Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Debian Linux HIGH 7.3
CVE-2025-62230

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data struc…

Fix: 21.1.19+
Fix from $1,950 2025-10-30
Cobalt HIGH 7.8
CVE-2025-11465

Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2025-10-29
Wazuh HIGH 7.5
CVE-2025-62788

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_event_for_log() references memo…

Fix: 4.11.0+
Fix from $1,950 2025-10-29
Fade In HIGH 7.8
CVE-2025-53814

A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .xml file can lead t…

No fix yet
Fix from $1,950 2025-10-28
Firefox CRITICAL 9.8
CVE-2025-12380

Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-rel…

Fix: 144.0.2+
Fix from $2,300 2025-10-28
Kamailio HIGH 7.8
CVE-2025-12205

A vulnerability was detected in Kamailio 5.5. The affected element is the function sr_push_yy_state of the file src/core/cfg.lex of the component Con…

No fix yet
Fix from $1,950 2025-10-27
Unclassified HIGH 7.5
CVE-2025-12105

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP…

Mitigation only
Fix from $1,950 2025-10-23
MongoDB MEDIUM 6.5
CVE-2025-11979

An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issu…

Fix: 7.0.25 / 8.0.15+
Fix from $1,600 2025-10-20
Unclassified MEDIUM 6.3
CVE-2025-11677

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations …

Mitigation only
Fix from $1,600 2025-10-20
Envoy HIGH 7.5
CVE-2025-62504

Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain a use-after-free vulnerabili…

Fix: 1.33.12 / 1.34.10+
Fix from $1,950 2025-10-16
Quickjs HIGH 8.8
CVE-2025-62490

In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a …

Fix: 2025-09-13+
Fix from $1,950 2025-10-16
Quickjs HIGH 8.8
CVE-2025-62491

A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promis…

Fix: 2025-09-13+
Fix from $1,950 2025-10-16
Big Ip Next Cloud Native Network Functions HIGH 7.5
CVE-2025-48008

When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacke…

Fix: 15.1.10.8 / 16.1.6+
Fix from $1,950 2025-10-15
Animate HIGH 7.8
CVE-2025-54279

Animate versions 23.0.13, 24.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the con…

Fix: 23.0.15 / 24.0.12+
Fix from $1,950 2025-10-15
Dimension HIGH 7.8
CVE-2025-61801

Dimension versions 4.1.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of t…

Fix: 4.1.5+
Fix from $1,950 2025-10-14
Substance 3d Stager HIGH 7.8
CVE-2025-61802

Substance3D - Stager versions 3.1.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the c…

Fix: 3.1.5+
Fix from $1,950 2025-10-14
Framemaker HIGH 7.8
CVE-2025-54281

Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in …

Fix: 2020.10 / 2022.8+
Fix from $1,950 2025-10-14
Windows 10 21h2 HIGH 7.8
CVE-2025-59290

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6332 / 10.0.19045.6332+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-59282

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to e…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59243

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59234

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19328.20000+
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59236

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20059+
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59238

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59225

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20059+
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59226

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59227

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19328.20000+
Fix from $1,950 2025-10-14
365 Apps HIGH 7.0
CVE-2025-59221

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59222

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59223

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20059+
Fix from $1,950 2025-10-14
365 Apps HIGH 7.8
CVE-2025-59224

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20059+
Fix from $1,950 2025-10-14