Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Windows 11 23h2 HIGH 7.0
CVE-2026-21241

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.4711 / 10.0.22631.6649+
Fix from $1,950 2026-02-10
Windows 10 21h2 HIGH 7.0
CVE-2026-21242

Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6937 / 10.0.19045.6937+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21235

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 21h2 HIGH 7.0
CVE-2026-21237

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attac…

Fix: 10.0.19044.6937 / 10.0.19045.6937+
Fix from $1,950 2026-02-10
Lrzip HIGH 7.8
CVE-2025-15570

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulatio…

Fix: after 0.651
Fix from $1,950 2026-02-10
Freerdp HIGH 7.5
CVE-2026-24684

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the …

Fix: 3.22.0+
Fix from $1,950 2026-02-09
Freerdp CRITICAL 9.1
CVE-2026-24677

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts server-controlled dimensions and …

Fix: 3.22.0+
Fix from $2,300 2026-02-09
Freerdp HIGH 7.5
CVE-2026-24678

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callb…

Fix: 3.22.0+
Fix from $1,950 2026-02-09
Freerdp HIGH 7.5
CVE-2026-24680

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New frees data on failure, then pointer_free calls sdl_…

Fix: 3.22.0+
Fix from $1,950 2026-02-09
Freerdp HIGH 7.5
CVE-2026-24681

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completions can use a freed channel cal…

Fix: 3.22.0+
Fix from $1,950 2026-02-09
Freerdp HIGH 7.5
CVE-2026-24683

FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a local variable and later uses i…

Fix: 3.22.0+
Fix from $1,950 2026-02-09
Freerdp HIGH 7.5
CVE-2026-24491

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, video_timer can send client notifications after the control channel…

Fix: 3.22.0+
Fix from $1,950 2026-02-09
Freerdp HIGH 7.5
CVE-2026-24675

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, urb_select_interface can free the device's MS config on error but l…

Fix: 3.22.0+
Fix from $1,950 2026-02-09
Freerdp HIGH 7.5
CVE-2026-24676

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, AUDIN format renegotiation frees the active format list while the c…

Fix: 3.22.0+
Fix from $1,950 2026-02-09
Emui MEDIUM 5.5
CVE-2026-24927

Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2026-02-06
Harmonyos MEDIUM 5.5
CVE-2026-24930

UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2026-02-06
Harmonyos MEDIUM 5.5
CVE-2026-24914

Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2026-02-06
Emui MEDIUM 5.5
CVE-2026-24917

UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2026-02-06
Mruby MEDIUM 5.5
CVE-2026-1979

A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization.…

Fix: after 3.4.0
Fix from $1,600 2026-02-06
Esp Idf MEDIUM 6.3
CVE-2026-25507

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a use-after-free vulnerab…

Patch available
Fix from $1,600 2026-02-04
Linux Kernel HIGH 7.8
CVE-2026-23089

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free() When snd_usb_create…

Fix: 5.10.249 / 5.15.199+
Fix from $1,950 2026-02-04
Linux Kernel HIGH 7.8
CVE-2026-23074

In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of te…

Fix: 5.10.249 / 5.15.199+
Fix from $1,950 2026-02-04
Linux Kernel HIGH 7.8
CVE-2026-23077

In the Linux kernel, the following vulnerability has been resolved: mm/vma: fix anon_vma UAF on mremap() faulted, unfaulted merge Patch series "mm/…

Fix: 6.18.8+
Fix from $1,950 2026-02-04
Sa9000p Firmware HIGH 7.8
CVE-2025-47398

Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.

Patch available
Fix from $1,950 2026-02-02
Fastconnect 6900 Firmware HIGH 7.8
CVE-2025-47358

Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently.

Mitigation only
Fix from $1,950 2026-02-02
Qca6391 Firmware HIGH 7.8
CVE-2025-47359

Memory Corruption when multiple threads simultaneously access a memory free API.

Mitigation only
Fix from $1,950 2026-02-02
Android HIGH 7.8
CVE-2026-20411

In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious actor has …

Mitigation only
Fix from $1,950 2026-02-02
Android MEDIUM 6.7
CVE-2026-20414

In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor h…

Mitigation only
Fix from $1,600 2026-02-02
Monkey HIGH 7.5
CVE-2025-63651

A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (…

Fix: after 1.8.5
Fix from $1,950 2026-01-29
Monkey HIGH 7.5
CVE-2025-63652

A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (Do…

Fix: after 1.8.5
Fix from $1,950 2026-01-29