Vulnerability index

Browse CVEs

7,918 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Windows 11 24h2 HIGH 7.0
CVE-2026-50323

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.0
CVE-2026-49806

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker…

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.8
CVE-2026-49808

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat…

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 10 21h2 HIGH 7.8
CVE-2026-50293

Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.0
CVE-2026-50296

Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.0
CVE-2026-49802

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker…

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 8.8
CVE-2026-49795

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 CRITICAL 9.3
CVE-2026-49798

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1809 HIGH 7.0
CVE-2026-49183

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker…

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.0
CVE-2026-49784

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attac…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49171

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 11 26h1 HIGH 7.8
CVE-2026-49173

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.28000.2269 / 10.0.28000.2525+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.8
CVE-2026-49166

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-49167

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows Server 2025 HIGH 8.8
CVE-2026-49169

Use after free in DNS Server allows an authorized attacker to execute code over a network.

Fix: 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 11 23h2 HIGH 7.0
CVE-2026-48571

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.7376 / 10.0.26100.8875+
Fix from $1,950 2026-07-14
Windows 11 23h2 HIGH 7.0
CVE-2026-48572

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to…

Fix: 10.0.22631.7376 / 10.0.26100.8875+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.0
CVE-2026-49162

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 11 23h2 HIGH 7.8
CVE-2026-44800

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.22631.7376 / 10.0.26100.8875+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.1
CVE-2026-42900

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to e…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Gawk HIGH 7.5
CVE-2026-40467

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects g…

Fix: after 5.4.0
Fix from $1,950 2026-07-13
Zephyr HIGH 7.8
CVE-2026-10667

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dyna…

Fix: after 4.4.1
Fix from $1,950 2026-07-12
Zephyr MEDIUM 6.1
CVE-2026-10663

In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device s…

Fix: 4.5.0+
Fix from $1,600 2026-07-12
Imagemagick HIGH 7.5
CVE-2026-61861

ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can tri…

Fix: 6.9.13-51 / 7.1.2-26+
Fix from $1,950 2026-07-11
Ddk HIGH 7.8
CVE-2026-34196

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow and map two GPU virtual addres…

Fix: 26.1+
Fix from $1,950 2026-07-10
Imagemagick MEDIUM 5.3
CVE-2026-56373

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attack…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,600 2026-07-10
Chrome HIGH 8.8
CVE-2026-15129

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome HIGH 8.8
CVE-2026-15133

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome HIGH 8.3
CVE-2026-15120

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome HIGH 8.8
CVE-2026-15121

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08