VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2026-42983High· 7.8
3mo ago

Windows DWM Core Library Elevation of Privilege Vulnerability

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-44801High· 7.5
3mo ago

Remote Desktop Client Remote Code Execution Vulnerability

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Remote Desktop client for Windows DesktopEPSS 0.61%via CVEORG
CVE-2026-42985High· 8.8
3mo ago

Remote Desktop Client Remote Code Execution Vulnerability

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Remote Desktop client for Windows DesktopEPSS 0.82%via CVEORG
CVE-2026-42987High· 8.1
3mo ago

Windows Deployment Services (WDS) Remote Code Execution

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows Server 2012EPSS 0.71%via CVEORG
CVE-2026-44813High· 7.8
3mo ago

Windows DWM Core Library Elevation of Privilege Vulnerability

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 26H1EPSS 0.33%via CVEORG
CVE-2026-44804High· 7.8
3mo ago

Windows DWM Core Library Elevation of Privilege Vulnerability

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 26H1EPSS 0.33%via CVEORG
CVE-2026-46323High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the…

In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the…

▾ Twilightlinux · linux_kernelEPSS 0.20%via NVD
CVE-2026-45447High· 8.8PoC
3mo ago

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remo…

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remo…

▾ Midnightopenssl · opensslEPSS 4.0%via NVD
CVE-2026-50263Medium· 5.5
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow()

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.

▾ Sunlitx.org · x_serverEPSS 0.19%via NVD
CVE-2026-50261High· 7.8
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter()

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while chang…

▾ Twilightx.org · x_serverEPSS 0.20%via NVD
CVE-2026-50260High· 7.8
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter()

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client…

▾ Twilightx.org · x_serverEPSS 0.20%via NVD
CVE-2026-50257High· 7.8
3mo ago

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence()

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to se…

▾ Twilightx.org · x_serverEPSS 0.20%via NVD
CVE-2026-46242High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside t…

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside t…

▾ Midnightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-44422High· 7.5
4mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR …

▾ Twilightfreerdp · freerdpEPSS 0.66%via NVD
CVE-2026-46116High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s hlist_del_rcu calls under syzkaller …

In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s hlist_del_rcu calls under syzkaller …

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-46227High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL The SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with list_for_each_entry_safe(), w…

In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL The SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with list_for_each_entry_safe(), w…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-45984High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in iomap inline data write path The inline data buffer head (dibh) is being released prematurely in gfs2_iomap_begin() via release_metapath() …

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in iomap inline data write path The inline data buffer head (dibh) is being released prematurely in gfs2_iomap_begin() via release_metapath() …

▾ Twilightlinux · linux_kernelEPSS 0.47%via NVD
CVE-2026-45998High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix potential UAF after skb_unshare() failure If skb_unshare() fails to unshare a packet due to allocation failure in rxrpc_input_packet(), the skb pointer in t…

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix potential UAF after skb_unshare() failure If skb_unshare() fails to unshare a packet due to allocation failure in rxrpc_input_packet(), the skb pointer in t…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2026-46090High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match…

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-43499High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

▾ Midnightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2026-5947High· 7.5
4mo ago

Undefined behavior may result due to a race condition leading to a use-after-free violation

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recur…

▾ Twilightisc · bindEPSS 0.80%via NVD
CVE-2026-41218High· 7.5
4mo ago

When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TM…

When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TM…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-40701Medium· 4.8PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured wi…

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured wi…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-34638High· 7.8
4mo ago

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha…

▾ Twilightadobe · premiere_proEPSS 0.38%via NVD
CVE-2026-28969High· 7.5
4mo ago

A use after free issue was addressed with improved memory management

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.7, macOS Sequoia 15.8, ma…

▾ Twilightapple · ipadosEPSS 0.64%via NVD
CVE-2026-28947High· 8.8
4mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing mali…

▾ Twilightapple · ipadosEPSS 0.49%via NVD
CVE-2026-6722Critical· 9.8⚖ disputed
4mo ago

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their referenc…

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their referenc…

▾ Midnightphp · phpEPSS 1.3%via NVD
CVE-2026-43303High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page->private in free_pages_prepare() Several subsystems (slub, shmem, ttm, etc.) use page->private but don't clear it before freeing pages

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page->private in free_pages_prepare() Several subsystems (slub, shmem, ttm, etc.) use page->private but don't clear it before freeing pages. When…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-43437High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() In the drain loop, the local variable 'runtime' is reassigned to a linked stream's runtime (r…

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() In the drain loop, the local variable 'runtime' is reassigned to a linked stream's runtime (r…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-8092High· 8.1
4mo ago

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run a…

▾ Twilightmozilla · firefoxEPSS 0.54%via NVD
CWE-416 vulnerabilities (CVEs) — page 26 · VulnSea