Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Substance 3d Stager HIGH 7.8
CVE-2026-27277

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the c…

Fix: 3.1.8+
Fix from $1,950 2026-03-10
Firefox HIGH 8.8
CVE-2026-3847

Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of…

Fix: 148.0.2+
Fix from $1,950 2026-03-10
Iccdev HIGH 7.8
CVE-2026-30978

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-use-after-free in CIcc…

Fix: 2.3.1.5+
Fix from $1,950 2026-03-10
Windows 10 21h2 HIGH 7.8
CVE-2026-26132

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7058 / 10.0.19045.7058+
Fix from $1,950 2026-03-10
365 Copilot HIGH 7.8
CVE-2026-26134

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

Fix: 16.0.19822.20000+
Fix from $1,950 2026-03-10
365 Apps HIGH 7.8
CVE-2026-26107

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20102+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.8
CVE-2026-25189

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-25178

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 11 23h2 HIGH 7.0
CVE-2026-25170

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4830 / 10.0.22631.6783+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-25171

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 11 24h2 HIGH 7.4
CVE-2026-25167

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.26100.7979 / 10.0.26100.32463+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.8
CVE-2026-24292

Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-24295

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorize…

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-24289

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
365 Copilot HIGH 7.0
CVE-2026-24285

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 8.8
CVE-2026-23669

Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-23671

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an auth…

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.0
CVE-2026-23667

Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
Imagemagick MEDIUM 5.3
CVE-2026-28687

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-a…

Fix: 6.9.13-41 / 7.1.2-16+
Fix from $1,600 2026-03-10
Imagemagick MEDIUM 5.3
CVE-2026-28688

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-a…

Fix: 6.9.13-41 / 7.1.2-16+
Fix from $1,600 2026-03-10
Pjsip HIGH 7.5
CVE-2026-28799

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in P…

Fix: 2.17+
Fix from $1,950 2026-03-06
Unclassified HIGH 7.1
CVE-2025-13350

Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB s…

Mitigation only
Fix from $1,950 2026-03-05
Nanomq MEDIUM 5.3
CVE-2026-22040

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency p…

Fix: 0.24.6+
Fix from $1,600 2026-03-04
Linux Kernel HIGH 7.8
CVE-2026-23234

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid UAF in f2fs_write_end_io() As syzbot reported an use-after-f…

Fix: 5.10.251 / 5.15.201+
Fix from $1,950 2026-03-04
Linux Kernel HIGH 7.8
CVE-2026-23231

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addc…

Fix: 6.1.165 / 6.6.128+
Fix from $1,950 2026-03-04
Android MEDIUM 6.7
CVE-2026-0027

In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privileg…

Patch available
Fix from $1,600 2026-03-02
Ar8031 Firmware HIGH 7.8
CVE-2025-47386

Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.

Patch available
Fix from $1,950 2026-03-02
Lemans Au Lgit Firmware HIGH 7.8
CVE-2025-47381

Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs.

Patch available
Fix from $1,950 2026-03-02
Ar8035 Firmware HIGH 7.8
CVE-2025-47377

Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.

Patch available
Fix from $1,950 2026-03-02
Sa8295p Firmware HIGH 7.8
CVE-2025-47379

Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resour…

Patch available
Fix from $1,950 2026-03-02