CVE-2026-87529 — CVSS 9.6 (critical): Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code…
CVE-2020-15202 — CVSS 9.0 (critical): In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a…
CVE-2026-63525 — CVSS 7.8 (high): Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-62698 — CVSS 7.8 (high): Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.
CVE-2026-50357 — CVSS 7.8 (high): Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-49792 — CVSS 7.8 (high): Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-44823 — CVSS 7.8 (high): Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-6965 — CVSS 7.7 (high): There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns…
CVE-2026-96280 — CVSS 7.5 (high): The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit…
CVE-2026-19667 — CVSS 7.5 (high): If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in…
CVE-2026-73523 — CVSS 7.5 (high): COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthenticated remote…
CVE-2026-42944 — CVSS 7.5 (high): NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID…
CVE-2026-101085 — CVSS 6.5 (medium): Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create…
CVE-2026-32240 — CVSS 6.5 (medium): Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a…
CVE-2023-36641 — CVSS 6.5 (medium): A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all…
CVE-2026-105768: apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5…
CVE-2026-86315 — CVSS 6.2 (medium): An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply…
CVE-2026-68895 — CVSS 5.5 (medium): Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally.
CVE-2026-55142 — CVSS 5.5 (medium): Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2022-34680 — CVSS 5.5 (medium): NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an…
CVE-2026-6039: LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The…