Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-126

MITRE ↗

CWE-126

33
HIGH
59
MEDIUM
5
LOW
100 CVEs · Page 2/2
6.5
CVE-2026-53414

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic

6.5
CVE-2026-65794

Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-69550

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.3
CVE-2026-20311

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta

6.1
CVE-2025-47331

Information disclosure while processing a firmware event.

6.1
CVE-2026-26169

Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.

6.1
CVE-2025-47406

Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.

6.1
CVE-2026-50813

An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the S

6.1
CVE-2026-50383

Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

5.9
CVE-2026-68819

Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.

5.5
CVE-2025-47330

Transient DOS while parsing video packets received from the video firmware.

5.5
CVE-2026-3203

RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

5.5
CVE-2026-6532

Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

5.5
CVE-2025-59609

Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.

5.5
CVE-2026-50341

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

5.5
CVE-2026-50475

Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.

5.5
CVE-2026-61347

Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62730

Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62746

Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62793

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

5.4
CVE-2026-62353

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/p

5.3
CVE-2026-26271

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_

5.3
CVE-2026-24028

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua cod

5.3
CVE-2026-5772

A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname

5.3
CVE-2026-41898

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampo

5.3
CVE-2026-8463

Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty enco

5.3
CVE-2026-49854

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tor

5.3
CVE-2026-55238

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Co

5.0
CVE-2026-11787

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without

4.9
CVE-2026-45684

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0

4.8
CVE-2026-40210

An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being se

4.7
CVE-2026-45460

Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.

4.6
CVE-2026-61350

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

4.5
CVE-2026-50485

Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

4.3
CVE-2026-0930

Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated us

4.3
CVE-2026-6575

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau

4.3
CVE-2025-43892

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v

4.3
CVE-2026-59840

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v

4.3
CVE-2026-14678

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a tab

4.3
CVE-2026-18024

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific

4.0
CVE-2026-27798

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

4.0
CVE-2026-27799

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

3.9
CVE-2025-66038

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com

3.5
CVE-2026-40341

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_u

3.1
CVE-2026-47088

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi

3.1
CVE-2026-76884

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

3.1
CVE-2026-76885

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVE-2026-65933

A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vuln

CVE-2026-65936

A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information

CVE-2026-70652

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahd

Frequently Asked Questions

What is CWE-126?

CWE-126 (CWE-126) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-126?

There are 100 CVE records associated with CWE-126 in our database. Of these, 0 are critical severity, 33 are high severity, and 59 are medium severity.

How can I protect against CWE-126 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-126 using AI-powered security agents.

Detect CWE-126 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-126 vulnerabilities across your infrastructure.

Get Started