Vulnerability index

Browse CVEs

7,925 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 8.8
CVE-2026-10890

Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruptio…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10891

Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10893

Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffi…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.3
CVE-2026-10894

Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pot…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10882

Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chrom…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.3
CVE-2026-10884

Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10885

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTM…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Libexpat MEDIUM 5.9
CVE-2026-50219

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset fr…

Fix: 2.8.2+
Fix from $1,600 2026-06-04
Html\ HIGH 7.5
CVE-2026-8829

HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cac…

Fix: 3.84+
Fix from $1,950 2026-06-04
Linux Kernel HIGH 7.8
CVE-2026-46267

In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freeing context llc_shdlc_deinit()…

Fix: 5.15.202 / 6.1.165+
Fix from $1,950 2026-06-03
Linux Kernel HIGH 8.4
CVE-2026-46270

In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_supply_changed() Using the `…

Fix: 5.10.252 / 5.15.202+
Fix from $1,950 2026-06-03
Linux Kernel HIGH 8.8
CVE-2026-46264

In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of devm_add_action_or_reset() failu…

Fix: 6.19.4+
Fix from $1,950 2026-06-03
Linux Kernel HIGH 7.8
CVE-2026-46246

In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler Using t…

Fix: 6.12.75 / 6.18.14+
Fix from $1,950 2026-06-03
Op Tee HIGH 7.8
CVE-2026-40290

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,950 2026-06-03
Unclassified MEDIUM 6.3
CVE-2026-10703

A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the f…

No fix yet
Fix from $1,600 2026-06-03
Unclassified MEDIUM 5.5
CVE-2025-60486

A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of …

Patch available
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.3
CVE-2026-10232

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the com…

No fix yet
Fix from $1,600 2026-06-01
Linux Kernel HIGH 7.8
CVE-2026-46242

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep…

Fix: 5.16 / 6.2+
Fix from $1,950 2026-05-30
Freerdp HIGH 8.8
CVE-2026-44422

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id…

Fix: 3.26.0+
Fix from $1,950 2026-05-29
Chrome HIGH 8.3
CVE-2026-9988

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a cr…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 7.5
CVE-2026-9990

Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9992

Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.3
CVE-2026-9993

Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially pe…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.3
CVE-2026-9994

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9995

Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.3
CVE-2026-9997

Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially pe…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9978

Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9984

Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page.…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.3
CVE-2026-9970

Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially pe…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9958

Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF …

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28