Vulnerability index

Browse CVEs

7,918 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Chrome HIGH 7.5
CVE-2026-19176

Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitra…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19166

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19170

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19171

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome HIGH 8.3
CVE-2026-19172

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially pe…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 7.5
CVE-2026-19158

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI g…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 7.5
CVE-2026-19159

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.3
CVE-2026-19163

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to pot…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 7.5
CVE-2026-19165

Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to ex…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19149

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a craf…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome HIGH 8.8
CVE-2026-19151

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.3
CVE-2026-19154

Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.3
CVE-2026-19155

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.3
CVE-2026-19140

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perf…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.3
CVE-2026-19141

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 7.5
CVE-2026-19142

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.8
CVE-2026-19144

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.8
CVE-2026-19145

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.3
CVE-2026-19147

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-19108

A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file …

No fix yet
Fix from $1,600 2026-08-06
Chrome HIGH 8.3
CVE-2026-19137

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to pot…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-67863

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish …

No fix yet
Fix from $1,950 2026-08-05
Hardened Images HIGH 7.3
CVE-2026-71226

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allo…

Fix: 1.5.1+
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-0163

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege w…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 7.5
CVE-2026-56848

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resu…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-18785

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the…

No fix yet
Fix from $1,600 2026-08-04
Zephyr MEDIUM 6.5
CVE-2026-11368

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_dat…

Fix: 4.5.0+
Fix from $1,600 2026-08-04
Edge Chromium HIGH 7.5
CVE-2026-66315

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 151.0.4129.59+
Fix from $1,950 2026-08-04
365 Apps HIGH 8.8
CVE-2026-62870

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.1
CVE-2026-69244

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C resp…

No fix yet
Fix from $1,950 2026-08-03