Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2026-27277
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the c…
Substance 3d Stager
3.1.8+
HIGH 8.8
CVE-2026-3847
Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of…
Firefox
148.0.2+
HIGH 7.8
CVE-2026-30978
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-use-after-free in CIcc…
Iccdev
2.3.1.5+
HIGH 7.8
CVE-2026-26132
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.7058 / 10.0.19045.7058+
HIGH 7.8
CVE-2026-26134
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Copilot
16.0.19822.20000+
HIGH 7.8
CVE-2026-26107
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20102+
HIGH 7.8
CVE-2026-25189
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8511 / 10.0.19044.7058+
HIGH 7.0
CVE-2026-25178
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.0
CVE-2026-25170
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.20348.4830 / 10.0.22631.6783+
HIGH 7.0
CVE-2026-25171
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.4
CVE-2026-25167
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.7979 / 10.0.26100.32463+
HIGH 7.8
CVE-2026-24292
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8511 / 10.0.19044.7058+
HIGH 7.0
CVE-2026-24295
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorize…
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.8
CVE-2026-24289
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.0
CVE-2026-24285
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
365 Copilot
10.0.14393.8957 / 10.0.17763.8511+
HIGH 8.8
CVE-2026-23669
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.0
CVE-2026-23671
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an auth…
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.0
CVE-2026-23667
Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8511 / 10.0.19044.7058+
MEDIUM 5.3
CVE-2026-28687
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-a…
Imagemagick
6.9.13-41 / 7.1.2-16+
MEDIUM 5.3
CVE-2026-28688
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-a…
Imagemagick
6.9.13-41 / 7.1.2-16+
HIGH 7.5
CVE-2026-28799
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in P…
Pjsip
2.17+
HIGH 7.1
CVE-2025-13350
Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB s…
Mitigation only
MEDIUM 5.3
CVE-2026-22040
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency p…
Nanomq
0.24.6+
HIGH 7.8
CVE-2026-23234
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid UAF in f2fs_write_end_io()
As syzbot reported an use-after-f…
Linux Kernel
5.10.251 / 5.15.201+
HIGH 7.8
CVE-2026-23231
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
nf_tables_addc…
Linux Kernel
6.1.165 / 6.6.128+
MEDIUM 6.7
CVE-2026-0027
In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privileg…
Android
Patch available
HIGH 7.8
CVE-2025-47386
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Ar8031 Firmware
Patch available
HIGH 7.8
CVE-2025-47381
Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs.
Lemans Au Lgit Firmware
Patch available
HIGH 7.8
CVE-2025-47377
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
Ar8035 Firmware
Patch available
HIGH 7.8
CVE-2025-47379
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resour…
Sa8295p Firmware
Patch available