Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 8.8
CVE-2026-8549

Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome MEDIUM 6.5
CVE-2026-8550

Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain p…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Chrome HIGH 8.3
CVE-2026-8533

Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.3
CVE-2026-8523

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.3
CVE-2026-8530

Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to p…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.3
CVE-2026-8514

Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.3
CVE-2026-8515

Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to po…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.8
CVE-2026-8518

Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 7.5
CVE-2026-8521

Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traff…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.8
CVE-2026-8522

Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML pa…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome CRITICAL 9.6
CVE-2026-8511

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pa…

Fix: 148.0.7778.168+
Fix from $2,300 2026-05-14
Chrome HIGH 8.3
CVE-2026-8512

Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gesture…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome HIGH 8.3
CVE-2026-8513

Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to pot…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-41218

When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the ur…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
MongoDB MEDIUM 6.5
CVE-2026-8336

After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authentica…

Fix: 8.2.9 / 8.3.2+
Fix from $1,600 2026-05-13
MongoDB HIGH 8.8
CVE-2026-8201

A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd a…

Fix: 7.0.34 / 8.0.23+
Fix from $1,950 2026-05-13
Exim CRITICAL 9.8
CVE-2026-45185

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a c…

Fix: 4.99.3+
Fix from $2,300 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-42825

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows Server 2012 HIGH 7.8
CVE-2026-41095

Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40419

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 8.1
CVE-2026-40415

Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40418

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
Windows 11 23h2 CRITICAL 9.3
CVE-2026-40402

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.20348.5074 / 10.0.22631.7079+
Fix from $2,300 2026-05-12
Windows 10 1607 HIGH 7.5
CVE-2026-40406

Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-40408

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-40410

Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-40382

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40366

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40358

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40359

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20128+
Fix from $1,950 2026-05-12