VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2026-65343High· 7.5PoC
1mo ago

A use after free issue was addressed with improved memory management

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected system ter…

▾ Midnightapple · ipadosEPSS 0.69%via NVD
CVE-2026-65338Medium· 4.3⚖ disputed
1mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may le…

▾ Sunlitapple · safariEPSS 0.46%via NVD
CVE-2026-64787Medium· 6.5⚖ disputed
1mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing ma…

▾ Sunlitapple · safariEPSS 0.33%via NVD
CVE-2026-65341Medium· 5.4⚖ disputed
1mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously craft…

▾ Sunlitapple · safariEPSS 0.24%via NVD
CVE-2026-50060High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered whil…

▾ Twilightsiemens · solid_edge_se2025EPSS 0.15%via NVD
CVE-2026-50061High· 7.8
1mo ago

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7)

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered whil…

▾ Twilightsiemens · solid_edge_se2025EPSS 0.15%via NVD
CVE-2026-73071Low· 3.3
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing t…

▾ SunlitEPSS 0.16%via NVD
GHSA-2q33-cf8w-7q23Critical· 9.8
1mo ago

Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability

Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability

▾ MidnightMicrosoft · Microsoft.Native.Quic.MsQuic.OpenSSLvia GHSA
CVE-2026-70307High· 7.0
1mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-70311High· 7.8
1mo ago

Microsoft Office Word Remote Code Execution Vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-61361High· 7.0
1mo ago

Windows DHCP Client Remote Code Execution Vulnerability

Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.26%via CVEORG
CVE-2026-62705High· 7.0
1mo ago

Microsoft Brokering File System Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-62693High· 7.0
1mo ago

Windows MIDI Service Module Elevation of Privileges Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-61934High· 7.8
1mo ago

Windows Bind Filter Driver Elevation of Privilege Vulnerability

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.33%via CVEORG
CVE-2026-61927High· 7.0
1mo ago

Windows Bind Filter Driver Elevation of Privilege Vulnerability

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-62779High· 7.8
1mo ago

Windows Schannel Elevation of Privilege Vulnerability

Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.33%via CVEORG
CVE-2026-62748High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-62729High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-62724High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-62723High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-62893Critical· 9.8
1mo ago

Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows Server 2012EPSS 0.97%via CVEORG
CVE-2026-62892High· 7.0
1mo ago

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.26%via CVEORG
CVE-2026-62819High· 8.1
1mo ago

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.71%via CVEORG
CVE-2026-62818High· 8.8
1mo ago

Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability

Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.91%via CVEORG
CVE-2026-62815Critical· 9.8
1mo ago

Microsoft QUIC Remote Code Execution Vulnerability

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows 11 version 23H2EPSS 0.97%via CVEORG
CVE-2026-62795High· 8.8
1mo ago

Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.82%via CVEORG
CVE-2026-62787High· 7.5
1mo ago

Windows DNS Server Remote Code Execution Vulnerability

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows Server 2012EPSS 0.66%via CVEORG
CVE-2026-62774High· 7.0
1mo ago

Windows Graphics Kernel Elevation of Privilege Vulnerability

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-62773High· 7.0
1mo ago

Windows Kerberos Elevation of Privilege Vulnerability

Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-65657High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CWE-416 vulnerabilities (CVEs) — page 14 · VulnSea