The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
Volume of CVEs assigned to CWE-129 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
601 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-48503HIGH The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web conte | Aug 14, 2023 | 8.8 | 68 | YES | NO |
CVE-2021-35592MEDIUM Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and | Oct 20, 2021 | 6.3 | 47 | NO | NO |
CVE-2021-35598MEDIUM Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and pr | Oct 20, 2021 | 6.3 | 46 | NO | NO |
CVE-2021-35594MEDIUM Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and pr | Oct 20, 2021 | 6.3 | 46 | NO | NO |
CVE-2026-14191HIGH An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when th | Jul 1, 2026 | 7.8 | 39 | NO | NO |
CVE-2026-57270HIGH GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clou | Jul 2, 2026 | 8.3 | 37 | NO | NO |
CVE-2026-13131HIGH GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Clou | Jul 2, 2026 | 8.3 | 37 | NO | NO |
CVE-2026-56111CRITICAL Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handler that a | Jun 24, 2026 | 9.1 | 37 | NO | NO |
CVE-2026-25276HIGH Memory corruption while using Strongbox due to missing bounds check. | Jun 1, 2026 | 8.8 | 37 | NO | NO |
CVE-2017-7228HIGH An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM | Apr 4, 2017 | 8.2 | 37 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.