CVEs classified under CWE-789, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-82435 — CVSS 9.8 (critical): Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames…
CVE-2026-77410: RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with…
CVE-2021-34869 — CVSS 8.8 (high): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker…
CVE-2021-34868 — CVSS 8.8 (high): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker…
CVE-2026-63574: Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPac…
CVE-2026-103603: Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy…
CVE-2026-63566: Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the…
CVE-2026-69219: The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1…
CVE-2026-58067: A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.
CVE-2026-20295 — CVSS 8.6 (high): A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow…
CVE-2026-12185 — CVSS 8.6 (high): In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects…
CVE-2024-20260 — CVSS 8.6 (high): Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance…
CVE-2021-34867 — CVSS 8.2 (high): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker…
CVE-2026-78861 — CVSS 7.7 (high): An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key
CVE-2026-20048 — CVSS 7.7 (high): A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could…
CVE-2026-102731 — CVSS 7.5 (high): Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small…
CVE-2026-92550 — CVSS 7.5 (high): A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service…
CVE-2026-77322 — CVSS 7.5 (high): SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a…
CVE-2026-59991 — CVSS 7.5 (high): psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy()…
CVE-2026-58268 — CVSS 7.5 (high): SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates…
CVE-2026-94626 — CVSS 7.5 (high): vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing…
CVE-2026-77301 — CVSS 7.5 (high): adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an…
CVE-2026-85715 — CVSS 7.5 (high): ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in…
CVE-2026-55149 — CVSS 7.5 (high): Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in…
CVE-2026-91752 — CVSS 7.5 (high): GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a…
CVE-2026-67211 — CVSS 7.5 (high): OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The…
CVE-2026-88045 — CVSS 7.5 (high): rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the…
CVE-2026-85445 — CVSS 7.5 (high): MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count…
CVE-2026-85442 — CVSS 7.5 (high): MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated…
CVE-2026-81693 — CVSS 7.5 (high): openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply…
CVE-2026-81692 — CVSS 7.5 (high): openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files…
CVE-2026-75935 — CVSS 7.5 (high): Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial…
CVE-2026-46603 — CVSS 7.5 (high): VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many…
CVE-2026-19566 — CVSS 7.5 (high): Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The…
CVE-2026-15567 — CVSS 7.5 (high): A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an…
CVE-2026-66733 — CVSS 7.5 (high): Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that…
CVE-2026-70377 — CVSS 7.5 (high): imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no…
CVE-2026-67589 — CVSS 7.5 (high): A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service…
CVE-2026-67551 — CVSS 7.5 (high): pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service…
CVE-2026-66273 — CVSS 7.5 (high): A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service…
CVE-2026-14682 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects…
CVE-2026-12852 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
CVE-2026-58060 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects…
CVE-2026-59649 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects…
CVE-2026-59646 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects…
CVE-2026-65315 — CVSS 7.5 (high): Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to…
CVE-2026-40378 — CVSS 7.5 (high): Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker…
CVE-2026-55213 — CVSS 7.5 (high): h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o…
CVE-2026-55380 — CVSS 7.5 (high): Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header…