CVEs classified under CWE-789, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2021-34869 — CVSS 8.8 (high): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker…
CVE-2021-34868 — CVSS 8.8 (high): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker…
CVE-2026-69219: The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1…
CVE-2026-58067: A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.
CVE-2026-14682: In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects…
CVE-2026-12852: In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
CVE-2026-58060: In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects…
CVE-2026-59649: In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects…
CVE-2026-59646: In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects…
CVE-2024-20260 — CVSS 8.6 (high): A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall…
CVE-2021-34867 — CVSS 8.2 (high): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker…
CVE-2026-20048 — CVSS 7.7 (high): A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could…
CVE-2026-75935 — CVSS 7.5 (high): Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial…
CVE-2026-46603 — CVSS 7.5 (high): VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many…
CVE-2026-19566 — CVSS 7.5 (high): Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The…
CVE-2026-15567 — CVSS 7.5 (high): A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an…
CVE-2026-66733 — CVSS 7.5 (high): Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that…
CVE-2026-70377 — CVSS 7.5 (high): imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no…
CVE-2026-61485 — CVSS 7.5 (high): ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy…
CVE-2026-67589 — CVSS 7.5 (high): A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service…
CVE-2026-67551 — CVSS 7.5 (high): pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service…
CVE-2026-66273 — CVSS 7.5 (high): A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service…
CVE-2026-65315 — CVSS 7.5 (high): Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to…
CVE-2026-40378 — CVSS 7.5 (high): Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker…
CVE-2026-55213 — CVSS 7.5 (high): h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o…
CVE-2026-55380 — CVSS 7.5 (high): Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header…
CVE-2026-55379 — CVSS 7.5 (high): Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file…
CVE-2026-54060 — CVSS 7.5 (high): Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap…
CVE-2026-54059 — CVSS 7.5 (high): Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section…
CVE-2026-53917 — CVSS 7.5 (high): Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ…
CVE-2026-53916 — CVSS 7.5 (high): Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An…
CVE-2026-50734 — CVSS 7.5 (high): Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An…
CVE-2026-10142 — CVSS 7.5 (high): kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or…
CVE-2026-49975 — CVSS 7.5 (high): Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP…
CVE-2026-9538 — CVSS 7.5 (high): Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar()…
CVE-2018-25368 — CVSS 7.5 (high): Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an…
CVE-2021-47973 — CVSS 7.5 (high): Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively…
CVE-2021-47972 — CVSS 7.5 (high): Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the application by creating…
CVE-2021-47971 — CVSS 7.5 (high): My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long…
CVE-2021-47970 — CVSS 7.5 (high): Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with…
CVE-2021-47969 — CVSS 7.5 (high): Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long…
CVE-2026-44375 — CVSS 7.5 (high): Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack contains an…
CVE-2021-47944 — CVSS 7.5 (high): memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long…
CVE-2026-42440 — CVSS 7.5 (high): OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before 1.9.5 before 2.5.9…
CVE-2026-33524 — CVSS 7.5 (high): Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted…
CVE-2026-35186 — CVSS 7.5 (high): Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backend contains a bug…
CVE-2026-24146 — CVSS 7.5 (high): NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a large number of outputs could cause a…
CVE-2026-39312 — CVSS 7.5 (high): SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authentication denial-of-service…