Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 8.4 CVE-2026-40361 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-35418 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8755 / 10.0.19044.7291+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-35416 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-34638 Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the … Premiere Pro 25.6.5 / 26.2+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34345 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34347 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34340 Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8755 / 10.0.19044.7291+ Fix from $1,9502026-05-12 HIGH 8.0 CVE-2026-34332 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. Windows Server 2025 10.0.26100.32772+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-34333 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34337 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8755 / 10.0.19044.7291+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-34338 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-33840 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.8390 / 10.0.26100.32772+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-34330 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34331 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-33835 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8755 / 10.0.19044.7291+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-32161 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthor… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 MEDIUM 6.8 CVE-2025-27723 Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Kernel may allow a denial of se… Mitigation only Fix from $1,6002026-05-12 HIGH 7.3 CVE-2026-8390 Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. Firefox 150.0.3+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-43668 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, … Ipados 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 MEDIUM 5.3 CVE-2026-28994 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, … Ipados 14.8.7 / 15.7.7+ Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-28969 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, … Ipados 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 MEDIUM 6.5 CVE-2026-28942 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5,… Ipados 26.5+ Fix from $1,6002026-05-11 MEDIUM 6.5 CVE-2026-28946 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously cr… macOS 26.5+ Fix from $1,6002026-05-11 HIGH 8.8 CVE-2026-28947 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 an… Ipados 26.5+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28883 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5,… Ipados 26.5+ Fix from $1,9502026-05-11 CRITICAL 9.8 CVE-2026-6722 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mech… PHP 8.2.31 / 8.3.31+ Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2026-7261 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSIS… PHP 8.2.31 / 8.3.31+ Fix from $2,3002026-05-10 HIGH 7.8 CVE-2026-43458 In the Linux kernel, the following vulnerability has been resolved: serial: caif: hold tty->link reference in ldisc_open and ser_release A reproduc… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-05-08 HIGH 7.3 CVE-2026-43459 In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: flush delayed work before removing DAIs and widgets When a soun… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-05-08 HIGH 7.8 CVE-2026-43447 In the Linux kernel, the following vulnerability has been resolved: iavf: fix PTP use-after-free during reset Commit 7c01dbfc8a1c5f ("iavf: periodi… Linux Kernel 6.18.19 / 6.19.9+ Fix from $1,9502026-05-08