VulnSea

CWE-416

CVEs classified under CWE-416, newest first.

1092 CVEsRSS

CVE-2026-56376Low· 3.7
7mo ago

ImageMagick has a possible heap Use After Free vulnerability in its meta coder

ImageMagick has a possible heap Use After Free vulnerability in its meta coder

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.32%via GHSA
CVE-2026-26986Medium· 5.5PoC
7mo ago

FreeRDP has heap-use-after-free in rail_window_free

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereferences a freed `xfAppWindow` pointer during `HashTable_Free` cleanup because `xf_rail_window_common` calls `free(appWindow…

▾ TwilightFreeRDP · FreeRDPEPSS 0.79%via CVEORG
CVE-2026-23185High· 7.8
7mo ago

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, wh…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-2441High· 8.8CISA KEVPoC
7mo ago

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ AbyssalGoogle · ChromeEPSS 55%via CVEORG
CVE-2026-23111High· 7.8PoC
7mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…

▾ Midnightlinux · linux_kernelEPSS 0.49%via NVD
CVE-2026-20644Medium· 6.5
7mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an…

▾ Sunlitapple · safariEPSS 0.31%via NVD
CVE-2026-21351High· 7.8
7mo ago

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi…

▾ Twilightadobe · after_effectsEPSS 0.23%via NVD
CVE-2026-21329High· 7.8
7mo ago

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi…

▾ Twilightadobe · after_effectsEPSS 0.23%via NVD
CVE-2026-21326High· 7.8
7mo ago

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi…

▾ Twilightadobe · after_effectsEPSS 0.23%via NVD
CVE-2026-21323High· 7.8
7mo ago

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi…

▾ Twilightadobe · after_effectsEPSS 0.23%via NVD
CVE-2026-21320High· 7.8
7mo ago

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi…

▾ Twilightadobe · after_effectsEPSS 0.23%via NVD
CVE-2026-24678High· 7.5
7mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. Thi…

▾ Twilightfreerdp · freerdpEPSS 0.65%via NVD
CVE-2026-23074High· 7.8
7mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of teql is that it is only supposed to be used as root qdisc. We need to check for that const…

In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of teql is that it is only supposed to be used as root qdisc. We need to check for that const…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-24869High· 8.8
8mo ago

Use-after-free in the Layout: Scrolling and Overflow component

Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.

▾ Twilightmozilla · firefoxEPSS 0.27%via NVD
CVE-2026-23884Critical· 9.8
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can tr…

▾ Midnightfreerdp · freerdpEPSS 0.47%via NVD
CVE-2026-23883Critical· 9.8
8mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointer_New` frees `cursorPixels` on failure, then `pointer_free` calls `xf_Pointer_Free` and frees it again, triggering ASan UAF. A malicious …

▾ Midnightfreerdp · freerdpEPSS 0.47%via NVD
CVE-2025-13845High· 7.8
8mo ago

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

▾ Twilightschneider-electric · ecostruxure_power_build_-_rapsodyEPSS 0.35%via NVD
CVE-2026-21287High· 7.8
8mo ago

Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that…

▾ Twilightadobe · substance_3d_stagerEPSS 0.21%via NVD
CVE-2026-20924High· 7.8
8mo ago

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.31%via NVD
CVE-2026-20923High· 7.8
8mo ago

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.41%via NVD
CVE-2026-20920High· 7.8
8mo ago

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_23h2EPSS 0.50%via NVD
CVE-2026-20918High· 7.8
8mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.31%via NVD
CVE-2026-20877High· 7.8
8mo ago

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.31%via NVD
CVE-2026-20874High· 7.8
8mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-20873High· 7.8
8mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-20871High· 7.8
8mo ago

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_21h2EPSS 4.2%via NVD
CVE-2026-20870High· 7.8
8mo ago

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.47%via NVD
CVE-2026-20867High· 7.8
8mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-20865High· 7.8
8mo ago

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.40%via NVD
CVE-2026-20861High· 7.8
8mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CWE-416 vulnerabilities (CVEs) — page 30 · VulnSea