CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,379
Total CVEs
208
Critical
2,014
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
117
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 769
2 Google 400
3 Microsoft 261
4 Debian 239
5 Fedoraproject 206
6 Adobe 147
7 Qualcomm 88
8 Foxit 84
9 Apple 77
10 Mozilla 53

All Use After Free CVEs (2,379)

CVE-2026-21241
7.0

This vulnerability is a use-after-free flaw in Windows Ancillary Function Driver for WinSock that allows an authenticated attacker to execute arbitrar...

Feb 10, 2026
CVE-2026-21219
7.0

This CVE describes a use-after-free vulnerability in Inbox COM Objects that allows an unauthorized attacker to execute arbitrary code locally on affec...

Jan 13, 2026
CVE-2026-20842
7.0

This vulnerability involves a use-after-free flaw in Windows Desktop Window Manager (DWM) that allows an authenticated attacker to execute arbitrary c...

Jan 13, 2026
CVE-2025-20779
7.0

CVE-2025-20779 is a use-after-free vulnerability in display drivers caused by a race condition. This allows local attackers with System privilege to e...

Jan 6, 2026
CVE-2025-68617
7.0

A race condition in FluidSynth versions 2.5.0 to 2.5.1 allows heap-based use-after-free when unloading DLS files concurrently with synthesizer destruc...

Dec 23, 2025
CVE-2025-62213
7.0

CVE-2025-62213 is a use-after-free vulnerability in Windows Ancillary Function Driver for WinSock that allows authenticated attackers to execute arbit...

Nov 11, 2025
CVE-2025-60716
7.0

This vulnerability involves a use-after-free flaw in Windows DirectX that allows an authenticated attacker to execute arbitrary code with elevated pri...

Nov 11, 2025
CVE-2025-60717
7.0

CVE-2025-60717 is a use-after-free vulnerability in Windows Broadcast DVR User Service that allows authenticated attackers to execute arbitrary code w...

Nov 11, 2025
CVE-2025-59515
7.0

This CVE describes a use-after-free vulnerability in Windows Broadcast DVR User Service that allows an authenticated attacker to execute arbitrary cod...

Nov 11, 2025
CVE-2025-58738
7.0

CVE-2025-58738 is a use-after-free vulnerability in Inbox COM Objects that allows an unauthorized attacker to execute arbitrary code locally on affect...

Oct 14, 2025
CVE-2025-58732
7.0

This vulnerability involves a use-after-free flaw in Inbox COM Objects that allows an unauthorized local attacker to execute arbitrary code. It affect...

Oct 14, 2025
CVE-2025-58734
7.0

This vulnerability involves a use-after-free flaw in Inbox COM Objects that allows an unauthorized attacker to execute arbitrary code locally on affec...

Oct 14, 2025
CVE-2025-58736
7.0

This vulnerability involves a use-after-free flaw in Inbox COM Objects that allows an unauthorized attacker to execute arbitrary code locally on affec...

Oct 14, 2025
CVE-2025-58730
7.0

CVE-2025-58730 is a use-after-free vulnerability in Inbox COM Objects that allows an unauthorized attacker to execute arbitrary code on the local syst...

Oct 14, 2025
CVE-2025-55689
7.0

This vulnerability is a use-after-free flaw in Windows PrintWorkflowUserSvc that allows an authenticated attacker to execute arbitrary code with eleva...

Oct 14, 2025
CVE-2025-55691
7.0

CVE-2025-55691 is a use-after-free vulnerability in Windows PrintWorkflowUserSvc that allows authenticated attackers to execute arbitrary code with el...

Oct 14, 2025
CVE-2025-55684
7.0

This is a local privilege escalation vulnerability in Windows PrintWorkflowUserSvc service where an authorized attacker can exploit a use-after-free c...

Oct 14, 2025
CVE-2025-55685
7.0

This CVE describes a use-after-free vulnerability in the Windows PrintWorkflowUserSvc service that allows an authenticated attacker to execute arbitra...

Oct 14, 2025
CVE-2025-55331
7.0

CVE-2025-55331 is a use-after-free vulnerability in Windows PrintWorkflowUserSvc that allows authenticated attackers to escalate privileges locally. T...

Oct 14, 2025
CVE-2025-50174
7.0

CVE-2025-50174 is a use-after-free vulnerability in the Windows Device Association Broker service that allows an authenticated attacker to execute arb...

Oct 14, 2025
CVE-2025-23280
7.0

A use-after-free vulnerability in NVIDIA Display Driver for Linux allows attackers to potentially execute arbitrary code with elevated privileges. Thi...

Oct 10, 2025
CVE-2025-39826
7.0

This CVE describes a use-after-free vulnerability in the Linux kernel's ROSE networking protocol implementation. The vulnerability occurs due to non-a...

Sep 16, 2025
CVE-2025-54112
7.0

CVE-2025-54112 is a use-after-free vulnerability in Microsoft Virtual Hard Drive that allows an authenticated attacker to execute arbitrary code with ...

Sep 9, 2025
CVE-2025-53802
7.0

CVE-2025-53802 is a use-after-free vulnerability in Windows Bluetooth Service that allows an authenticated attacker to execute arbitrary code with ele...

