Vulnerability index

Browse CVEs

7,918 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
MEDIUM 6.0 CVE-2026-20473 In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al… Mt6991 Firmware No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-67299 FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled … No fix yet Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-67300 FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTI… No fix yet Fix from $1,9502026-08-01 HIGH 7.6 CVE-2026-10685 The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->su… Zephyr 4.5.0+ Fix from $1,9502026-07-31 HIGH 8.1 CVE-2026-63035 A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of serv… No fix yet Fix from $1,9502026-07-30 MEDIUM 5.4 CVE-2026-54522 MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/bu… Messagepack 1.8.2+ Fix from $1,6002026-07-30 CRITICAL 9.1 CVE-2026-51290 SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure wi… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-51291 sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module. No fix yet Fix from $2,3002026-07-30 HIGH 8.1 CVE-2026-12996 A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of serv… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 8.1 CVE-2026-13117 An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-18017 Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-18012 Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted P… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17967 Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via … Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 CRITICAL 9.6 CVE-2026-17947 Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted … Chrome 151.0.7922.72+ Fix from $2,3002026-07-30 MEDIUM 5.5 CVE-2026-17932 Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive informatio… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-17920 Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arb… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 CRITICAL 9.6 CVE-2026-17924 Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perfo… Chrome 151.0.7922.72+ Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-17918 Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 MEDIUM 5.8 CVE-2026-17891 Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to pote… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-17894 Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a craft… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-17896 Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-17898 Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execu… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17881 Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17884 Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a craft… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17886 Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted H… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-17887 Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures t… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17875 Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted P… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-17862 Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a … Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17836 Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 CRITICAL 9.6 CVE-2026-17832 Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per… Chrome 151.0.7922.72+ Fix from $2,3002026-07-30