comms/libmodbus libmodbus-3.2.0 ! CVE-2024-34244 7.5 libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. Thi ! CVE-2024-36845 4.3 An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers t devel/capstone capstone-5.0.9 ! CVE-2026-55893 7.3 Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode ! CVE-2026-55894 6.8 Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode ! CVE-2026-49282 5.1 Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and p ! CVE-2025-67873 4.8 Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow ! CVE-2025-68114 4.8 Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow a ! CVE-2026-49263 2.0 Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and devel/php-geshi php-geshi-1.0.9.1_1 ! CVE-2025-2123 5.1 GeSHi CSS cssgen.php get_var cross site scripting devel/py-capstone py312-capstone-5.0.9 ! CVE-2026-55893 7.3 Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode ! CVE-2026-55894 6.8 Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode ! CVE-2026-49282 5.1 Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and p ! CVE-2025-67873 4.8 Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow ! CVE-2025-68114 4.8 Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow a ! CVE-2026-49263 2.0 Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and devel/radare2 radare2-6.1.4 ! CVE-2026-8695 8.7 radare2 6.1.5 Use-After-Free via gdbr_threads_list() ! CVE-2026-8696 8.7 radare2 6.1.5 Use-After-Free via gdbr_pids_list() ! CVE-2026-40527 8.5 radare2 Command Injection via DWARF Parameter Names ! CVE-2026-14757 4.8 radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow ! CVE-2026-14758 4.8 radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow ! CVE-2026-14759 4.8 radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_si ! CVE-2026-14760 4.8 radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free ! CVE-2026-14761 4.8 radareorg radare2 str.c r_str_append integer overflow ! CVE-2026-14786 4.8 radareorg radare2 str.c r_str_word_get0set integer overflow ! CVE-2026-14787 4.8 radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow ! CVE-2026-14788 4.8 radareorg radare2 cfile.c r_core_bin_load use after free ! CVE-2026-14789 4.8 radareorg radare2 Memory64ListStream mdmp.c stack-based overflow emulators/qemu qemu-11.1.1 ! CVE-2024-6519 8.2 Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability ! CVE-2023-2680 7.5 Dma reentrancy issue (incomplete fix for cve-2021-3750) ! CVE-2023-3354 7.5 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of s ! CVE-2023-3180 6.0 Heap buffer overflow in virtio_crypto_sym_op_helper() ! CVE-2024-8354 5.5 Qemu-kvm: usb: assertion failure in usb_ep_get() ! CVE-2023-1386 3.3 Qemu: 9pfs: suid/sgid bits not dropped on file write emulators/qemu-devel qemu-devel-11.0.20260731 ! CVE-2024-6519 8.2 Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability ! CVE-2023-2680 7.5 Dma reentrancy issue (incomplete fix for cve-2021-3750) ! CVE-2023-3354 7.5 Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of s ! CVE-2023-3180 6.0 Heap buffer overflow in virtio_crypto_sym_op_helper() ! CVE-2024-8354 5.5 Qemu-kvm: usb: assertion failure in usb_ep_get() ! CVE-2023-1386 3.3 Qemu: 9pfs: suid/sgid bits not dropped on file write lang/guile1 guile1-1.8.8_2 ! CVE-2016-8605 5.3 guile: Thread-unsafe umask modification sysutils/consul consul-2.0.3_2 ! CVE-2026-87090 8.3 Consul vulnerable to an authorization bypass in the catalog node-write path ! CVE-2026-88021 7.5 Consul vulnerable to an authorization bypass in the Connect service mesh ! CVE-2026-87106 6.5 Consul vulnerable to a denial of service in the native RPC listener www/dojo dojo-1.15.6 ! CVE-2021-23450 7.5 Prototype Pollution www/minio minio-2025.10.15.17.29.55_14 ! CVE-2026-33322 9.2 MinIO: JWT Algorithm Confusion in OIDC Authentication ! CVE-2026-33419 9.1 MinIO: LDAP login brute-force via user enumeration and missing rate limit ! CVE-2026-40344 8.8 MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-T ! CVE-2026-41145 8.8 MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in ! CVE-2018-1000538 7.5 Minio Inc. Minio S3 server version prior to RELEASE.2018-05-16T23-35-33Z contains a Alloca ! CVE-2026-34204 7.1 MinIO is Vulnerable to SSE Metadata Injection via Replication Headers ! CVE-2026-39414 7.1 MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing ! CVE-2026-42600 6.9 MinIO: Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint 1160 port(s): 354 with CPE, 11 affected, 0 with only unconfirmed CVEs, 8 with no known CVEs; 806 without CPE info, 0 make error(s) [maintainer: bofh@FreeBSD.org]. 6 link(s) to CVEs rejected by their CNA skipped. ! = affected (CNA ranges, else NVD CPE data) ? = linked CVE without usable version data