Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-63639
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream…
Fix unknown
HIGH 7.5
CVE-2026-56684
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pendin…
Fix unknown
HIGH 8.8
CVE-2026-74949
Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fire…
Fix unknown
HIGH 8.8
CVE-2026-74937
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.…
Fix unknown
MEDIUM 5.4
CVE-2026-65341
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26…
Safari
Fix unknown
HIGH 7.5
CVE-2026-65343
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. A remo…
Ipados
Fix unknown
MEDIUM 6.5
CVE-2026-64787
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe…
Safari
Fix unknown
MEDIUM 6.5
CVE-2026-64715
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.…
Safari
Fix unknown
HIGH 8.8
CVE-2026-12366
Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its ref…
No fix yet
MEDIUM 5.8
CVE-2026-12365
A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work …
No fix yet
MEDIUM 5.5
CVE-2026-19548
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils…
No fix yet
HIGH 8.8
CVE-2026-19556
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…
Chrome
No fix yet
HIGH 8.3
CVE-2026-19557
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to pote…
Chrome
No fix yet
HIGH 7.5
CVE-2026-19558
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to ex…
Chrome
No fix yet
HIGH 8.8
CVE-2026-19559
Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…
Chrome
No fix yet
HIGH 8.8
CVE-2026-19560
Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…
Chrome
No fix yet
HIGH 7.1
CVE-2026-18711
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference t…
No fix yet
MEDIUM 6.6
CVE-2026-18706
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management command…
No fix yet
MEDIUM 6.5
CVE-2026-18700
An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used …
No fix yet
HIGH 8.8
CVE-2026-18692
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal ref…
No fix yet
MEDIUM 5.6
CVE-2026-0465
A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially result…
No fix yet
HIGH 7.0
CVE-2026-70307
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.8
CVE-2026-70311
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.0
CVE-2026-68820 KEV
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 8.1
CVE-2026-66802
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health …
Windows 10 1809
No fix yet
HIGH 7.0
CVE-2026-65788
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.22631.7517 / 10.0.26100.9106+
HIGH 8.1
CVE-2026-65789
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Windows 10 1607
No fix yet
HIGH 7.0
CVE-2026-65778
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.9106 / 10.0.26200.9106+
HIGH 7.0
CVE-2026-65779
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.9106 / 10.0.26200.9106+
HIGH 7.0
CVE-2026-65781
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.9106 / 10.0.26200.9106+