOCTL handler. A local attacker with standard user privileges can exploit this to crash the system or potentially execute code with elevated privileges. The vulnerability requires local access and cannot be exploited remotely. A public exploit exists, elevating the practical risk. Upgrading to version 2.7.0 eliminates the vulnerability.
- CVE-2026-14605HIGH 7.8
RT-Thread versions up to 5.0.2 contain a stack-based buffer overflow vulnerability in the CAN (Controller Area Network) handler for Loongson LS1C devices. The flaw exists in the recvmsg function within the ls1c_can.h library component and can be exploited by a local attacker to corrupt memory on the stack, potentially leading to privilege escalation, data theft, or system compromise. An attacker must already have local system access to trigger the vulnerability, which significantly narrows the threat surface but remains serious in embedded or IoT deployment contexts where physical or administrative access may be easier to obtain.
- CVE-2026-14606HIGH 7.8
RT-Thread versions up to 5.0.2 contain a stack-based buffer overflow vulnerability in the SWM341 CAN (Controller Area Network) handler component. An attacker with local access and standard user privileges can trigger a buffer overflow through the CAN_Receive function, potentially allowing arbitrary code execution or system crash. The vulnerability is particularly concerning because exploit code has already been publicly released, making active exploitation more likely.
- CVE-2026-10701HIGH 7.5
Firefox's text rendering engine contains a flaw in how it validates memory boundaries when processing text data. An attacker on the network can exploit this without requiring user interaction or special permissions, allowing them to read sensitive information from the browser's memory. The vulnerability affects Firefox versions prior to 151.0.3.
- CVE-2026-12305HIGH 7.5
A memory safety vulnerability was discovered in Firefox and Thunderbird that could allow an attacker to crash the application or potentially cause other harmful effects through network access. The flaw affects the way these programs manage memory, and no user interaction is required for exploitation. Mozilla has patched this issue in recent versions of both applications.
- CVE-2026-12310HIGH 7.5
A memory safety vulnerability was discovered in Firefox and Thunderbird that allows an attacker to read sensitive information from an affected system without requiring user interaction or special privileges. The flaw stems from improper memory handling in the browser engine and has been patched in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. No active exploitation has been reported to CISA as of this analysis.
- CVE-2026-12312HIGH 7.5
A memory safety vulnerability in Mozilla Firefox and Thunderbird allows an attacker on the network to read sensitive information from an affected user's system without requiring any user interaction or special privileges. The issue stems from improper memory handling in the browser engine and has been resolved in the latest versions of both applications.
- CVE-2026-12314HIGH 7.5
A memory safety vulnerability in Firefox and Thunderbird allows an attacker to read sensitive data from affected browsers without user interaction. The flaw stems from unsafe memory handling that permits out-of-bounds reads. An attacker on the network can exploit this remotely to compromise the confidentiality of user data—such as cached credentials, browsing history, or page content—without requiring the user to click a malicious link or perform any action. The vulnerability does not enable data modification or system crashes.
- CVE-2026-12317HIGH 7.5
Mozilla has patched a memory safety vulnerability affecting Firefox and Thunderbird that could allow an attacker to crash the application remotely without any user interaction required. The flaw does not expose sensitive data or enable unauthorized modifications, but the denial-of-service capability makes it worth prompt attention, especially in environments where browser availability is critical.
- CVE-2026-12200HIGH 7.3
TinyWeb Server version 1.94 and earlier on Windows contains a stack-based buffer overflow vulnerability in how it processes the Authorization header. An attacker can send a specially crafted HTTP request with a malicious Authorization header to overflow the server's memory and potentially execute code, crash the service, or access sensitive data. The vulnerability requires no authentication or user interaction to exploit, making it actionable for remote attackers.
- CVE-2026-12318HIGH 7.3
A boundary condition error in the NSS (Network Security Services) Libraries component affects Mozilla Firefox and Thunderbird. This vulnerability allows attackers to send specially crafted network requests that can leak small amounts of sensitive data, corrupt application state, or crash the affected software. No user interaction is required for exploitation—an attacker on the network or a compromised website could trigger the flaw.
- CVE-2026-13592HIGH 7.3
A flaw in liftoff-sr CIPster allows an attacker on the network to send specially crafted EtherNet IP messages that cause the BufWriter::append function to write data beyond allocated memory boundaries. This out-of-bounds write vulnerability can corrupt data, crash the service, or potentially enable code execution. The vulnerability affects versions up to commit e8e9dba09bf56962807d3504b783ccdb6287f3e4, and a public exploit is now available, making active exploitation more likely.
- CVE-2026-12309MEDIUM 6.5
A memory safety vulnerability has been identified and patched in Mozilla Firefox and Thunderbird. The flaw allows an attacker to crash the affected application or potentially leak sensitive information without requiring user interaction or special privileges. Mozilla has released fixes in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12 to address this issue.
- CVE-2026-39872MEDIUM 6.5
CVE-2026-39872 is a memory handling flaw in Apple's Safari browser and related operating systems that can crash the application when processing malicious web content. An attacker would need to trick a user into visiting a crafted webpage, but no additional privileges or special conditions are required. The crash itself does not compromise data confidentiality or integrity—it simply denies availability of the browser temporarily. This is a moderate-severity issue affecting Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
- CVE-2026-43663MEDIUM 6.5
CVE-2026-43663 is a memory handling vulnerability affecting Safari and multiple Apple operating systems. When a user visits or interacts with a maliciously crafted website, the affected application can crash unexpectedly. While the crash itself prevents normal operation, the vulnerability does not enable attackers to steal data or take control of the device—it is primarily a denial-of-service issue triggered by user interaction with hostile web content.
