Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.0
CVE-2026-21241
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.20348.4711 / 10.0.22631.6649+
HIGH 7.0
CVE-2026-21242
Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.6937 / 10.0.19045.6937+
HIGH 7.3
CVE-2026-21235
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.0
CVE-2026-21237
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attac…
Windows 10 21h2
10.0.19044.6937 / 10.0.19045.6937+
HIGH 7.8
CVE-2025-15570
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulatio…
Lrzip
after 0.651
HIGH 7.5
CVE-2026-24684
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the …
Freerdp
3.22.0+
CRITICAL 9.1
CVE-2026-24677
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts server-controlled dimensions and …
Freerdp
3.22.0+
HIGH 7.5
CVE-2026-24678
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callb…
Freerdp
3.22.0+
HIGH 7.5
CVE-2026-24680
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New frees data on failure, then pointer_free calls sdl_…
Freerdp
3.22.0+
HIGH 7.5
CVE-2026-24681
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completions can use a freed channel cal…
Freerdp
3.22.0+
HIGH 7.5
CVE-2026-24683
FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a local variable and later uses i…
Freerdp
3.22.0+
HIGH 7.5
CVE-2026-24491
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, video_timer can send client notifications after the control channel…
Freerdp
3.22.0+
HIGH 7.5
CVE-2026-24675
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, urb_select_interface can free the device's MS config on error but l…
Freerdp
3.22.0+
HIGH 7.5
CVE-2026-24676
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, AUDIN format renegotiation frees the active format list while the c…
Freerdp
3.22.0+
MEDIUM 5.5
CVE-2026-24927
Out-of-bounds access vulnerability in the frequency modulation module.
Impact: Successful exploitation of this vulnerability may affect availability.
Emui
No fix yet
MEDIUM 5.5
CVE-2026-24930
UAF concurrency vulnerability in the graphics module.
Impact: Successful exploitation of this vulnerability may affect availability.
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2026-24914
Type confusion vulnerability in the camera module.
Impact: Successful exploitation of this vulnerability may affect availability.
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2026-24917
UAF vulnerability in the security module.
Impact: Successful exploitation of this vulnerability may affect availability.
Emui
No fix yet
MEDIUM 5.5
CVE-2026-1979
A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization.…
Mruby
after 3.4.0
MEDIUM 6.3
CVE-2026-25507
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a use-after-free vulnerab…
Esp Idf
Patch available
HIGH 7.8
CVE-2026-23089
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free()
When snd_usb_create…
Linux Kernel
5.10.249 / 5.15.199+
HIGH 7.8
CVE-2026-23074
In the Linux kernel, the following vulnerability has been resolved:
net/sched: Enforce that teql can only be used as root qdisc
Design intent of te…
Linux Kernel
5.10.249 / 5.15.199+
HIGH 7.8
CVE-2026-23077
In the Linux kernel, the following vulnerability has been resolved:
mm/vma: fix anon_vma UAF on mremap() faulted, unfaulted merge
Patch series "mm/…
Linux Kernel
6.18.8+
HIGH 7.8
CVE-2025-47398
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.
Sa9000p Firmware
Patch available
HIGH 7.8
CVE-2025-47358
Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently.
Fastconnect 6900 Firmware
Mitigation only
HIGH 7.8
CVE-2025-47359
Memory Corruption when multiple threads simultaneously access a memory free API.
Qca6391 Firmware
Mitigation only
HIGH 7.8
CVE-2026-20411
In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious actor has …
Android
Mitigation only
MEDIUM 6.7
CVE-2026-20414
In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor h…
Android
Mitigation only
HIGH 7.5
CVE-2025-63651
A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (…
Monkey
after 1.8.5
HIGH 7.5
CVE-2025-63652
A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (Do…
Monkey
after 1.8.5