Vulnerability index

Browse CVEs

7,925 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.8 CVE-2026-13129 When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid… Pdf Editor after 2026.1.1.36485 Fix from $1,9502026-07-08 HIGH 7.8 CVE-2026-56000 Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a H… X Server 21.2.24 / 24.1.13+ Fix from $1,9502026-07-08 CRITICAL 9.4 CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the cl… Openssh 10.4+ Fix from $2,3002026-07-08 HIGH 7.8 CVE-2026-42958 The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This … Mitigation only Fix from $1,9502026-07-07 HIGH 7.8 CVE-2025-59615 Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchroniz… Fastconnect 6700 Firmware Patch available Fix from $1,9502026-07-06 HIGH 7.8 CVE-2025-59616 Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. Fastconnect 6700 Firmware Patch available Fix from $1,9502026-07-06 HIGH 7.3 CVE-2025-59617 Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. Fastconnect 6700 Firmware Patch available Fix from $1,9502026-07-06 HIGH 7.8 CVE-2026-14788 A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the fi… Radare2 after 6.1.6 Fix from $1,9502026-07-06 HIGH 7.8 CVE-2026-14760 A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the… Radare2 6.1.8+ Fix from $1,9502026-07-05 HIGH 8.8 CVE-2026-53359 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af… Linux Kernel 6.1.177 / 6.6.144+ Fix from $1,9502026-07-04 HIGH 7.5 CVE-2026-58294 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 8.3 CVE-2026-58287 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 8.3 CVE-2026-58288 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-57992 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-58276 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 8.8 CVE-2026-57981 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-57984 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-57986 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 7.3 CVE-2026-9080 Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts… Curl 8.21.0+ Fix from $1,9502026-07-03 CRITICAL 9.8 CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CUR… Curl 8.21.0+ Fix from $2,3002026-07-03 HIGH 8.1 CVE-2026-13368 WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2.… Fireware 11.12.4 / 12.5.19+ Fix from $1,9502026-07-03 HIGH 8.0 CVE-2026-53357 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-07-02 CRITICAL 9.6 CVE-2026-14425 Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 HIGH 7.5 CVE-2026-14426 Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to exec… Chrome 150.0.7871.46+ Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-14432 Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Chrome 150.0.7871.46+ Fix from $1,9502026-07-01 CRITICAL 9.6 CVE-2026-14417 Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14419 Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14424 Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14398 Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 HIGH 8.8 CVE-2026-14403 Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Chrome 150.0.7871.46+ Fix from $1,9502026-07-01