Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Windows 10 21h2 MEDIUM 6.7
CVE-2025-26681

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.5737 / 10.0.19045.5737+
Fix from $1,600 2025-04-08
Windows Server 2008 HIGH 8.1
CVE-2025-26671

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 8.1
CVE-2025-26670EPSS 10%

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 8.1
CVE-2025-26663

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.8
CVE-2025-26648

Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 11 22h2 HIGH 7.0
CVE-2025-26649

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker t…

Fix: 10.0.20348.3453 / 10.0.22621.5189+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 7.0
CVE-2025-26640

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Unclassified HIGH 8.3
CVE-2025-31498

c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqu…

Patch available
Fix from $1,950 2025-04-08
Qam8255p Firmware HIGH 7.8
CVE-2025-21437

Memory corruption while processing memory map or unmap IOCTL operations simultaneously.

Mitigation only
Fix from $1,950 2025-04-07
Fastconnect 7800 Firmware HIGH 7.8
CVE-2025-21436

Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.

Mitigation only
Fix from $1,950 2025-04-07
Qam8255p Firmware MEDIUM 6.7
CVE-2024-49848

Memory corruption while processing multiple IOCTL calls from HLOS to DSP.

Mitigation only
Fix from $1,600 2025-04-07
C V2x 9150 Firmware MEDIUM 6.6
CVE-2024-45544

Memory corruption while processing IOCTL calls to add route entry in the HW.

No fix yet
Fix from $1,600 2025-04-07
Csrb31024 Firmware HIGH 7.8
CVE-2024-43066

Memory corruption while handling file descriptor during listener registration/de-registration.

Mitigation only
Fix from $1,950 2025-04-07
C V2x 9150 Firmware MEDIUM 6.6
CVE-2024-45540

Memory corruption while invoking IOCTL map buffer request from userspace.

No fix yet
Fix from $1,600 2025-04-07
PHP HIGH 8.1
CVE-2024-11235

In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use…

Fix: 8.3.19 / 8.4.5+
Fix from $1,950 2025-04-04
Edge Chromium HIGH 7.6
CVE-2025-29815

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Fix: 134.0.3124.66+
Fix from $1,950 2025-04-04
Unclassified HIGH 8.7
CVE-2025-31115

XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder i…

Patch available
Fix from $1,950 2025-04-03
Linux Kernel HIGH 7.8
CVE-2025-21999

In the Linux kernel, the following vulnerability has been resolved: proc: fix UAF in proc_get_inode() Fix race between rmmod and /proc/XXX's inode …

Fix: 6.1.132 / 6.6.85+
Fix from $1,950 2025-04-03
Linux Kernel HIGH 8.6
CVE-2025-22004

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix use after free in lec_send() The ->send() operation frees skb so …

Fix: 6.1.132 / 6.6.85+
Fix from $1,950 2025-04-03
Chrome HIGH 8.8
CVE-2025-3066

Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 135.0.7049.52+
Fix from $1,950 2025-04-02
Linux Kernel HIGH 7.8
CVE-2025-21979

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel wiphy_work before freeing wiphy A wiphy_work can be queu…

Fix: 6.1.132 / 6.6.84+
Fix from $1,950 2025-04-01
Linux Kernel HIGH 7.8
CVE-2025-21968

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix slab-use-after-free on hdcp_work [Why] A slab-use-after-fr…

Fix: 5.10.236 / 5.15.180+
Fix from $1,950 2025-04-01
Linux Kernel HIGH 7.8
CVE-2025-21969

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd After the hci …

Fix: 6.6.84 / 6.12.20+
Fix from $1,950 2025-04-01
Linux Kernel HIGH 7.8
CVE-2025-21967

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_free_work_struct ->interim_entry of ksmbd_wo…

Fix: 6.6.84 / 6.12.20+
Fix from $1,950 2025-04-01
Linux Kernel HIGH 7.8
CVE-2025-21945

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_lock If smb_lock->zero_len has value, ->llist…

Fix: 6.1.131 / 6.6.83+
Fix from $1,950 2025-04-01
Linux Kernel HIGH 7.8
CVE-2025-21934

In the Linux kernel, the following vulnerability has been resolved: rapidio: fix an API misues when rio_add_net() fails rio_add_net() calls device_…

Fix: 5.4.291 / 5.10.235+
Fix from $1,950 2025-04-01
Linux Kernel HIGH 7.8
CVE-2025-21923

In the Linux kernel, the following vulnerability has been resolved: HID: hid-steam: Fix use-after-free when detaching device When a hid-steam devic…

Fix: 6.6.83 / 6.12.19+
Fix from $1,950 2025-04-01
Linux Kernel HIGH 7.8
CVE-2025-21928

In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() The system c…

Fix: 5.4.291 / 5.10.235+
Fix from $1,950 2025-04-01
Linux Kernel HIGH 7.8
CVE-2025-21929

In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove() During th…

Fix: 6.12.19 / 6.13.7+
Fix from $1,950 2025-04-01
Linux Kernel HIGH 7.8
CVE-2025-21915

In the Linux kernel, the following vulnerability has been resolved: cdx: Fix possible UAF error in driver_override_show() Fixed a possible UAF prob…

Fix: 6.6.83 / 6.12.19+
Fix from $1,950 2025-04-01