Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Windows 10 21h2 HIGH 7.8
CVE-2026-27924

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7184 / 10.0.19045.7184+
Fix from $1,950 2026-04-14
Windows 10 1607 MEDIUM 6.5
CVE-2026-27925

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1809 HIGH 7.0
CVE-2026-27926

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an autho…

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,950 2026-04-14
Windows 10 1809 HIGH 7.0
CVE-2026-27927

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized att…

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-27922

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-27923

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-27921

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevat…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-27917

Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-27915

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-27916

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-27911

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attac…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-27908

Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-27909

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 11 23h2 HIGH 7.8
CVE-2026-26181

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.6936 / 10.0.25398.2274+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-26182

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-26177

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-26173

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-26174

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized att…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 21h2 HIGH 7.8
CVE-2026-26172

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.19044.7184 / 10.0.19045.7184+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-26167

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-26168

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 11 23h2 HIGH 7.0
CVE-2026-26165

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.5020 / 10.0.22631.6936+
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-23657

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
Indesign HIGH 7.8
CVE-2026-27283

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in th…

Fix: 20.5.3 / 21.3+
Fix from $1,950 2026-04-14
Imagemagick MEDIUM 5.5
CVE-2026-40311

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap u…

Fix: 6.9.13-44 / 7.1.2-19+
Fix from $1,600 2026-04-13
Unclassified HIGH 8.1
CVE-2026-6100

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `M…

Patch available
Fix from $1,950 2026-04-13
Nitro Pdf Pro HIGH 8.4
CVE-2025-69627

Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). Durin…

Mitigation only
Fix from $1,950 2026-04-13
Linux Kernel HIGH 7.0
CVE-2026-31426

In the Linux kernel, the following vulnerability has been resolved: ACPI: EC: clean up handlers on probe failure in acpi_ec_setup() When ec_install…

Fix: 6.1.168 / 6.6.131+
Fix from $1,950 2026-04-13
Linux Kernel HIGH 7.8
CVE-2026-31419

In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast()…

Fix: 5.11 / 5.16+
Fix from $1,950 2026-04-13
Harmonyos HIGH 7.1
CVE-2026-34854

UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

No fix yet
Fix from $1,950 2026-04-13