Vulnerability index

Browse CVEs

7,918 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 8.8 CVE-2026-63639 Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream… Fix unknown Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-56684 Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pendin… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fire… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74937 Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-65341 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26… Safari Fix unknown Fix from $4,0002026-08-17 HIGH 7.5 CVE-2026-65343 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. A remo… Ipados Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-64787 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe… Safari Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.5 CVE-2026-64715 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.… Safari Fix unknown Fix from $4,0002026-08-17 HIGH 8.8 CVE-2026-12366 Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its ref… No fix yet Fix from $4,9002026-08-14 MEDIUM 5.8 CVE-2026-12365 A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work … No fix yet Fix from $4,0002026-08-14 MEDIUM 5.5 CVE-2026-19548 Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils… No fix yet Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-19556 Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… Chrome No fix yet Fix from $4,9002026-08-11 HIGH 8.3 CVE-2026-19557 Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to pote… Chrome No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-19558 Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to ex… Chrome No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-19559 Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT… Chrome No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-19560 Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H… Chrome No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-18711 An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference t… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.6 CVE-2026-18706 An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management command… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18700 An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used … No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-18692 An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal ref… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.6 CVE-2026-0465 A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially result… No fix yet Fix from $4,0002026-08-11 HIGH 7.0 CVE-2026-70307 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70311 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-68820 KEV Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-66802 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health … Windows 10 1809 No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-65788 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.22631.7517 / 10.0.26100.9106+ Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-65789 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-65778 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26200.9106+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-65779 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26200.9106+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-65781 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26200.9106+ Fix from $4,9002026-08-11