Vulnerability index

Browse CVEs

7,918 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Mt6991 Firmware MEDIUM 6.0
CVE-2026-20473

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67299

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled …

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67300

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTI…

No fix yet
Fix from $1,950 2026-08-01
Zephyr HIGH 7.6
CVE-2026-10685

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->su…

Fix: 4.5.0+
Fix from $1,950 2026-07-31
Unclassified HIGH 8.1
CVE-2026-63035

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of serv…

No fix yet
Fix from $1,950 2026-07-30
Messagepack MEDIUM 5.4
CVE-2026-54522

MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/bu…

Fix: 1.8.2+
Fix from $1,600 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-51290

SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure wi…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-51291

sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.

No fix yet
Fix from $2,300 2026-07-30
Openvpn HIGH 8.1
CVE-2026-12996

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of serv…

Fix: 2.6.21 / 2.7.5+
Fix from $1,950 2026-07-30
Openvpn HIGH 8.1
CVE-2026-13117

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during…

Fix: 2.6.21 / 2.7.5+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-18017

Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-18012

Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted P…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17967

Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17947

Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome MEDIUM 5.5
CVE-2026-17932

Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive informatio…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome HIGH 8.8
CVE-2026-17920

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arb…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17924

Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perfo…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome HIGH 8.8
CVE-2026-17918

Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome MEDIUM 5.8
CVE-2026-17891

Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome HIGH 8.8
CVE-2026-17894

Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.5
CVE-2026-17896

Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.5
CVE-2026-17898

Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execu…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17881

Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17884

Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17886

Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.5
CVE-2026-17887

Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures t…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17875

Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted P…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.8
CVE-2026-17862

Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17836

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17832

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30