Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.0 CVE-2026-23454 In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardo… Linux Kernel 5.15.203 / 6.1.167+ Fix from $1,9502026-04-03 HIGH 7.8 CVE-2026-23432 In the Linux kernel, the following vulnerability has been resolved: mshv: Fix use-after-free in mshv_map_user_memory error path In the error path o… Linux Kernel 6.19.10+ Fix from $1,9502026-04-03 HIGH 7.8 CVE-2026-23427 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in durable v2 replay of active file handles parse_dur… Linux Kernel 6.6.130 / 6.12.78+ Fix from $1,9502026-04-03 HIGH 7.8 CVE-2026-23428 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of share_conf in compound request smb2_get_ksmbd_tcon… Linux Kernel 5.15.203 / 6.1.167+ Fix from $1,9502026-04-03 HIGH 7.8 CVE-2026-23412 In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qia… Linux Kernel 6.6.130 / 6.12.78+ Fix from $1,9502026-04-02 HIGH 7.8 CVE-2026-23413 In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback asymmetry Fix a use-after-f… Linux Kernel 6.6.130 / 6.10+ Fix from $1,9502026-04-02 HIGH 7.8 CVE-2026-23415 In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() During … Linux Kernel 6.18.21 / 6.19.11+ Fix from $1,9502026-04-02 MEDIUM 5.5 CVE-2026-23401 In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE Wh… Linux Kernel 5.15.203 / 6.1.168+ Fix from $1,6002026-04-01 HIGH 8.8 CVE-2026-5286 Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromiu… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 HIGH 8.8 CVE-2026-5287 Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 CRITICAL 9.6 CVE-2026-5288 Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to p… Chrome 146.0.7680.177+ Fix from $2,3002026-04-01 CRITICAL 9.6 CVE-2026-5289 Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potential… Chrome 146.0.7680.177+ Fix from $2,3002026-04-01 CRITICAL 9.6 CVE-2026-5290 Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentia… Chrome 146.0.7680.177+ Fix from $2,3002026-04-01 HIGH 8.8 CVE-2026-5278 Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 HIGH 8.8 CVE-2026-5280 Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 HIGH 8.8 CVE-2026-5281 KEV Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitra… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 HIGH 7.5 CVE-2026-5284 Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitra… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 HIGH 8.8 CVE-2026-5285 Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 MEDIUM 6.3 CVE-2026-5273 Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM… Chrome 146.0.7680.177+ Fix from $1,6002026-04-01 HIGH 7.8 CVE-2026-3779 The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows cr… Pdf Editor after 2025.3.0.69570 Fix from $1,9502026-04-01 HIGH 7.8 CVE-2026-3777 The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and p… Pdf Editor after 2025.3.0.69570 Fix from $1,9502026-04-01 HIGH 7.5 CVE-2026-27854 An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in cust… Dnsdist 1.9.12 / 2.0.3+ Fix from $1,9502026-03-31 HIGH 7.8 CVE-2026-27309 Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the c… Substance 3d Stager 3.1.8+ Fix from $1,9502026-03-27 MEDIUM 6.5 CVE-2024-14028 Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.… Mitigation only Fix from $1,6002026-03-27 HIGH 7.5 CVE-2026-33416 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versio… Libpng 1.6.56+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-27828 EVerest is an EV charging software stack. Prior to version 2026.02.0, ISO15118_chargerImpl::handle_session_setup uses v2g_ctx after it has been freed… Everest 2026.02.0+ Fix from $1,9502026-03-26 MEDIUM 5.3 CVE-2026-27813 EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This is triggered by EV plug-in/unp… Everest 2026.02.0+ Fix from $1,6002026-03-26 HIGH 7.5 CVE-2026-33526EPSS 9% Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP tr… Squid 7.5+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-32748EPSS 9% Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bug… Squid 7.5+ Fix from $1,9502026-03-26 HIGH 7.8 CVE-2026-28529 cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allow… Cryptodev Linux after 1.14 Fix from $1,9502026-03-25