Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.3 CVE-2025-62230 A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data struc… Debian Linux 21.1.19+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2025-11465 Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… Cobalt Mitigation only Fix from $1,9502025-10-29 HIGH 7.5 CVE-2025-62788 Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_event_for_log() references memo… Wazuh 4.11.0+ Fix from $1,9502025-10-29 HIGH 7.8 CVE-2025-53814 A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .xml file can lead t… Fade In No fix yet Fix from $1,9502025-10-28 CRITICAL 9.8 CVE-2025-12380 Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-rel… Firefox 144.0.2+ Fix from $2,3002025-10-28 HIGH 7.8 CVE-2025-12205 A vulnerability was detected in Kamailio 5.5. The affected element is the function sr_push_yy_state of the file src/core/cfg.lex of the component Con… Kamailio No fix yet Fix from $1,9502025-10-27 HIGH 7.5 CVE-2025-12105 A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP… Mitigation only Fix from $1,9502025-10-23 MEDIUM 6.5 CVE-2025-11979 An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issu… MongoDB 7.0.25 / 8.0.15+ Fix from $1,6002025-10-20 MEDIUM 6.3 CVE-2025-11677 Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations … Mitigation only Fix from $1,6002025-10-20 HIGH 7.5 CVE-2025-62504 Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain a use-after-free vulnerabili… Envoy 1.33.12 / 1.34.10+ Fix from $1,9502025-10-16 HIGH 8.8 CVE-2025-62490 In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a … Quickjs 2025-09-13+ Fix from $1,9502025-10-16 HIGH 8.8 CVE-2025-62491 A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promis… Quickjs 2025-09-13+ Fix from $1,9502025-10-16 HIGH 7.5 CVE-2025-48008 When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacke… Big Ip Next Cloud Native Network Functions 15.1.10.8 / 16.1.6+ Fix from $1,9502025-10-15 HIGH 7.8 CVE-2025-54279 Animate versions 23.0.13, 24.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the con… Animate 23.0.15 / 24.0.12+ Fix from $1,9502025-10-15 HIGH 7.8 CVE-2025-61801 Dimension versions 4.1.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of t… Dimension 4.1.5+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-61802 Substance3D - Stager versions 3.1.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the c… Substance 3d Stager 3.1.5+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-54281 Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in … Framemaker 2020.10 / 2022.8+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59290 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6332 / 10.0.19045.6332+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-59282 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to e… Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59243 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59234 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19328.20000+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59236 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59238 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59225 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59226 Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59227 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19328.20000+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-59221 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59222 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59223 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59224 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14