CWE-129
High likelihoodImproper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
603 vulnerabilities with CWE-129
CVE-2026-23448
HIGH
net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check
CVSS 7.8
CVE-2026-23447
HIGH
net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
CVSS 7.8
CVE-2026-33762
LOW
go-git: Missing validation decoding Index v4 files leads to panic
CVSS 2.8
CVE-2026-32286
HIGH
Denial of service in github.com/jackc/pgproto3/v2
CVSS 7.5
CVE-2026-32285
HIGH
Denial of service in github.com/buger/jsonparser
CVSS 7.5
CVE-2026-23354
HIGH
x86/fred: Correct speculative safety in fred_extint()
CVSS 7.8
CVE-2026-33281
MEDIUM
Ella Core < 1.6.0 - Unauthenticated Denial of Service via NGAP Message PDU Session ID
CVSS 6.5
CVE-2026-33022
MEDIUM
Tekton Pipelines: Controller can panic when setting long resolver names in TaskRun/PipelineRun
CVSS 6.5
CVE-2026-32937
MEDIUM
free5GC CHF has Out-of-Bounds Slice Access that Leads to DoS
CVSS 6.5
CVE-2026-26933
MEDIUM
Improper Validation of Array Index in Packetbeat Leading to Denial of Service
CVSS 5.7
CVE-2026-31967
CRITICAL
HTSlib CRAM reader has out-of-bounds read due to improper validation of input
CVSS 9.1
CVE-2026-31966
CRITICAL
HTSlib CRAM reader has out-of-bounds read due to improper validation of input
CVSS 9.1
CVE-2026-31965
HIGH
HTSlib CRAM reader has out-of-bounds reads due to improper validation of input
CVSS 8.2
CVE-2026-31963
HIGH
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
CVSS 8.1
CVE-2026-31962
HIGH
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
CVSS 8.8
CVE-2026-23246
HIGH
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
CVSS 8.8
CVE-2026-3083
HIGH
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-30984
MEDIUM
iccDEV <2.3.1.5 - Memory Corruption
CVSS 6.1
CVE-2026-30982
MEDIUM
iccDEV <2.3.1.5 - Memory Corruption
CVSS 6.1
CVE-2026-26932
MEDIUM
Packetbeat 8.0.0-8.19.11 - Denial of Service via PostgreSQL Protocol Parser
CVSS 5.7
CVE-2026-25882
HIGH
Fiber 2.0.0-2.52.11 and 0-3.0.9 - Denial of Service via Route Parameter Overflow
CVSS 7.5
CVE-2026-2006
HIGH
PostgreSQL 14.0-14.20 - Remote Code Execution via Multibyte Character Length Mismanagement
CVSS 8.8
CVE-2026-25585
HIGH
iccdev < 2.3.1.3 - Out-of-bounds Read in IccCmm.cpp
CVSS 7.8
CVE-2026-25518
MEDIUM
cert-manager 1.18.0-1.18.4 and 1.19.0-1.19.2 - Denial of Service via ACME DNS-01 Processing
CVSS 5.9
CVE-2026-25068
MEDIUM
alsa-lib <1.2.15.2 - Buffer Overflow
Details
Vulnerabilities
603
Exploit Likelihood
High