Vulnerability index

Browse CVEs

7,918 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 8.8
CVE-2026-15126

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome HIGH 8.8
CVE-2026-15110

Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to po…

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome HIGH 7.5
CVE-2026-15111

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome HIGH 8.8
CVE-2026-15112

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome CRITICAL 9.6
CVE-2026-15113

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via …

Fix: 150.0.7871.115+
Fix from $2,300 2026-07-08
Chrome HIGH 8.8
CVE-2026-15116

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome HIGH 7.5
CVE-2026-15117

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome HIGH 8.8
CVE-2026-15118

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Chrome HIGH 8.8
CVE-2026-15107

Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft…

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57250

When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, …

Fix: after 2026.1.1.70276
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57252

When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachm…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57256

When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57242

The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57244

After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failur…

Fix: after 2026.1.1.70276
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57245

When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to validate the abnormal annotation re…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57247

The application re-enters the document structure via field processing and deletes the current page, and then continues using the field objects obtain…

Fix: after 2026.1.1.70276
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57249

After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form event by additional action. Du…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57237

When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by t…

Fix: after 2026.1.1.70276
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57238

After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-57240

When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in inv…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-13126

The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invali…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-13127

The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page obj…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-13128

Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the d…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
Pdf Editor HIGH 7.8
CVE-2026-13129

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
X Server HIGH 7.8
CVE-2026-56000

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a H…

Fix: 21.2.24 / 24.1.13+
Fix from $1,950 2026-07-08
Openssh CRITICAL 9.4
CVE-2026-60002

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the cl…

Fix: 10.4+
Fix from $2,300 2026-07-08
Unclassified HIGH 7.8
CVE-2026-42958

The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This …

Mitigation only
Fix from $1,950 2026-07-07
Fastconnect 6700 Firmware HIGH 7.8
CVE-2025-59615

Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchroniz…

Patch available
Fix from $1,950 2026-07-06
Fastconnect 6700 Firmware HIGH 7.8
CVE-2025-59616

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.

Patch available
Fix from $1,950 2026-07-06
Fastconnect 6700 Firmware HIGH 7.3
CVE-2025-59617

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.

Patch available
Fix from $1,950 2026-07-06