Vulnerability index

Browse CVEs

7,925 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Safari MEDIUM 6.5
CVE-2026-43742

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43746

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari HIGH 8.8
CVE-2026-43715

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe…

Fix: 26.5.2+
Fix from $1,950 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43716

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Proces…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43717

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43720

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 5.3
CVE-2026-43704

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43709

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-39872

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43663

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43699

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Hardened Images MEDIUM 5.3
CVE-2026-13595

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers …

Fix: 2.42.2+
Fix from $1,600 2026-06-29
Zephyr HIGH 7.4
CVE-2026-10646

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct g…

Fix: after 4.4.1
Fix from $1,950 2026-06-28
FreeBSD HIGH 7.0
CVE-2026-49417

Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory could …

Mitigation only
Fix from $1,950 2026-06-27
FreeBSD HIGH 7.8
CVE-2026-49412

The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, then reacquired the lock. Du…

Mitigation only
Fix from $1,950 2026-06-27
Linux Kernel HIGH 7.8
CVE-2026-53300

In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix NTMP DMA use-after-free issue The AI-generated review reported …

Fix: 6.18.33 / 7.0.10+
Fix from $1,950 2026-06-26
Linux Kernel HIGH 7.8
CVE-2026-53296

In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: free channels on probe error On probe error, free the pr…

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-06-26
Linux Kernel HIGH 7.8
CVE-2026-53290

In the Linux kernel, the following vulnerability has been resolved: drm/xe/eustall: Fix drm_dev_put called before stream disable in close In xe_eu_…

Fix: 6.18.33 / 7.0.10+
Fix from $1,950 2026-06-26
Envoy MEDIUM 5.9
CVE-2026-48090

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (e…

Fix: 1.37.5 / 1.38.3+
Fix from $1,600 2026-06-26
Envoy MEDIUM 5.9
CVE-2026-47205

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free…

Fix: 1.36.9 / 1.37.5+
Fix from $1,600 2026-06-26
Envoy MEDIUM 6.5
CVE-2026-47207

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy c…

Fix: 1.35.13 / 1.36.9+
Fix from $1,600 2026-06-26
Chrome HIGH 7.5
CVE-2026-13283

Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific U…

Fix: 149.0.7827.201+
Fix from $1,950 2026-06-25
Chrome MEDIUM 6.8
CVE-2026-13282

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via ph…

Fix: 149.0.7827.201+
Fix from $1,600 2026-06-25
Wolfssl CRITICAL 9.8
CVE-2026-7531

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server…

Fix: 5.9.2+
Fix from $2,300 2026-06-25
Gpac HIGH 7.8
CVE-2025-60464

A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to caus…

Fix: 26.02.0+
Fix from $1,950 2026-06-25
Gpac MEDIUM 6.1
CVE-2025-60465

A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause …

Fix: 26.02.0+
Fix from $1,600 2026-06-25
Daqfactory HIGH 7.8
CVE-2026-12921

In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files whi…

Fix: after 21.1
Fix from $1,950 2026-06-25
Nokogiri MEDIUM 6.6
CVE-2026-57438

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML:…

Fix: 1.19.4+
Fix from $1,600 2026-06-25
Nokogiri HIGH 7.5
CVE-2026-57435

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a R…

Fix: 1.19.4+
Fix from $1,950 2026-06-25
Nokogiri MEDIUM 5.3
CVE-2026-57436

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that…

Fix: 1.19.4+
Fix from $1,600 2026-06-25