VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2026-58288High· 8.3
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.61%via CVEORG
CVE-2026-58287High· 8.3
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.61%via CVEORG
CVE-2026-58294High· 7.5
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.61%via CVEORG
CVE-2026-9080High· 7.3PoC
2mo ago

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory…

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory…

▾ Midnighthaxx · curlEPSS 0.49%via NVD
CVE-2026-10536Critical· 9.8PoC⚖ disputed
2mo ago

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates…

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates…

▾ Abyssalhaxx · curlEPSS 0.60%via NVD
CVE-2026-14403High· 8.8
2mo ago

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-14398Critical· 9.6
2mo ago

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-14393High· 8.8
2mo ago

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-14390Critical· 9.6
2mo ago

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-50521High· 8.3
2mo ago

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · edge_chromiumEPSS 0.82%via NVD
CVE-2025-10994Low· 7.8
2mo ago

Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule

Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule

▾ Sunlitopenbabel · openbabelEPSS 0.24%via GHSA
CVE-2026-43715High· 8.8
3mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing ma…

▾ Twilightapple · safariEPSS 0.41%via NVD
CVE-2026-43746Medium· 6.5
3mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may …

▾ Sunlitapple · safariEPSS 0.34%via NVD
CVE-2026-10646High· 7.4
3mo ago

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct getaddrinfo_state ai_state) as the user_data of an asynchronous DNS resolver query

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct getaddrinfo_state ai_state) as the user_data of an asynchronous DNS resolver query. The s…

▾ Twilightzephyrproject · zephyrEPSS 0.45%via NVD
CVE-2026-53462Medium· 5.9
3mo ago

ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails

ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.37%via GHSA
CVE-2026-53275High· 8.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processing MLD queries When processing an MLD query, a pointer to the multicast group address is retrieved when initially parsing …

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processing MLD queries When processing an MLD query, a pointer to the multicast group address is retrieved when initially parsing …

▾ Twilightlinux · linux_kernelEPSS 0.26%via NVD
CVE-2026-53239High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() Fix the race by pruning the bin while still holding xfrm_policy_lock, before dropping it

In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() Fix the race by pruning the bin while still holding xfrm_policy_lock, before dropping it. Us…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53185High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks the sync or async backing device read path based on whether the parent bio is NULL

In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks the sync or async backing device read path based on whether the parent bio is NULL. zram_…

▾ Twilightlinux · linux_kernelEPSS 0.11%via NVD
CVE-2026-12921None
3mo ago

In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.

In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.

▾ SunlitEPSS 0.19%via NVD
CVE-2026-53175Critical· 9.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns teardown, fqdir_pre_exit() walks the fqdir rhashtable and flushes every fragment queue th…

In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns teardown, fqdir_pre_exit() walks the fqdir rhashtable and flushes every fragment queue th…

▾ Midnightlinux · linux_kernelEPSS 0.45%via NVD
CVE-2026-53161High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context There is a race between fastrpc_device_release() and the workqueue that processes DSP responses.…

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context There is a race between fastrpc_device_release() and the workqueue that processes DSP responses.…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53160High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free race in fastrpc_map_create fastrpc_map_lookup returns a raw pointer after releasing fl->lock

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free race in fastrpc_map_create fastrpc_map_lookup returns a raw pointer after releasing fl->lock. The caller fastrpc_map_create then call…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53156High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free bugs in error paths Fix several instances of error paths in which we call __nvmem_device_put() - which may end up freeing the underlyin…

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix use-after-free bugs in error paths Fix several instances of error paths in which we call __nvmem_device_put() - which may end up freeing the underlyin…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-53212High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix use-after-free on object destroy nft_tunnel_obj_destroy() calls metadata_dst_free() which directly kfree()s the metadata_dst, ignoring the d…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix use-after-free on object destroy nft_tunnel_obj_destroy() calls metadata_dst_free() which directly kfree()s the metadata_dst, ignoring the d…

▾ Twilightlinux · linux_kernelEPSS 0.21%via NVD
CVE-2026-52924Critical· 9.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfi…

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfi…

▾ Abyssallinux · linux_kernelEPSS 0.84%via NVD
CVE-2026-53071High· 8.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_…

▾ Twilightlinux · linux_kernelEPSS 0.43%via NVD
CVE-2026-52943High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy the old skb_shared_info header…

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb_carve helpers pskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy the old skb_shared_info header…

▾ Midnightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-52912High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN …

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN …

▾ Twilightlinux · linux_kernelEPSS 0.15%via NVD
CVE-2026-53010Critical· 9.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durable reconnect In smb2_open, the call to ksmbd_put_durable_fd(fp) drops the reference to the durable file descriptor e…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durable reconnect In smb2_open, the call to ksmbd_put_durable_fd(fp) drops the reference to the durable file descriptor e…

▾ Midnightlinux · linux_kernelEPSS 0.65%via NVD
CVE-2026-53009High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it…

In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CWE-416 vulnerabilities (CVEs) — page 23 · VulnSea