Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2026-34859
UAF vulnerability in the kernel module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Harmonyos
Mitigation only
CRITICAL 9.6
CVE-2026-6068
NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global d…
Netwide Assembler
No fix yet
MEDIUM 6.5
CVE-2026-5460
A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the error handling path of TLSX_KeyS…
Wolfssl
5.9.1+
HIGH 7.8
CVE-2026-34734
HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply…
Hdf5
1.14.1-2+
MEDIUM 5.0
CVE-2026-34983
Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free bugs. This bug is not contro…
Wasmtime
Mitigation only
CRITICAL 9.6
CVE-2026-5874
Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures …
Chrome
147.0.7727.55+
HIGH 8.8
CVE-2026-5877
Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft…
Chrome
147.0.7727.55+
HIGH 8.8
CVE-2026-5883
Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…
Chrome
147.0.7727.55+
HIGH 8.8
CVE-2026-5866
Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…
Chrome
147.0.7727.55+
HIGH 8.8
CVE-2026-5872
Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…
Chrome
147.0.7727.55+
HIGH 8.8
CVE-2026-5860
Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…
Chrome
147.0.7727.55+
HIGH 8.8
CVE-2026-5861
Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …
Chrome
147.0.7727.55+
HIGH 8.1
CVE-2026-28387
Issue summary: An uncommon configuration of clients performing DANE TLSA-based
server authentication, when paired with uncommon server DANE TLSA reco…
OpenSSL
1.1.1zg / 3.0.20+
MEDIUM 6.2
CVE-2026-39316
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free v…
Cups
after 2.4.16
HIGH 8.7
CVE-2026-35554
A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics.
…
Kafka
3.9.2 / 4.0.2+
MEDIUM 5.5
CVE-2026-34764
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5,…
Electron
39.8.5 / 40.8.5+
HIGH 7.8
CVE-2026-21380
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
Cologne Firmware
No fix yet
MEDIUM 6.5
CVE-2025-47374
Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
Fastconnect 6900 Firmware
Patch available
HIGH 8.8
CVE-2026-31408
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold
…
Linux Kernel
5.15.203 / 6.1.168+
HIGH 8.8
CVE-2026-34772
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and…
Electron
38.8.6 / 39.8.0+
HIGH 8.1
CVE-2026-34774
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0,…
Electron
39.8.1 / 40.7.0+
HIGH 8.8
CVE-2026-34770
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and…
Electron
38.8.6 / 39.8.1+
HIGH 8.8
CVE-2026-34771
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and…
Electron
38.8.6 / 39.8.0+
HIGH 7.8
CVE-2026-31399
In the Linux kernel, the following vulnerability has been resolved:
nvdimm/bus: Fix potential use after free in asynchronous initialization
Dingiso…
Linux Kernel
4.5 / 4.10+
HIGH 7.8
CVE-2026-31396
In the Linux kernel, the following vulnerability has been resolved:
net: macb: fix use-after-free access to PTP clock
PTP clock is registered on ev…
Linux Kernel
5.10.253 / 5.15.203+
HIGH 7.8
CVE-2026-31389
In the Linux kernel, the following vulnerability has been resolved:
spi: fix use-after-free on controller registration failure
Make sure to deregis…
Linux Kernel
6.1.167 / 6.6.130+
HIGH 8.8
CVE-2026-23461
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user
After commit ab4e…
Linux Kernel
6.6.130 / 6.12.78+
HIGH 8.8
CVE-2026-23462
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: HIDP: Fix possible UAF
This fixes the following trace caused by not …
Linux Kernel
5.10.253 / 5.15.203+
HIGH 7.8
CVE-2026-23458
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()
ctnetlink_d…
Linux Kernel
5.10.253 / 5.15.203+
CRITICAL 9.8
CVE-2026-23450
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock()
Syzkaller repo…
Linux Kernel
5.15.203 / 6.1.167+