CWE-129
High likelihoodImproper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
603 vulnerabilities with CWE-129
CVE-2026-56111
CRITICAL
Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler
CVSS 9.1
CVE-2026-52915
HIGH
netfilter: ip6t_hbh: reject oversized option lists
CVSS 7.1
CVE-2026-32682
MEDIUM
NGINX Gateway Fabric vulnerability
CVSS 6.5
CVE-2026-45624
MEDIUM
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
CVSS 5.1
CVE-2026-45359
MEDIUM
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
CVSS 5.7
CVE-2026-24181
HIGH
Nvidia Dali - Improper Validation of Array Index
CVSS 7.3
CVE-2026-25276
HIGH
Qualcomm Snapdragon Secure Processor - Strongbox Bounds Check Memory Corruption
CVSS 8.8
CVE-2026-46163
HIGH
wifi: b43legacy: enforce bounds check on firmware key index in RX path
CVSS 7.8
CVE-2026-46122
HIGH
wifi: b43: enforce bounds check on firmware key index in b43_rx()
CVSS 7.8
CVE-2026-45104
HIGH
MapServer: NULL pointer dereference in SLD `<ElseFilter>` rule parsing reachable via WMS `SLD_BODY`
CVSS 7.5
CVE-2026-45896
HIGH
mtd: intel-dg: Fix accessing regions before setting nregions
CVSS 7.8
CVE-2026-45839
HIGH
bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()
CVSS 7.8
CVE-2026-46598
MEDIUM
Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
CVSS 5.3
CVE-2026-44310
MEDIUM
gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
CVSS 5.4
CVE-2026-44222
MEDIUM
vLLM: Remote DoS via Special-Token Placeholders
CVSS 6.5
CVE-2026-41643
HIGH
GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
CVSS 7.5
CVE-2026-40251
MEDIUM
Incus out-of-bounds panic in snapshot metadata handling allows denial of service
CVSS 6.5
CVE-2026-31776
HIGH
ALSA: ctxfi: Fix missing SPDIFI1 index handling
CVSS 7.8
CVE-2026-31764
HIGH
iio: imu: st_lsm6dsx: Set buffer sampling frequency for accelerometer only
CVSS 7.8
CVE-2026-31729
HIGH
usb: typec: ucsi: validate connector number in ucsi_notify_common()
CVSS 7.8
CVE-2026-40886
HIGH
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller
CVSS 7.7
CVE-2026-6840
MEDIUM
Samsung ONE <1.30.0 - Memory Corruption
CVSS 5.5
CVE-2026-40097
LOW
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
CVSS 3.7
CVE-2026-34942
MEDIUM
Wasmtime panics when transcoding misaligned utf-16 strings
CVSS 6.5
CVE-2026-21413
CRITICAL
LibRaw - Heap-Based Buffer Overflow in lossless_jpeg_load_raw
CVSS 9.8
Details
Vulnerabilities
603
Exploit Likelihood
High