Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
FreeBSD HIGH 8.4
CVE-2026-5398

The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' sessi…

Mitigation only
Fix from $1,950 2026-04-22
Firefox HIGH 7.5
CVE-2026-6784

Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6754

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 1…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6758

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6759

Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6746

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 15…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6747

Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-21
Thin Vec MEDIUM 5.1
CVE-2026-6654

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skip…

No fix yet
Fix from $1,600 2026-04-20
Chrome HIGH 8.8
CVE-2026-6318

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 7.5
CVE-2026-6319

Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific U…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6358

Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a craf…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6359

Use after free in Video in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to per…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6360

Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially exploit object corruption via a crafte…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6315

Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specifi…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6316

Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6317

Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromiu…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.3
CVE-2026-6309

Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perf…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.3
CVE-2026-6310

Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6302

Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6303

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.3
CVE-2026-6304

Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.3
CVE-2026-6297

Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbo…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6299

Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Ch…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6300

Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Libsixel HIGH 7.3
CVE-2026-33021

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in six…

Fix: 1.8.7-r1+
Fix from $1,950 2026-04-14
Libsixel HIGH 7.8
CVE-2026-33023

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 op…

Fix: after 1.8.7
Fix from $1,950 2026-04-14
Framemaker HIGH 7.8
CVE-2026-27292

Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the cont…

Fix: 2022.9+
Fix from $1,950 2026-04-14
Libsixel HIGH 7.0
CVE-2026-33018

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via th…

Fix: 1.8.7-r1+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-33104

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
365 Apps HIGH 8.4
CVE-2026-33115

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14