Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Firefox MEDIUM 6.5
CVE-2026-0885

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.…

Fix: 140.7.0 / 147.0+
Fix from $1,600 2026-01-13
Firefox HIGH 8.8
CVE-2026-0882

Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunder…

Fix: 115.32.0 / 140.7.0+
Fix from $1,950 2026-01-13
Firefox CRITICAL 9.8
CVE-2026-0884

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 1…

Fix: 140.7.0 / 147.0+
Fix from $2,300 2026-01-13
Usb Host Hid Driver MEDIUM 6.8
CVE-2025-68656

Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_request_get_descriptor() frees…

Fix: 1.1.0+
Fix from $1,600 2026-01-12
Android MEDIUM 6.7
CVE-2026-20968

Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Mitigation only
Fix from $1,600 2026-01-09
Android HIGH 7.8
CVE-2026-20971

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

Mitigation only
Fix from $1,950 2026-01-09
Wcd9378 Firmware MEDIUM 6.7
CVE-2025-47336

Memory corruption while performing sensor register read operations.

Patch available
Fix from $1,600 2026-01-07
Fastconnect 6700 Firmware MEDIUM 6.7
CVE-2025-47337

Memory corruption while accessing a synchronization object during concurrent operations.

Patch available
Fix from $1,600 2026-01-07
Fastconnect 6900 Firmware HIGH 7.8
CVE-2025-47339

Memory corruption while deinitializing a HDCP session.

No fix yet
Fix from $1,950 2026-01-07
Sa6150p Firmware MEDIUM 6.6
CVE-2025-47333

Memory corruption while handling buffer mapping operations in the cryptographic driver.

Patch available
Fix from $1,600 2026-01-07
Iccdev HIGH 7.8
CVE-2026-21486

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below contain Use After Free, Heap-…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-06
Iccdev CRITICAL 9.8
CVE-2026-21675

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free vulner…

Fix: 2.3.1.1+
Fix from $2,300 2026-01-06
Android MEDIUM 6.7
CVE-2025-20802

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has …

Mitigation only
Fix from $1,600 2026-01-06
Android MEDIUM 6.7
CVE-2025-20804

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has alread…

Mitigation only
Fix from $1,600 2026-01-06
Android MEDIUM 6.7
CVE-2025-20805

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has alread…

Mitigation only
Fix from $1,600 2026-01-06
Android MEDIUM 6.7
CVE-2025-20806

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has alread…

Mitigation only
Fix from $1,600 2026-01-06
Android MEDIUM 6.7
CVE-2025-20787

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al…

Mitigation only
Fix from $1,600 2026-01-06
Android HIGH 7.8
CVE-2025-20799

In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has alrea…

Mitigation only
Fix from $1,950 2026-01-06
Android HIGH 7.0
CVE-2025-20779

In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actor has alr…

Mitigation only
Fix from $1,950 2026-01-06
Android HIGH 7.8
CVE-2025-20780

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al…

Mitigation only
Fix from $1,950 2026-01-06
Android HIGH 7.8
CVE-2025-20781

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al…

Mitigation only
Fix from $1,950 2026-01-06
Android MEDIUM 6.7
CVE-2025-20785

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al…

Mitigation only
Fix from $1,600 2026-01-06
Android MEDIUM 6.7
CVE-2025-20786

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al…

Mitigation only
Fix from $1,600 2026-01-06
Nuttx HIGH 8.1
CVE-2025-48769

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer us…

Fix: 12.11.0+
Fix from $1,950 2026-01-01
Fontforge HIGH 8.8
CVE-2025-15280

FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15269

FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…

Mitigation only
Fix from $1,950 2025-12-31
Linux Kernel HIGH 7.8
CVE-2023-54207

In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Correct devm device reference for hidinput input_dev name Referen…

Fix: 5.10.249 / 5.15.199+
Fix from $1,950 2025-12-30
Nanomq HIGH 7.5
CVE-2025-59946

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which …

Fix: 0.24.4+
Fix from $1,950 2025-12-27
Fluidsynth HIGH 7.0
CVE-2025-68617

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading …

Fix: 2.5.2+
Fix from $1,950 2025-12-23
Gimp HIGH 7.8
CVE-2025-14424

GIMP XCF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…

Patch available
Fix from $1,950 2025-12-23