Sep 9, 2025
CVE-2025-53718
7.0

CVE-2025-53718 is a use-after-free vulnerability in Windows Ancillary Function Driver for WinSock that allows authenticated attackers to execute arbit...

Aug 12, 2025
CVE-2025-53147
7.0

This is a use-after-free vulnerability in Windows Ancillary Function Driver for WinSock that allows an authenticated attacker to execute arbitrary cod...

Aug 12, 2025
CVE-2025-53140
7.0

CVE-2025-53140 is a use-after-free vulnerability in the Windows Kernel Transaction Manager that allows authenticated local attackers to execute arbitr...

Aug 12, 2025
CVE-2025-53142
7.0

This vulnerability is a use-after-free flaw in Microsoft's Brokering File System that allows an authenticated attacker to execute arbitrary code with ...

Aug 12, 2025
CVE-2025-53137
7.0

This vulnerability allows an authorized attacker to exploit a use-after-free flaw in Windows Ancillary Function Driver for WinSock to elevate privileg...

Aug 12, 2025
CVE-2025-49685
7.0

CVE-2025-49685 is a use-after-free vulnerability in Microsoft Windows Search Component that allows an authenticated attacker to execute arbitrary code...

Jul 8, 2025
CVE-2025-38051
7.0

A use-after-free vulnerability in the Linux kernel's CIFS client implementation allows an attacker to trigger memory corruption during concurrent dire...

Jun 18, 2025
CVE-2025-37776
7.0

This CVE describes a use-after-free vulnerability in the Linux kernel's ksmbd (SMB server) module. Attackers could potentially exploit this race condi...

May 1, 2025
CVE-2025-24983
KEV 7.0

This is a use-after-free vulnerability in the Windows Win32 Kernel Subsystem that allows an authenticated attacker to execute arbitrary code with elev...

Mar 11, 2025
CVE-2025-24078
7.0

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on affected systems by tricking users into opening ...

Mar 11, 2025
CVE-2024-46981
EPSS 69.3% 7.0

This CVE describes a use-after-free vulnerability in Redis where an authenticated user can craft a malicious Lua script to manipulate the garbage coll...

Jan 6, 2025
CVE-2024-56672
7.0

This is a use-after-free vulnerability in the Linux kernel's block cgroup subsystem that allows an attacker to potentially crash the system or execute...

Dec 27, 2024
CVE-2024-49097
7.0

This vulnerability in Windows PrintWorkflowUserSvc allows attackers to escalate privileges from a low-privileged user account to SYSTEM level. It affe...

Dec 12, 2024
CVE-2024-50286
7.0

This is a use-after-free vulnerability in the Linux kernel's ksmbd SMB server module caused by a race condition between session creation and expiratio...

Nov 19, 2024
CVE-2024-50154
7.0

A race condition in the Linux kernel's TCP/DCCP implementation can cause a use-after-free vulnerability when handling connection requests. This allows...

Nov 7, 2024
CVE-2024-50106
7.0

This is a use-after-free vulnerability in the Linux kernel's NFS server (nfsd) that allows a race condition between delegation cleanup and client oper...

Nov 5, 2024
CVE-2024-50086
7.0

This CVE describes a use-after-free vulnerability in the Linux kernel's ksmbd (SMB server) module. It allows an attacker to potentially crash the kern...

Oct 29, 2024
CVE-2024-50059
7.0

This is a use-after-free vulnerability in the Linux kernel's ntb_hw_switchtec driver caused by a race condition during module removal. It allows poten...

Oct 21, 2024
CVE-2024-50061
7.0

A use-after-free vulnerability in the Linux kernel's Cadence I3C master driver allows local attackers to potentially crash the system or execute arbit...

Oct 21, 2024
CVE-2022-48988
7.0

This Linux kernel vulnerability allows local attackers to trigger a use-after-free condition in the memory controller subsystem by manipulating file d...

Oct 21, 2024
CVE-2024-49903
7.0

A use-after-free vulnerability in the Linux kernel's JFS filesystem allows race conditions between dbUnmount and jfs_ioc_trim operations, potentially ...

Oct 21, 2024
CVE-2024-47747
7.0

This CVE describes a use-after-free vulnerability in the Linux kernel's ether3 network driver caused by a race condition during device removal. An att...

Oct 21, 2024
CVE-2024-43535
7.0

This vulnerability allows attackers to gain elevated privileges on Windows systems by exploiting a use-after-free bug in the kernel-mode driver. It af...

Oct 8, 2024
CVE-2024-46858
7.0

This is a use-after-free vulnerability in the Linux kernel's MPTCP subsystem that occurs due to a race condition in timer deletion. It allows attacker...

Sep 27, 2024
CVE-2024-23716
7.0

CVE-2024-23716 is a use-after-free vulnerability in Android's kernel memory management that allows local attackers to escalate privileges without user...

Sep 11, 2024
CVE-2024-38248
7.0

This Windows Storage Elevation of Privilege vulnerability allows an authenticated attacker to gain SYSTEM-level privileges by exploiting a use-after-f...

Sep 10, 2024

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,379 CVEs classified as CWE-416, with 208 rated critical and 2,014 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free