Vulnerability index

Browse CVEs

7,925 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 8.8 CVE-2026-10890 Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruptio… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10891 Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10893 Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffi… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.3 CVE-2026-10894 Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pot… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10882 Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chrom… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.3 CVE-2026-10884 Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentiall… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10885 Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTM… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 MEDIUM 5.9 CVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset fr… Libexpat 2.8.2+ Fix from $1,6002026-06-04 HIGH 7.5 CVE-2026-8829 HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cac… Html\ 3.84+ Fix from $1,9502026-06-04 HIGH 7.8 CVE-2026-46267 In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freeing context llc_shdlc_deinit()… Linux Kernel 5.15.202 / 6.1.165+ Fix from $1,9502026-06-03 HIGH 8.4 CVE-2026-46270 In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_supply_changed() Using the `… Linux Kernel 5.10.252 / 5.15.202+ Fix from $1,9502026-06-03 HIGH 8.8 CVE-2026-46264 In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of devm_add_action_or_reset() failu… Linux Kernel 6.19.4+ Fix from $1,9502026-06-03 HIGH 7.8 CVE-2026-46246 In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler Using t… Linux Kernel 6.12.75 / 6.18.14+ Fix from $1,9502026-06-03 HIGH 7.8 CVE-2026-40290 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone… Op Tee after 4.10.0 Fix from $1,9502026-06-03 MEDIUM 6.3 CVE-2026-10703 A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the f… No fix yet Fix from $1,6002026-06-03 MEDIUM 5.5 CVE-2025-60486 A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of … Patch available Fix from $1,6002026-06-01 MEDIUM 5.3 CVE-2026-10232 A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the com… No fix yet Fix from $1,6002026-06-01 HIGH 7.8 CVE-2026-46242 In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep… Linux Kernel 5.16 / 6.2+ Fix from $1,9502026-05-30 HIGH 8.8 CVE-2026-44422 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id… Freerdp 3.26.0+ Fix from $1,9502026-05-29 HIGH 8.3 CVE-2026-9988 Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a cr… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-9990 Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9992 Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-9993 Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially pe… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-9994 Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to pote… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9995 Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-9997 Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially pe… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9978 Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9984 Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page.… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-9970 Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially pe… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9958 Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF … Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28