Vulnerability index

Browse CVEs

7,918 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Linux Kernel HIGH 7.8
CVE-2026-64251

In the Linux kernel, the following vulnerability has been resolved: pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() pwrseq_debugfs_se…

Fix: 6.12.95 / 6.18.38+
Fix from $1,950 2026-07-24
Linux Kernel HIGH 7.8
CVE-2026-64239

In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() DAMON sysfs mai…

Fix: 6.6.143 / 6.12.93+
Fix from $1,950 2026-07-24
Linux Kernel HIGH 7.8
CVE-2026-64245

In the Linux kernel, the following vulnerability has been resolved: fbdev: modedb: fix a possible UAF in fb_find_mode() If mode_option is NULL, it …

Fix unknown
Fix from $1,950 2026-07-24
Linux Kernel HIGH 7.8
CVE-2026-64226

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path In scx_root_…

Fix: 6.12.92 / 6.18.34+
Fix from $1,950 2026-07-24
Linux Kernel CRITICAL 9.8
CVE-2026-64216

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_ab…

Fix: 6.18.34 / 7.0.11+
Fix from $2,300 2026-07-24
Linux Kernel HIGH 7.8
CVE-2026-64221

In the Linux kernel, the following vulnerability has been resolved: spi: ti-qspi: fix use-after-free after DMA setup failure The driver falls back …

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-07-24
Ddk HIGH 7.8
CVE-2026-49743

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in t…

Fix: 26.1+
Fix from $1,950 2026-07-24
Chrome HIGH 8.3
CVE-2026-16804

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially pe…

Fix: 150.0.7871.186+
Fix from $1,950 2026-07-23
Chrome HIGH 8.8
CVE-2026-16805

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 150.0.7871.186+
Fix from $1,950 2026-07-23
Chrome HIGH 8.8
CVE-2026-16806

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Fix: 150.0.7871.186+
Fix from $1,950 2026-07-23
MongoDB MEDIUM 6.5
CVE-2026-13071

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side…

No fix yet
Fix from $1,600 2026-07-22
Unbound MEDIUM 5.9
CVE-2026-50046

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('se…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound MEDIUM 5.9
CVE-2026-52863

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of t…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Chrome CRITICAL 9.6
CVE-2026-16424

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to poten…

Fix: 150.0.7871.182+
Fix from $2,300 2026-07-21
Chrome HIGH 8.8
CVE-2026-16423

Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to pot…

Fix: 150.0.7871.182+
Fix from $1,950 2026-07-21
Hardened Images HIGH 7.5
CVE-2026-59850

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data …

No fix yet
Fix from $1,950 2026-07-21
Firefox CRITICAL 10.0
CVE-2026-16367

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16356

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefo…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox HIGH 8.8
CVE-2026-16362

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbir…

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16351

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 1…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16352

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefo…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16353

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunder…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Fory HIGH 7.3
CVE-2026-60080

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted …

Fix: 1.4.0+
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.6
CVE-2026-63729

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free …

No fix yet
Fix from $1,600 2026-07-21
Chrome HIGH 8.8
CVE-2026-15904

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI ges…

Fix: 150.0.7871.128+
Fix from $1,950 2026-07-20
Chrome HIGH 7.8
CVE-2026-15905

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file.…

Fix: 150.0.7871.128+
Fix from $1,950 2026-07-20
Chrome CRITICAL 9.6
CVE-2026-15899

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via…

Fix: 150.0.7871.128+
Fix from $2,300 2026-07-20
Chrome CRITICAL 9.6
CVE-2026-15900

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a cra…

Fix: 150.0.7871.128+
Fix from $2,300 2026-07-20
Chrome CRITICAL 9.6
CVE-2026-15901

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 150.0.7871.128+
Fix from $2,300 2026-07-20
Chrome HIGH 8.8
CVE-2026-15902

Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…

Fix: 150.0.7871.128+
Fix from $1,950 2026-07-20