Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-416

MITRE ↗

Use After Free

834
CRITICAL
5,751
HIGH
1,124
MEDIUM
88
LOW
7,832 CVEs · Page 56/157
7.0
CVE-2025-26640

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-26649

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel al

7.0
CVE-2025-27492

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel al

7.0
CVE-2025-29841

Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Managemen

7.0
CVE-2022-49956

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8712: fix use after free bugs _Read/Wr

7.0
CVE-2022-50129

In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix a use-after-free Change the LIO por

7.0
CVE-2025-49677

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-49685

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-49699

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-23281

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can

7.0
CVE-2025-50167

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an

7.0
CVE-2025-53137

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2025-53140

Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-53142

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-53147

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2025-53718

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2025-53721

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally

7.0
CVE-2025-38584

In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a rac

7.0
CVE-2025-53802

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-53807

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon

7.0
CVE-2025-54105

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File

7.0
CVE-2025-54108

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem

7.0
CVE-2025-54112

Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55223

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an

7.0
CVE-2025-39776

In the Linux kernel, the following vulnerability has been resolved: mm/debug_vm_pgtable: clear page table entries at de

7.0
CVE-2025-59215

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-59216

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon

7.0
CVE-2025-59220

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service

7.0
CVE-2023-53572

In the Linux kernel, the following vulnerability has been resolved: clk: imx: scu: use _safe list iterator to avoid a u

7.0
CVE-2023-53638

In the Linux kernel, the following vulnerability has been resolved: octeon_ep: cancel queued works in probe error path

7.0
CVE-2025-23280

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful ex

7.0
CVE-2025-50174

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55331

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55678

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55684

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55685

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55686

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55688

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55689

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55690

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-55691

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-58730

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-58731

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-58732

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-58733

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-58734

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-58735

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-58736

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-58737

Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-58738

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Frequently Asked Questions

What is CWE-416?

CWE-416 (Use After Free) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-416?

There are 9,940 CVE records associated with CWE-416 in our database. Of these, 834 are critical severity, 5751 are high severity, and 1124 are medium severity.

How can I protect against CWE-416 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-416 using AI-powered security agents.

Detect CWE-416 Vulnerabilities

CyberStrike's AI agents automatically detect use after free vulnerabilities across your infrastructure.

Get Started