Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-416

MITRE ↗

Use After Free

834
CRITICAL
5,751
HIGH
1,124
MEDIUM
88
LOW
7,832 CVEs · Page 55/157
7.5
CVE-2025-29831

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

7.5
CVE-2025-1706

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern

7.5
CVE-2025-27038 KEV

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

7.5
CVE-2025-52946

A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Ju

7.5
CVE-2025-46709

Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kern

7.5
CVE-2025-57616

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleav

7.5
CVE-2025-54588

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Version

7.5
CVE-2025-11234

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSourc

7.5
CVE-2025-62170

rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality

7.5
CVE-2025-55326

Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a net

7.5
CVE-2025-48008

When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with

7.5
CVE-2025-12105

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-base

7.5
CVE-2025-62788

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_ev

7.5
CVE-2025-12437

Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to eng

7.5
CVE-2025-64183

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the

7.5
CVE-2024-9126

Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a use

7.5
CVE-2025-59946

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing iss

7.4
CVE-2024-41168

Use after free in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may al

7.4
CVE-2025-20006

Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenti

7.4
CVE-2025-54103

Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.

7.4
CVE-2025-8410

Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.This issue affects

7.4
CVE-2025-48004

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

7.4
CVE-2025-55335

Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

7.4
CVE-2025-55687

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File Sy

7.4
CVE-2025-55693

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

7.4
CVE-2025-59189

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

7.4
CVE-2025-59206

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

7.4
CVE-2025-59210

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

7.4
CVE-2025-36934

In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race co

7.3
CVE-2025-29792

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

7.3
CVE-2025-48798

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been special

7.3
CVE-2025-49682

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

7.3
CVE-2025-50159

Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privilege

7.3
CVE-2025-54911

Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

7.3
CVE-2023-53500

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix slab-use-after-free in decode_session6 W

7.3
CVE-2023-53640

In the Linux kernel, the following vulnerability has been resolved: ASoC: lpass: Fix for KASAN use_after_free out of bo

7.3
CVE-2025-62229

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error

7.3
CVE-2025-62230

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The soft

7.3
CVE-2025-62565

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

7.1
CVE-2025-21379

DHCP Client Service Remote Code Execution Vulnerability

7.1
CVE-2025-27491

Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.

7.1
CVE-2025-48821

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges

7.1
CVE-2025-10527

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, F

7.1
CVE-2025-47342

Transient DOS may occur when multi-profile concurrency arises with QHS enabled.

7.0
CVE-2024-46981

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua

7.0
CVE-2022-49127

In the Linux kernel, the following vulnerability has been resolved: ref_tracker: implement use-after-free detection Wh

7.0
CVE-2022-49287

In the Linux kernel, the following vulnerability has been resolved: tpm: fix reference counting for struct tpm_chip Th

7.0
CVE-2025-24078

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-24983 KEV

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-21915

In the Linux kernel, the following vulnerability has been resolved: cdx: Fix possible UAF error in driver_override_show

Frequently Asked Questions

What is CWE-416?

CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-416?

There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.

How can I protect against CWE-416 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.

Detect CWE-416 Vulnerabilities

CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.

Get Started