CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,457 vulnerabilities with CWE-416
CVE-2026-34638 HIGH
Premiere Pro | Use After Free (CWE-416)
CVSS 7.8
CVE-2026-34347 HIGH
Microsoft Windows 10 Version 1607 - Windows Win32k Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-34345 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-34340 HIGH
Microsoft Windows 10 Version 1809 - Windows Projected File System Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-34338 HIGH
Microsoft Windows 10 Version 1607 - Windows Telephony Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-34337 HIGH
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-34333 HIGH
Microsoft Windows 10 Version 1607 - Windows Win32k Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-34332 HIGH
Microsoft Windows Server 2025 - Windows Kernel-Mode Driver Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-34331 HIGH
Windows 10 1607-22H2 and Windows 11 22H3-26H2 - Local Privilege Escalation via Win32K GRFX Race Condition
CVSS 7.0
CVE-2026-34330 HIGH
Windows 10 1607 Privilege Escalation via Win32K GRFX Integer Overflow
CVSS 7.8
CVE-2026-33840 HIGH
Windows 11 24H2-26H1 and Windows Server 2025 - Use-After-Free in Win32K ICOMP
CVSS 7.8
CVE-2026-33835 HIGH
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-32161 HIGH
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability
CVSS 7.5
CVE-2026-8390 HIGH
Use-after-free in the JavaScript: WebAssembly component
CVSS 7.3
CVE-2026-43668 HIGH
iOS and iPadOS < 18.7.9 - Use-After-Free
CVSS 7.5
CVE-2026-28994 MEDIUM
iOS and iPadOS < 18.7.9 - Use-After-Free via Crafted Wi-Fi Packets
CVSS 5.3
CVE-2026-28969 HIGH
iOS and iPadOS < 18.7.9 - Use-After-Free
CVSS 7.5
CVE-2026-28947 HIGH
iOS and iPadOS < 26.5 - Use-After-Free via Maliciously Crafted Web Content
CVSS 8.8
CVE-2026-28946 MEDIUM
macOS < 26.5 - Use-After-Free via Maliciously Crafted Web Content
CVSS 6.5
CVE-2026-28942 MEDIUM
iOS and iPadOS < 26.5 - Use-After-Free via Malicious Web Content
CVSS 6.5
CVE-2026-28883 HIGH
iOS and iPadOS < 26.5 - Use-After-Free
CVSS 7.5
CVE-2026-7261 CRITICAL
SoapServer session-persisted object use-after-free via SOAP header fault
CVSS 9.8
CVE-2026-6722 CRITICAL
Use-After-Free in SOAP using Apache map
CVSS 9.8
CVE-2026-43459 HIGH
ASoC: soc-core: flush delayed work before removing DAIs and widgets
CVSS 7.3
CVE-2026-43458 HIGH
serial: caif: hold tty->link reference in ldisc_open and ser_release
CVSS 7.8
Details
Vulnerabilities 7,457
Exploit Likelihood High