Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Linux Kernel HIGH 7.3
CVE-2026-43497

In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free dlfb_ops_mm…

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-05-21
Linux Kernel HIGH 7.8
CVE-2026-43499

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter()…

Fix: 6.1.175 / 6.6.140+
Fix from $1,950 2026-05-21
FreeBSD HIGH 7.8
CVE-2026-45251

A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. Because the blocked thread doe…

Mitigation only
Fix from $1,950 2026-05-21
Chrome HIGH 8.8
CVE-2026-9126

Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Fix: 148.0.7778.178+
Fix from $1,950 2026-05-20
Chrome HIGH 8.8
CVE-2026-9118

Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.…

Fix: 148.0.7778.178+
Fix from $1,950 2026-05-20
Chrome HIGH 8.8
CVE-2026-9120

Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chrom…

Fix: 148.0.7778.178+
Fix from $1,950 2026-05-20
Chrome HIGH 8.8
CVE-2026-9112

Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

Fix: 148.0.7778.179+
Fix from $1,950 2026-05-20
Chrome HIGH 8.8
CVE-2026-9114

Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious…

Fix: 148.0.7778.179+
Fix from $1,950 2026-05-20
Chrome HIGH 8.8
CVE-2026-9111

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML pag…

Fix: 148.0.7778.179+
Fix from $1,950 2026-05-20
Bind MEDIUM 5.9
CVE-2026-5947

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SI…

Fix: 9.20.23 / 9.21.22+
Fix from $1,600 2026-05-20
Bind CRITICAL 9.8
CVE-2026-3593

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 thr…

Fix: 9.20.23 / 9.21.22+
Fix from $2,300 2026-05-20
Unbound CRITICAL 9.8
CVE-2026-33278

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible …

Fix: 1.25.1+
Fix from $2,300 2026-05-20
Firefox CRITICAL 9.6
CVE-2026-8953

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefo…

Fix: 115.36.0 / 140.11+
Fix from $2,300 2026-05-19
Firefox HIGH 7.3
CVE-2026-8947

Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderb…

Fix: 115.36.0 / 140.11+
Fix from $1,950 2026-05-19
Escargot CRITICAL 9.8
CVE-2026-47310

Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6…

Patch available
Fix from $2,300 2026-05-19
Unclassified MEDIUM 6.5
CVE-2026-28733

in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.

No fix yet
Fix from $1,600 2026-05-19
Open5gs MEDIUM 6.5
CVE-2026-8746

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function discover_handler in the library /lib/sbi/nghttp2-s…

Fix: after 2.7.7
Fix from $1,600 2026-05-17
Radare2 CRITICAL 9.8
CVE-2026-8696

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cau…

Fix: after 6.1.4
Fix from $2,300 2026-05-15
Radare2 CRITICAL 9.8
CVE-2026-8695

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption b…

Fix: after 6.1.4
Fix from $2,300 2026-05-15
Unclassified MEDIUM 6.9
CVE-2025-48521

Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, pote…

Mitigation only
Fix from $1,600 2026-05-15
Chrome HIGH 8.8
CVE-2026-8587

Use after free in Extensions in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extensio…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome CRITICAL 9.6
CVE-2026-8580

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 148.0.7778.168+
Fix from $2,300 2026-05-14
Chrome HIGH 8.8
CVE-2026-8581

Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.3
CVE-2026-8574

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.3
CVE-2026-8575

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perfo…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.8
CVE-2026-8555

Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 7.5
CVE-2026-8557

Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perfor…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.8
CVE-2026-8551

Use after free in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.3
CVE-2026-8542

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.8
CVE-2026-8544

Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14