Total
8659 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-69530 | 2026-09-09 | N/A | 8.1 HIGH | ||
| Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69333 | 2026-09-09 | N/A | 7.0 HIGH | ||
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-62697 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-68886 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-68843 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-76957 | 1 Libexpat Project | 1 Libexpat | 2026-09-08 | N/A | 4.9 MEDIUM |
| libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412. | |||||
| CVE-2026-69574 | 2026-09-08 | N/A | 7.0 HIGH | ||
| Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69474 | 2026-09-08 | N/A | 4.8 MEDIUM | ||
| Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. | |||||
| CVE-2026-68847 | 2026-09-08 | N/A | 7.0 HIGH | ||
| Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-68824 | 2026-09-08 | N/A | 7.0 HIGH | ||
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-56172 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-86713 | 2026-09-08 | N/A | 7.1 HIGH | ||
| PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers can trigger this vulnerability by issuing the load_mon stop command from any PXH or MAVLink shell, causing reads and writes through freed memory that corrupt heap objects and destabilize the flight stack. | |||||
| CVE-2026-72965 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-82325 | 2026-09-08 | N/A | N/A | ||
| A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages | |||||
| CVE-2026-20515 | 2026-09-08 | N/A | 5.5 MEDIUM | ||
| In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132. | |||||
| CVE-2026-20517 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID: MSV-6781. | |||||
| CVE-2026-20511 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID: MSV-8890. | |||||
| CVE-2026-20506 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9126. | |||||
| CVE-2026-20507 | 2026-09-08 | N/A | 6.7 MEDIUM | ||
| In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9125. | |||||
| CVE-2026-84333 | 1 Google | 2 Android, Chrome | 2026-09-08 | N/A | 9.6 CRITICAL |
| Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
