CWE-476: NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
1,433 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-24826 — Out-of-bounds write in turso3d
- CVE-2026-21688 — iccDEV has Type Confusion in SIccCalcOp::ArgsPushed() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-21485 — iccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()
- CVE-2026-28390 — Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo
- CVE-2026-28389 — Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo
- CVE-2026-28388 — NULL Pointer Dereference When Processing a Delta CRL
- CVE-2025-69421 — NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function
- CVE-2026-33063 — free5GC AUSF UE Authentication Panic on Nil SuciSupiMap Interface Conversion
- CVE-2026-2507 — BIG-IP TMM Vulnerability
- CVE-2026-24813 — A null pointer dereference in abcz316/SKRoot-linuxKernelRoot
- CVE-2025-68274 — SIPGO library has response DoS vulnerability via nil pointer dereference
- CVE-2025-61960 — BIG-IP APM portal access vulnerability
- CVE-2025-61668 — @plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user
- CVE-2025-59777 — NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in co
- CVE-2025-59668 — Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafte
- CVE-2025-58120 — BIG-IP Next (CNF, SPK, and Kubernetes) vulnerability
- CVE-2025-52585 — BIG-IP Client SSL profile vulnerability
- CVE-2025-41433 — BIG-IP SIP ALG profile vulnerability
- CVE-2025-41414 — BIG-IP HTTP/2 vulnerability
- CVE-2025-30645 — Junos OS: SRX Series: Transmission of specific control traffic sent out of a DS-Lite tunnel results in flowd crash
Recently published
- CVE-2026-86547 — mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER
- CVE-2026-84392 — A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all v
- CVE-2026-82055 — Null Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of Service
- CVE-2026-18453 — 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search
- CVE-2026-86097 — PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select
- CVE-2026-80118 — PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL
- CVE-2026-17273 — IBM i is Affected By Multiple Vulnerabilities in Debug Server
- CVE-2026-85150 — Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header
- CVE-2026-17539 — RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL
- CVE-2026-78222 — NGINX ngx_http_js_module vulnerability
- CVE-2026-82926 — NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mT
- CVE-2026-82821 — FLVMeta AMF Object Parsing amf.c amf_object_get null pointer dereference
- CVE-2026-82803 — armink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMENT null pointer dereference
- CVE-2026-82588 — Open5GS Transfer Endpoint namf-handler.c null pointer dereference
- CVE-2026-76650 — Pre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query Processing in TP-Link TL-WR841N
- CVE-2026-76649 — Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Processing in TP-Link TL-WR841N
- CVE-2026-81490 — MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of SQL Service
- CVE-2026-77217 — PLANET GS-4210-16P2S V3 Stack Buffer Overflow and NULL Pointer Dereference via dispatcher.cgi RADIUS Handlers
- CVE-2026-75125 — PLANET GS-4210-16P2S V3 Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_post
- CVE-2026-54084 — Wazuh agent enrollment NULL pointer dereference via malformed manager response