- CVE-2026-43707MEDIUM 6.5
Apple has patched a memory corruption vulnerability affecting Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. An attacker can craft a malicious web page that, when visited, crashes the affected application. The vulnerability requires user interaction—specifically, visiting a compromised or attacker-controlled website—but poses no risk of data theft or system compromise beyond the denial of service from the crash itself.
- CVE-2026-43716MEDIUM 6.5
A memory handling flaw in Apple's Safari browser and related Apple platforms can crash the browser when processing specially crafted web content. An attacker would need to trick a user into visiting a malicious website; the crash itself does not enable data theft or system compromise, but it does disrupt service. Apple has released patches addressing the underlying memory issue across Safari, iOS, iPadOS, and macOS.
- CVE-2026-43740MEDIUM 6.5
Apple has patched a memory disclosure vulnerability affecting Safari, iOS, iPadOS, and macOS. When a user visits a maliciously crafted website, the browser can leak sensitive data from its process memory to an attacker. The flaw stems from insufficient memory handling in the browser's web content processing engine. While the vulnerability requires user interaction (visiting a malicious site), the confidentiality risk is significant enough that Apple classified it as MEDIUM severity and issued fixes across multiple platforms simultaneously.
- CVE-2026-52188MEDIUM 6.5
A buffer overflow flaw in UTT nv518G devices running firmware version nv518GV3v3.2.7-210919-161313 can be triggered remotely to crash the device or disrupt its operations. An attacker on the local network can send specially crafted network packets to the gohead HTTP service component, causing the device to run out of memory or fail, resulting in a denial-of-service condition. This is a memory safety issue where input validation is insufficient to prevent writing beyond allocated buffers.
- CVE-2026-0409MEDIUM 6.4
NETGEAR Orbi 370 series mesh routers contain a vulnerability that allows attackers to execute arbitrary commands on the device. An attacker must intercept and modify network traffic between the router and the Internet, then wait for the device administrator to perform specific management actions. The vulnerability affects Orbi 370, 371, 372, and 374 models running firmware versions prior to V12.1.2.7.
- CVE-2026-10064MEDIUM 6.3
TRENDnet has disclosed a remote stack-based buffer overflow vulnerability in the TEW-432BRP wireless router (firmware version 3.10B20 and earlier). An authenticated attacker can exploit this flaw by sending a specially crafted request to the port forwarding configuration endpoint, potentially allowing code execution or denial of service. The vendor has confirmed this product reached end-of-life in 2009 and will not issue patches. Public exploit code is available, elevating the practical risk despite the device's age.
- CVE-2026-10194MEDIUM 6.3
A heap-based buffer overflow exists in OFFIS DCMTK 3.7.0 within the query/retrieve service component (dcmqrscp). An authenticated attacker can trigger this flaw remotely by sending specially crafted requests to the image deletion function, potentially causing memory corruption, data loss, or service disruption. The vulnerability requires valid credentials to exploit but poses moderate risk in networked medical imaging environments where DCMTK is deployed.
- CVE-2026-10703MEDIUM 6.3
A use-after-free memory safety flaw exists in EIPStackGroup OpENer versions up to 2.3.0 within the SendRRData request handler. An authenticated attacker can remotely trigger memory corruption by crafting malicious messages, potentially leading to information disclosure or service disruption. The vulnerability has been publicly disclosed but the vendor has not yet acknowledged or released a patch.
- CVE-2026-12805MEDIUM 6.3
OFFIS DCMTK, a widely-used open-source DICOM toolkit for medical imaging, contains a buffer overflow vulnerability in its XML file parsing function. When the software processes a specially crafted XML file, an attacker can overwrite memory on the heap, potentially leading to information disclosure, data corruption, or application crash. The vulnerability requires user interaction—someone must open or process a malicious XML file—but no authentication is needed, and the attack can be triggered remotely by sending the file over the network.
- CVE-2026-14604MEDIUM 6.3
Assimp, an open-source 3D model import/export library widely used in game engines, graphics applications, and CAD tools, contains a memory management flaw in its PLY (Polygon File Format) handler. When exporting 3D models to the PLY format, the library can inadvertently free the same memory region twice—a condition known as a double-free error. An authenticated attacker can trigger this flaw remotely by submitting a specially crafted PLY file, leading to application crash or potential code execution. The vulnerability affects Assimp versions up to and including 6.0.4.
- CVE-2026-15105MEDIUM 6.3
A memory corruption vulnerability exists in snap7, an open-source library for communicating with Siemens S7 PLCs, affecting versions up to 1.4.3. When processing certain ReadVar requests, the TS7Worker::PerformFunctionRead handler writes data beyond the bounds of an allocated buffer. An attacker with access to the local network can trigger this flaw to corrupt memory, potentially causing crashes or enabling code execution. The vulnerability is publicly exploitable; proof-of-concept code has been released and the vendor has not yet issued a patch or timeline for remediation.