VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2026-8090High· 7.3
4mo ago

Use-after-free in the DOM: Networking component

Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

▾ Twilightmozilla · firefoxEPSS 0.45%via NVD
CVE-2026-23479High· 8.8PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is e…

▾ Midnightredis · redisEPSS 1.5%via NVD
CVE-2026-23631High· 8.1PoC
4mo ago

Redis is an in-memory data structure store

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read…

▾ Midnightredis · redisEPSS 2.8%via NVD
CVE-2026-24082High· 7.8
4mo ago

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

▾ TwilightEPSS 0.07%via NVD
CVE-2026-7111High· 8.4
5mo ago

Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke r…

Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke r…

▾ TwilightEPSS 0.22%via NVD
CVE-2026-31488High· 7.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not skip unrelated mode changes in DSC validation Starting with commit 17ce8a6907f7 ("drm/amd/display: Add dsc pre-validation in atomic check"), am…

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not skip unrelated mode changes in DSC validation Starting with commit 17ce8a6907f7 ("drm/amd/display: Add dsc pre-validation in atomic check"), am…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2026-26165High· 7.0
5mo ago

Windows Shell Elevation of Privilege Vulnerability

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 22H3EPSS 0.26%via CVEORG
CVE-2026-26167High· 8.8
5mo ago

Windows Push Notifications Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.21%via CVEORG
CVE-2026-26181High· 7.8
5mo ago

Microsoft Brokering File System Elevation of Privilege Vulnerability

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 22H3EPSS 0.26%via CVEORG
CVE-2026-27915High· 7.8
5mo ago

Windows UPnP Device Host Elevation of Privilege Vulnerability

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-27908High· 7.0
5mo ago

Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability

Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-27926High· 7.0
5mo ago

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.20%via CVEORG
CVE-2026-27921High· 7.0
5mo ago

Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-27917High· 7.0
5mo ago

Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability

Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-27927High· 7.8
5mo ago

Windows Projected File System Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.21%via CVEORG
CVE-2026-27924High· 7.8
5mo ago

Desktop Window Manager Elevation of Privilege Vulnerability

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.33%via CVEORG
CVE-2026-32075High· 7.0
5mo ago

Windows UPnP Device Host Elevation of Privilege Vulnerability

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-32073High· 7.0
5mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-32152High· 7.8
5mo ago

Desktop Window Manager Elevation of Privilege Vulnerability

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 22H3EPSS 0.33%via CVEORG
CVE-2026-32090High· 7.8
5mo ago

Windows Speech Brokered Api Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.21%via CVEORG
CVE-2026-32089High· 7.8
5mo ago

Windows Speech Brokered Api Elevation of Privilege Vulnerability

Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-32154High· 7.8
5mo ago

Desktop Window Manager Elevation of Privilege Vulnerability

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-32158High· 7.8
5mo ago

Windows Push Notifications Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.20%via CVEORG
CVE-2026-32159High· 7.8
5mo ago

Windows Push Notifications Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.20%via CVEORG
CVE-2026-32156High· 7.4
5mo ago

Windows UPnP Device Host Remote Code Execution Vulnerability

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.29%via CVEORG
CVE-2026-32165High· 7.8
5mo ago

Windows User Interface Core Elevation of Privilege Vulnerability

Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.20%via CVEORG
CVE-2026-32189High· 7.8
5mo ago

Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-33098High· 7.8
5mo ago

Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability

Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-33095High· 7.8
5mo ago

Microsoft Word Remote Code Execution Vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-23657High· 7.8
5mo ago

Microsoft Word Remote Code Execution Vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.41%via CVEORG
CWE-416 vulnerabilities (CVEs) — page 27 · VulnSea