Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Harmonyos HIGH 7.1
CVE-2026-34859

UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Mitigation only
Fix from $1,950 2026-04-13
Netwide Assembler CRITICAL 9.6
CVE-2026-6068

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global d…

No fix yet
Fix from $2,300 2026-04-10
Wolfssl MEDIUM 6.5
CVE-2026-5460

A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the error handling path of TLSX_KeyS…

Fix: 5.9.1+
Fix from $1,600 2026-04-10
Hdf5 HIGH 7.8
CVE-2026-34734

HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply…

Fix: 1.14.1-2+
Fix from $1,950 2026-04-09
Wasmtime MEDIUM 5.0
CVE-2026-34983

Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free bugs. This bug is not contro…

Mitigation only
Fix from $1,600 2026-04-09
Chrome CRITICAL 9.6
CVE-2026-5874

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Fix: 147.0.7727.55+
Fix from $2,300 2026-04-08
Chrome HIGH 8.8
CVE-2026-5877

Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome HIGH 8.8
CVE-2026-5883

Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome HIGH 8.8
CVE-2026-5866

Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome HIGH 8.8
CVE-2026-5872

Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome HIGH 8.8
CVE-2026-5860

Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome HIGH 8.8
CVE-2026-5861

Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
OpenSSL HIGH 8.1
CVE-2026-28387

Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA reco…

Fix: 1.1.1zg / 3.0.20+
Fix from $1,950 2026-04-07
Cups MEDIUM 6.2
CVE-2026-39316

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free v…

Fix: after 2.4.16
Fix from $1,600 2026-04-07
Kafka HIGH 8.7
CVE-2026-35554

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. …

Fix: 3.9.2 / 4.0.2+
Fix from $1,950 2026-04-07
Electron MEDIUM 5.5
CVE-2026-34764

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5,…

Fix: 39.8.5 / 40.8.5+
Fix from $1,600 2026-04-06
Cologne Firmware HIGH 7.8
CVE-2026-21380

Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.

No fix yet
Fix from $1,950 2026-04-06
Fastconnect 6900 Firmware MEDIUM 6.5
CVE-2025-47374

Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.

Patch available
Fix from $1,600 2026-04-06
Linux Kernel HIGH 8.8
CVE-2026-31408

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold …

Fix: 5.15.203 / 6.1.168+
Fix from $1,950 2026-04-06
Electron HIGH 8.8
CVE-2026-34772

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and…

Fix: 38.8.6 / 39.8.0+
Fix from $1,950 2026-04-04
Electron HIGH 8.1
CVE-2026-34774

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0,…

Fix: 39.8.1 / 40.7.0+
Fix from $1,950 2026-04-04
Electron HIGH 8.8
CVE-2026-34770

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and…

Fix: 38.8.6 / 39.8.1+
Fix from $1,950 2026-04-04
Electron HIGH 8.8
CVE-2026-34771

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and…

Fix: 38.8.6 / 39.8.0+
Fix from $1,950 2026-04-04
Linux Kernel HIGH 7.8
CVE-2026-31399

In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchronous initialization Dingiso…

Fix: 4.5 / 4.10+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 7.8
CVE-2026-31396

In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock PTP clock is registered on ev…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 7.8
CVE-2026-31389

In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregis…

Fix: 6.1.167 / 6.6.130+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 8.8
CVE-2026-23461

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user After commit ab4e…

Fix: 6.6.130 / 6.12.78+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 8.8
CVE-2026-23462

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: Fix possible UAF This fixes the following trace caused by not …

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 7.8
CVE-2026-23458

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() ctnetlink_d…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-03
Linux Kernel CRITICAL 9.8
CVE-2026-23450

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller repo…

Fix: 5.15.203 / 6.1.167+
Fix from $2,300 2026-04-03