Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
365 Apps HIGH 8.4
CVE-2026-40361

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 7.0
CVE-2026-35418

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-35416

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Premiere Pro HIGH 7.8
CVE-2026-34638

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the …

Fix: 25.6.5 / 26.2+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-34345

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-34347

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 7.0
CVE-2026-34340

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows Server 2025 HIGH 8.0
CVE-2026-34332

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

Fix: 10.0.26100.32772+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34333

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 7.0
CVE-2026-34337

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34338

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 11 24h2 HIGH 7.8
CVE-2026-33840

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8390 / 10.0.26100.32772+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34330

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-34331

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 7.8
CVE-2026-33835

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.5
CVE-2026-32161

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthor…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Unclassified MEDIUM 6.8
CVE-2025-27723

Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Kernel may allow a denial of se…

Mitigation only
Fix from $1,600 2026-05-12
Firefox HIGH 7.3
CVE-2026-8390

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.

Fix: 150.0.3+
Fix from $1,950 2026-05-12
Ipados HIGH 7.5
CVE-2026-43668

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, …

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Ipados MEDIUM 5.3
CVE-2026-28994

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, …

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Ipados HIGH 7.5
CVE-2026-28969

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, …

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Ipados MEDIUM 6.5
CVE-2026-28942

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5,…

Fix: 26.5+
Fix from $1,600 2026-05-11
macOS MEDIUM 6.5
CVE-2026-28946

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously cr…

Fix: 26.5+
Fix from $1,600 2026-05-11
Ipados HIGH 8.8
CVE-2026-28947

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 an…

Fix: 26.5+
Fix from $1,950 2026-05-11
Ipados HIGH 7.5
CVE-2026-28883

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5,…

Fix: 26.5+
Fix from $1,950 2026-05-11
PHP CRITICAL 9.8
CVE-2026-6722

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mech…

Fix: 8.2.31 / 8.3.31+
Fix from $2,300 2026-05-10
PHP CRITICAL 9.8
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSIS…

Fix: 8.2.31 / 8.3.31+
Fix from $2,300 2026-05-10
Linux Kernel HIGH 7.8
CVE-2026-43458

In the Linux kernel, the following vulnerability has been resolved: serial: caif: hold tty->link reference in ldisc_open and ser_release A reproduc…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-05-08
Linux Kernel HIGH 7.3
CVE-2026-43459

In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: flush delayed work before removing DAIs and widgets When a soun…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-05-08
Linux Kernel HIGH 7.8
CVE-2026-43447

In the Linux kernel, the following vulnerability has been resolved: iavf: fix PTP use-after-free during reset Commit 7c01dbfc8a1c5f ("iavf: periodi…

Fix: 6.18.19 / 6.19.9+
Fix from $1,950 2026-05-08