Vulnerability index

Browse CVEs

7,925 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Pdf Editor HIGH 7.8
CVE-2026-13129

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid…

Fix: after 2026.1.1.36485
Fix from $1,950 2026-07-08
X Server HIGH 7.8
CVE-2026-56000

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a H…

Fix: 21.2.24 / 24.1.13+
Fix from $1,950 2026-07-08
Openssh CRITICAL 9.4
CVE-2026-60002

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the cl…

Fix: 10.4+
Fix from $2,300 2026-07-08
Unclassified HIGH 7.8
CVE-2026-42958

The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This …

Mitigation only
Fix from $1,950 2026-07-07
Fastconnect 6700 Firmware HIGH 7.8
CVE-2025-59615

Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchroniz…

Patch available
Fix from $1,950 2026-07-06
Fastconnect 6700 Firmware HIGH 7.8
CVE-2025-59616

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.

Patch available
Fix from $1,950 2026-07-06
Fastconnect 6700 Firmware HIGH 7.3
CVE-2025-59617

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.

Patch available
Fix from $1,950 2026-07-06
Radare2 HIGH 7.8
CVE-2026-14788

A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the fi…

Fix: after 6.1.6
Fix from $1,950 2026-07-06
Radare2 HIGH 7.8
CVE-2026-14760

A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the…

Fix: 6.1.8+
Fix from $1,950 2026-07-05
Linux Kernel HIGH 8.8
CVE-2026-53359

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af…

Fix: 6.1.177 / 6.6.144+
Fix from $1,950 2026-07-04
Edge Chromium HIGH 7.5
CVE-2026-58294

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 8.3
CVE-2026-58287

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 8.3
CVE-2026-58288

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 7.5
CVE-2026-57992

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 7.5
CVE-2026-58276

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 8.8
CVE-2026-57981

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 7.5
CVE-2026-57984

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 7.5
CVE-2026-57986

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Curl HIGH 7.3
CVE-2026-9080

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts…

Fix: 8.21.0+
Fix from $1,950 2026-07-03
Curl CRITICAL 9.8
CVE-2026-10536

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CUR…

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Fireware HIGH 8.1
CVE-2026-13368

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2.…

Fix: 11.12.4 / 12.5.19+
Fix from $1,950 2026-07-03
Linux Kernel HIGH 8.0
CVE-2026-53357

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept…

Fix: 5.10.259 / 5.15.210+
Fix from $1,950 2026-07-02
Chrome CRITICAL 9.6
CVE-2026-14425

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 150.0.7871.46+
Fix from $2,300 2026-07-01
Chrome HIGH 7.5
CVE-2026-14426

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to exec…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Chrome HIGH 8.8
CVE-2026-14432

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Chrome CRITICAL 9.6
CVE-2026-14417

Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…

Fix: 150.0.7871.46+
Fix from $2,300 2026-07-01
Chrome CRITICAL 9.6
CVE-2026-14419

Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…

Fix: 150.0.7871.46+
Fix from $2,300 2026-07-01
Chrome CRITICAL 9.6
CVE-2026-14424

Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted…

Fix: 150.0.7871.46+
Fix from $2,300 2026-07-01
Chrome CRITICAL 9.6
CVE-2026-14398

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 150.0.7871.46+
Fix from $2,300 2026-07-01
Chrome HIGH 8.8
CVE-2026-14403

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01