Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-416

MITRE ↗

Use After Free

834
CRITICAL
5,751
HIGH
1,124
MEDIUM
88
LOW
7,832 CVEs · Page 33/157
7.0
CVE-2026-62724

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62725

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62726

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62729

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

7.0
CVE-2026-62734

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

7.0
CVE-2026-62748

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

7.0
CVE-2026-62749

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62773

Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62774

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62780

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62788

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62892

Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges loca

7.0
CVE-2026-62908

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all

7.0
CVE-2026-65678

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-65776

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-65778

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-65779

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-65781

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-65782

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-65783

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-65788

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-68820 KEV

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2026-70307

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2026-58093

The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty loc

6.8
CVE-2025-68656

Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_r

6.8
CVE-2026-11628

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap co

6.8
CVE-2026-13282

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e

6.8
CVE-2026-13595

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, an

6.7
CVE-2025-20785

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20786

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20787

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20802

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil

6.7
CVE-2025-20804

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if

6.7
CVE-2025-20805

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if

6.7
CVE-2025-20806

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if

6.7
CVE-2025-47336

Memory corruption while performing sensor register read operations.

6.7
CVE-2025-47337

Memory corruption while accessing a synchronization object during concurrent operations.

6.7
CVE-2026-20968

Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.

6.7
CVE-2026-20414

In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of pri

6.7
CVE-2026-20443

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2026-0027

In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to

6.7
CVE-2026-71968

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo

6.6
CVE-2025-47333

Memory corruption while handling buffer mapping operations in the cryptographic driver.

6.6
CVE-2026-57438

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitutio

6.6
CVE-2025-59615

Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe

6.6
CVE-2025-59616

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea

6.6
CVE-2025-59617

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.

6.6
CVE-2026-63729

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince co

6.6
CVE-2026-61920

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut

6.6
CVE-2026-18706

An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation

Frequently Asked Questions

What is CWE-416?

CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-416?

There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.

How can I protect against CWE-416 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.

Detect CWE-416 Vulnerabilities

CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.

Get Started