Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Linux Kernel HIGH 7.0
CVE-2026-23454

In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardo…

Fix: 5.15.203 / 6.1.167+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 7.8
CVE-2026-23432

In the Linux kernel, the following vulnerability has been resolved: mshv: Fix use-after-free in mshv_map_user_memory error path In the error path o…

Fix: 6.19.10+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 7.8
CVE-2026-23427

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in durable v2 replay of active file handles parse_dur…

Fix: 6.6.130 / 6.12.78+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 7.8
CVE-2026-23428

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of share_conf in compound request smb2_get_ksmbd_tcon…

Fix: 5.15.203 / 6.1.167+
Fix from $1,950 2026-04-03
Linux Kernel HIGH 7.8
CVE-2026-23412

In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qia…

Fix: 6.6.130 / 6.12.78+
Fix from $1,950 2026-04-02
Linux Kernel HIGH 7.8
CVE-2026-23413

In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback asymmetry Fix a use-after-f…

Fix: 6.6.130 / 6.10+
Fix from $1,950 2026-04-02
Linux Kernel HIGH 7.8
CVE-2026-23415

In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() During …

Fix: 6.18.21 / 6.19.11+
Fix from $1,950 2026-04-02
Linux Kernel MEDIUM 5.5
CVE-2026-23401

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE Wh…

Fix: 5.15.203 / 6.1.168+
Fix from $1,600 2026-04-01
Chrome HIGH 8.8
CVE-2026-5286

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromiu…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome HIGH 8.8
CVE-2026-5287

Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome CRITICAL 9.6
CVE-2026-5288

Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to p…

Fix: 146.0.7680.177+
Fix from $2,300 2026-04-01
Chrome CRITICAL 9.6
CVE-2026-5289

Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 146.0.7680.177+
Fix from $2,300 2026-04-01
Chrome CRITICAL 9.6
CVE-2026-5290

Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentia…

Fix: 146.0.7680.177+
Fix from $2,300 2026-04-01
Chrome HIGH 8.8
CVE-2026-5278

Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome HIGH 8.8
CVE-2026-5280

Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome HIGH 8.8
CVE-2026-5281 KEV

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitra…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome HIGH 7.5
CVE-2026-5284

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitra…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome HIGH 8.8
CVE-2026-5285

Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Chrome MEDIUM 6.3
CVE-2026-5273

Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM…

Fix: 146.0.7680.177+
Fix from $1,600 2026-04-01
Pdf Editor HIGH 7.8
CVE-2026-3779

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows cr…

Fix: after 2025.3.0.69570
Fix from $1,950 2026-04-01
Pdf Editor HIGH 7.8
CVE-2026-3777

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and p…

Fix: after 2025.3.0.69570
Fix from $1,950 2026-04-01
Dnsdist HIGH 7.5
CVE-2026-27854

An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in cust…

Fix: 1.9.12 / 2.0.3+
Fix from $1,950 2026-03-31
Substance 3d Stager HIGH 7.8
CVE-2026-27309

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the c…

Fix: 3.1.8+
Fix from $1,950 2026-03-27
Unclassified MEDIUM 6.5
CVE-2024-14028

Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.…

Mitigation only
Fix from $1,600 2026-03-27
Libpng HIGH 7.5
CVE-2026-33416

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versio…

Fix: 1.6.56+
Fix from $1,950 2026-03-26
Everest HIGH 7.5
CVE-2026-27828

EVerest is an EV charging software stack. Prior to version 2026.02.0, ISO15118_chargerImpl::handle_session_setup uses v2g_ctx after it has been freed…

Fix: 2026.02.0+
Fix from $1,950 2026-03-26
Everest MEDIUM 5.3
CVE-2026-27813

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This is triggered by EV plug-in/unp…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Squid HIGH 7.5
CVE-2026-33526EPSS 9%

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP tr…

Fix: 7.5+
Fix from $1,950 2026-03-26
Squid HIGH 7.5
CVE-2026-32748EPSS 9%

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bug…

Fix: 7.5+
Fix from $1,950 2026-03-26
Cryptodev Linux HIGH 7.8
CVE-2026-28529

cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allow…

Fix: after 1.14
Fix from $1,950 2026-03-25