VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2026-62870High· 8.8
1mo ago

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · 365_appsEPSS 0.82%via NVD
CVE-2026-66315High· 7.5
1mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.61%via CVEORG
CVE-2026-69244High· 7.5
1mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker contro…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.53%via NVD
CVE-2026-20473None
1mo ago

In display, there is a possible memory corruption due to use after free

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Pa…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-67300High· 7.5
1mo ago

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP ser…

▾ TwilightEPSS 0.59%via NVD
CVE-2026-67299High· 7.5
1mo ago

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() ove…

▾ Twilightfreerdp · freerdpEPSS 0.63%via NVD
CVE-2026-10685High· 7.6
1mo ago

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). P…

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). P…

▾ Twilightzephyrproject · zephyrEPSS 0.30%via NVD
CVE-2026-13117Medium· 6.0
1mo ago

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

▾ SunlitOpenVPN · OpenVPNEPSS 0.64%via CVEORG
CVE-2026-17670Critical· 9.6
1mo ago

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-17665High· 8.8
1mo ago

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-17784High· 8.8
1mo ago

Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

▾ TwilightEPSS 0.34%via NVD
CVE-2026-54522Low
1mo ago

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

▾ Sunlitmsgpack · msgpackEPSS 0.23%via GHSA
CVE-2026-54619Low
2mo ago

sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity

sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity

▾ Sunlitsqlite3-ruby · sqlite3-rubyEPSS 0.14%via GHSA
CVE-2026-54620Low
2mo ago

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

▾ Sunlitsqlite3-ruby · sqlite3-rubyEPSS 0.14%via GHSA
CVE-2026-64718Medium· 5.5⚖ disputed
2mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, Safari 27, iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.6, tvOS 2…

▾ Sunlitapple · safariEPSS 0.21%via NVD
CVE-2026-64423High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: remove multicast group from hash table on device destruction When a device is destroyed under RTNL, ip_mc_destroy_dev() iterates through the multicast list…

In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: remove multicast group from hash table on device destruction When a device is destroyed under RTNL, ip_mc_destroy_dev() iterates through the multicast list…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-64424High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netpoll: fix a use-after-free on shutdown path There is a use-after-free error on netpoll, which is clearly detected by KASAN. BUG: KASAN: slab-use-after-free i…

In the Linux kernel, the following vulnerability has been resolved: netpoll: fix a use-after-free on shutdown path There is a use-after-free error on netpoll, which is clearly detected by KASAN. BUG: KASAN: slab-use-after-free i…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-64406High· 8.0
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock. bt_accept_dequeue() currently drops that r…

▾ Twilightlinux · linux_kernelEPSS 0.43%via NVD
CVE-2026-64401High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: resolve SWN tcon from live registrations cifs_swn_notify() looks up a witness registration by id under cifs_swnreg_idr_mutex, drops the mutex, and then us…

In the Linux kernel, the following vulnerability has been resolved: smb: client: resolve SWN tcon from live registrations cifs_swn_notify() looks up a witness registration by id under cifs_swnreg_idr_mutex, drops the mutex, and then us…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-64397Critical· 9.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data

In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUE…

▾ Midnightlinux · linux_kernelEPSS 0.70%via NVD
CVE-2026-64396High· 8.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation When a blocking byte-range lock request is deferred in the FILE_LOCK_DEFERRED path, ksmbd re…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation When a blocking byte-range lock request is deferred in the FILE_LOCK_DEFERRED path, ksmbd re…

▾ Twilightlinux · linux_kernelEPSS 0.63%via NVD
CVE-2026-64365High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: HID: letsketch: fix UAF on inrange_timer at driver unbind letsketch_driver does not provide a .remove callback, but letsketch_probe() arms a per-device timer: tim…

In the Linux kernel, the following vulnerability has been resolved: HID: letsketch: fix UAF on inrange_timer at driver unbind letsketch_driver does not provide a .remove callback, but letsketch_probe() arms a per-device timer: tim…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-64363High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: HID: appleir: fix UAF on pending key_up_timer in remove() appleir_remove() runs hid_hw_stop() before timer_delete_sync(). hid_hw_stop() synchronously unregisters the H…

In the Linux kernel, the following vulnerability has been resolved: HID: appleir: fix UAF on pending key_up_timer in remove() appleir_remove() runs hid_hw_stop() before timer_delete_sync(). hid_hw_stop() synchronously unregisters the H…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-64362High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: HID: lg-g15: cancel pending work on remove to fix a use-after-free lg_g15_data is allocated with devm and holds a work item

In the Linux kernel, the following vulnerability has been resolved: HID: lg-g15: cancel pending work on remove to fix a use-after-free lg_g15_data is allocated with devm and holds a work item. The report handlers schedule that work str…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-64329High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove The threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(), which on a connector-change event ca…

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove The threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(), which on a connector-change event ca…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-64372High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation pcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the two-phase _OSC negotiation

In the Linux kernel, the following vulnerability has been resolved: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation pcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the two-phase _OSC negotiation. Between…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
GHSA-qvxh-prvr-85w2Low· 3.7
2mo ago

ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails

ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-55510Medium· 5.5
2mo ago

ImageMagick: Use-After-Free in crafted 8BIM when identifying an image

ImageMagick: Use-After-Free in crafted 8BIM when identifying an image

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
GHSA-qh5g-q395-cx4jLow· 3.7
2mo ago

ImageMagick: Heap-use-after-free via XMP profile could result in a crash

ImageMagick: Heap-use-after-free via XMP profile could result in a crash

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-6jwg-7q3p-5fqmLow· 3.7
2mo ago

ImageMagick: Use-After-Free when freetype initialization fails

ImageMagick: Use-After-Free when freetype initialization fails

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CWE-416 vulnerabilities (CVEs) — page 17 · VulnSea