Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-416

MITRE ↗

Use After Free

834
CRITICAL
5,751
HIGH
1,124
MEDIUM
88
LOW
7,832 CVEs · Page 29/157
7.5
CVE-2026-13807

Use after free in Import in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user t

7.5
CVE-2026-13814

Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage

7.5
CVE-2026-13831

Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromise

7.5
CVE-2026-13855

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user

7.5
CVE-2026-14064

Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a

7.5
CVE-2026-14426

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in

7.5
CVE-2026-57984

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-57986

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-57992

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-58276

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-58294

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-15111

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engag

7.5
CVE-2026-15117

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to en

7.5
CVE-2026-40467

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may

7.5
CVE-2026-49171

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-50379

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a

7.5
CVE-2026-50414

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a

7.5
CVE-2026-50500

Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.

7.5
CVE-2026-50505

Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.

7.5
CVE-2026-56648

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevat

7.5
CVE-2026-57089

Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute co

7.5
CVE-2026-58531

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an aut

7.5
CVE-2026-15764

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user

7.5
CVE-2026-15765

Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engag

7.5
CVE-2026-15777

Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to

7.5
CVE-2026-58164

Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This iss

7.5
CVE-2026-17887

Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to eng

7.5
CVE-2026-17896

Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code i

7.5
CVE-2026-17898

Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a

7.5
CVE-2026-67299

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER

7.5
CVE-2026-67300

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAI

7.5
CVE-2026-66315

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-56848

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m

7.5
CVE-2026-67863

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when

7.5
CVE-2026-19142

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engag

7.5
CVE-2026-19158

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a us

7.5
CVE-2026-19159

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engag

7.5
CVE-2026-19165

Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to instal

7.5
CVE-2026-19176

Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the render

7.5
CVE-2026-62787

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

7.5
CVE-2026-62898

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

7.5
CVE-2026-19558

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to instal

7.5
CVE-2026-65343

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.

7.5
CVE-2026-56684

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPending

7.5
CVE-2026-26447

Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same

7.4
CVE-2026-20844

Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

7.4
CVE-2026-22264

Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead

7.4
CVE-2026-25167

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

7.4
CVE-2026-0112

In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local es

7.4
CVE-2026-32156

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code loc

Frequently Asked Questions

What is CWE-416?

CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-416?

There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.

How can I protect against CWE-416 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.

Detect CWE-416 Vulnerabilities

CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.

Get Started