VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2026-62711High· 7.8
1mo ago

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-62707High· 7.8
1mo ago

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-62701High· 7.8
1mo ago

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-62690High· 7.0
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.20%via NVD
CVE-2026-61939High· 7.0
1mo ago

Use after free in Winlogon allows an authorized attacker to elevate privileges locally.

Use after free in Winlogon allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-61920Medium· 6.6
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

▾ SunlitMicrosoft · Windows Server 2012 R2EPSS 0.52%via NVD
CVE-2026-61349High· 7.8
1mo ago

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-61348High· 7.0
1mo ago

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-61346High· 7.0
1mo ago

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.26%via NVD
CVE-2026-59125High· 7.0
1mo ago

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-59122High· 7.0
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-62898High· 7.5
1mo ago

Microsoft QUIC Information Disclosure Vulnerability

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.0%via CVEORG
CVE-2026-71968Medium· 6.7
1mo ago

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memor…

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memor…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-71847Low
1mo ago

Ruby JSON is a JSON implementation for Ruby

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released stora…

▾ Sunlitjson · jsonEPSS 0.43%via NVD
CVE-2026-43631High· 8.1
1mo ago

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary…

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary…

▾ Twilightggml · llama.cppEPSS 0.57%via NVD
CVE-2026-43632High· 8.1
1mo ago

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that by…

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that by…

▾ Twilightggml · llama.cppEPSS 0.48%via NVD
CVE-2026-1289High· 7.8
1mo ago

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary co…

▾ Twilightautodesk · revitEPSS 0.19%via NVD
CVE-2026-19175Critical· 9.6
1mo ago

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-19171Critical· 9.6
1mo ago

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-19166Critical· 9.6
1mo ago

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.39%via NVD
CVE-2026-19159High· 7.5
1mo ago

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-19158High· 7.5
1mo ago

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium securi…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-19147High· 8.3
1mo ago

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ TwilightEPSS 0.30%via NVD
CVE-2026-19144High· 8.8
1mo ago

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

▾ TwilightEPSS 0.34%via NVD
CVE-2026-19142High· 7.5
1mo ago

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity…

▾ TwilightEPSS 0.30%via NVD
CVE-2026-19141High· 8.3
1mo ago

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severi…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-19108Medium· 5.3
1mo ago

A vulnerability was found in MZ Automation libiec61850 up to 1.6.1

A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The mani…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-71226High· 7.3
1mo ago

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

▾ Twilightredhat · hardened_imagesEPSS 0.18%via NVD
CVE-2026-0163Critical· 9.8PoC
1mo ago

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…

▾ Abyssalgoogle · androidEPSS 0.38%via NVD
CVE-2026-11368High· 7.1
1mo ago

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan)

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, it…

▾ Twilightzephyrproject · zephyrEPSS 0.30%via NVD
CWE-416 vulnerabilities (CVEs) — page 16 · VulnSea