Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2026-8549
Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…
Chrome
148.0.7778.168+
MEDIUM 6.5
CVE-2026-8550
Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain p…
Chrome
148.0.7778.168+
HIGH 8.3
CVE-2026-8533
Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potent…
Chrome
148.0.7778.168+
HIGH 8.3
CVE-2026-8523
Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially per…
Chrome
148.0.7778.168+
HIGH 8.3
CVE-2026-8530
Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to p…
Chrome
148.0.7778.168+
HIGH 8.3
CVE-2026-8514
Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially per…
Chrome
148.0.7778.168+
HIGH 8.3
CVE-2026-8515
Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to po…
Chrome
148.0.7778.168+
HIGH 8.8
CVE-2026-8518
Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…
Chrome
148.0.7778.168+
HIGH 7.5
CVE-2026-8521
Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traff…
Chrome
148.0.7778.168+
HIGH 8.8
CVE-2026-8522
Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML pa…
Chrome
148.0.7778.168+
CRITICAL 9.6
CVE-2026-8511
Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pa…
Chrome
148.0.7778.168+
HIGH 8.3
CVE-2026-8512
Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gesture…
Chrome
148.0.7778.168+
HIGH 8.3
CVE-2026-8513
Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to pot…
Chrome
148.0.7778.168+
HIGH 7.5
CVE-2026-41218
When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the ur…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 6.5
CVE-2026-8336
After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authentica…
MongoDB
8.2.9 / 8.3.2+
HIGH 8.8
CVE-2026-8201
A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd a…
MongoDB
7.0.34 / 8.0.23+
CRITICAL 9.8
CVE-2026-45185
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a c…
Exim
4.99.3+
HIGH 7.0
CVE-2026-42825
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.8
CVE-2026-41095
Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
Windows Server 2012
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.8
CVE-2026-40419
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
HIGH 8.1
CVE-2026-40415
Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
Windows 10 1809
10.0.17763.8755 / 10.0.19044.7291+
HIGH 7.8
CVE-2026-40418
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
CRITICAL 9.3
CVE-2026-40402
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.20348.5074 / 10.0.22631.7079+
HIGH 7.5
CVE-2026-40406
Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.8
CVE-2026-40408
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.0
CVE-2026-40410
Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 7.8
CVE-2026-40382
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 8.4
CVE-2026-40366
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2026-40358
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-40359
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20128+