Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Pjsip HIGH 8.1
CVE-2026-32942

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability i…

Fix: 2.17+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4458

Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convinced a user to install a malicious extension to po…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4454

Use after free in Network in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4456

Use after free in Digital Credentials API in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the renderer process…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4445

Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4446

Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4449

Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4441

Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Samtools CRITICAL 9.8
CVE-2026-31972

SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been a…

Fix: 1.21.1+
Fix from $2,300 2026-03-18
Linux Kernel HIGH 7.8
CVE-2026-23270

In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks …

Fix: 5.15.203 / 6.1.167+
Fix from $1,950 2026-03-18
Linux Kernel HIGH 7.8
CVE-2026-23248

In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in perf_mmap Syzkaller reported a…

Fix: 6.18.17 / 6.19.7+
Fix from $1,950 2026-03-18
MongoDB HIGH 8.8
CVE-2026-4148

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $looku…

Fix: 7.0.31 / 8.0.20+
Fix from $1,950 2026-03-17
Enterprise Linux HIGH 7.5
CVE-2026-4271

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme…

No fix yet
Fix from $1,950 2026-03-17
Px4 Drone Autopilot MEDIUM 5.3
CVE-2026-32724

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() functi…

Fix: 1.17.0+
Fix from $1,600 2026-03-16
Unclassified MEDIUM 5.3
CVE-2026-3979

A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulatio…

Patch available
Fix from $1,600 2026-03-12
Chrome HIGH 8.8
CVE-2026-3936

Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a c…

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Chrome HIGH 8.8
CVE-2026-3917

Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Chrome HIGH 8.8
CVE-2026-3918

Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Chrome HIGH 8.8
CVE-2026-3919

Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to pot…

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Chrome HIGH 8.8
CVE-2026-3921

Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Chrome HIGH 8.8
CVE-2026-3922

Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Chrome HIGH 8.8
CVE-2026-3923

Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Chrome HIGH 7.5
CVE-2026-3924

use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to potentia…

Fix: 146.0.7680.71+
Fix from $1,950 2026-03-11
Curl HIGH 7.5
CVE-2026-3805

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

Fix: 8.19.0+
Fix from $1,950 2026-03-11
Acrobat Dc HIGH 7.8
CVE-2026-27278

Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbi…

Fix: 24.001.30356 / 25.001.21288+
Fix from $1,950 2026-03-10
Acrobat Dc HIGH 7.8
CVE-2026-27220

Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbi…

Fix: 24.001.30356 / 25.001.21288+
Fix from $1,950 2026-03-10
Android HIGH 7.4
CVE-2026-0112

In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no…

Mitigation only
Fix from $1,950 2026-03-10
Envoy MEDIUM 5.9
CVE-2026-26311

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerability in Envoy's HTTP connection…

Fix: 1.34.13 / 1.35.8+
Fix from $1,600 2026-03-10
Envoy HIGH 7.5
CVE-2026-26330

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit filter, if the response phase …

Fix: 1.34.13 / 1.35.8+
Fix from $1,950 2026-03-10
Substance 3d Stager HIGH 7.8
CVE-2026-27276

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the c…

Fix: 3.1.8+
Fix from $1,950 2026-03-10