Vulnerability index

Browse CVEs

7,937 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.8 CVE-2025-32709 KEV Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-30393 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-30400 KEV Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7314 / 10.0.19044.5854+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-32701 KEV Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-30385 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8066 / 10.0.17763.7314+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-30386 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.18827.20000+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-30377 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20010+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-29977 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20010+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-29978 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-29970 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.25398.1611 / 10.0.26100.4061+ Fix from $1,9502025-05-13 HIGH 7.0 CVE-2025-29841 Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorize… Windows 10 21h2 10.0.19044.5854 / 10.0.19045.5854+ Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-29831 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8066 / 10.0.17763.7314+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2023-53145 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition… Linux Kernel 4.14.326 / 4.19.295+ Fix from $1,9502025-05-10 HIGH 7.8 CVE-2025-37882 In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix isochronous Ring Underrun/Overrun event handling The TRB pointer… Linux Kernel 6.12.26 / 6.14.5+ Fix from $1,9502025-05-09 HIGH 7.8 CVE-2025-37885 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reset IRTE to host control if *new* route isn't postable Restore an I… Linux Kernel 5.10.237 / 5.15.181+ Fix from $1,9502025-05-09 HIGH 7.8 CVE-2025-37861 In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue When t… Linux Kernel 6.12.24 / 6.13.12+ Fix from $1,9502025-05-09 HIGH 7.8 CVE-2025-37869 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Use local fence in error path of xe_migrate_clear The intent of the err… Linux Kernel 6.12.25 / 6.14.4+ Fix from $1,9502025-05-09 HIGH 7.8 CVE-2025-37854 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix mode1 reset crash issue If HW scheduler hangs and mode1 reset i… Linux Kernel 6.1.135 / 6.6.88+ Fix from $1,9502025-05-09 HIGH 7.8 CVE-2025-37845 In the Linux kernel, the following vulnerability has been resolved: tracing: fprobe events: Fix possible UAF on modules Commit ac91052f0ae5 ("traci… Linux Kernel 6.12.24 / 6.13.12+ Fix from $1,9502025-05-09 HIGH 7.8 CVE-2025-37849 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fa… Linux Kernel 6.1.135 / 6.6.88+ Fix from $1,9502025-05-09 MEDIUM 6.2 CVE-2025-31946 Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause me… Mitigation only Fix from $1,6002025-05-08 HIGH 7.5 CVE-2025-27578 Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption… Mitigation only Fix from $1,9502025-05-08 HIGH 7.8 CVE-2025-37819 In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode() With ACPI in pla… Linux Kernel 5.4.294 / 5.10.238+ Fix from $1,9502025-05-08 HIGH 7.8 CVE-2025-37823 In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too Similarly to the pre… Linux Kernel 5.4.293 / 5.10.237+ Fix from $1,9502025-05-08 HIGH 8.8 CVE-2025-4372 Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… Chrome 136.0.7103.92+ Fix from $1,9502025-05-06 HIGH 7.8 CVE-2025-21453 Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. 315 5g Iot Modem Firmware Patch available Fix from $1,9502025-05-06 HIGH 7.8 CVE-2024-45583 Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations. Fastconnect 7800 Firmware Patch available Fix from $1,9502025-05-06 HIGH 7.8 CVE-2024-45567 Memory corruption while encoding JPEG format. Fastconnect 6900 Firmware Patch available Fix from $1,9502025-05-06 HIGH 7.8 CVE-2024-45562 Memory corruption during concurrent access to server info object due to unprotected critical field. C V2x 9150 Firmware Patch available Fix from $1,9502025-05-06 HIGH 7.8 CVE-2024-45564 Memory corruption during concurrent access to server info object due to incorrect reference count update. C V2x 9150 Firmware Patch available Fix from $1,9502025-05-06