CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
1,560 results Clear all
CVE-2022-3526 5.3 MEDIUM EPSS 0.01
Linux Kernel - Memory Leak
A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the function macvlan_handle_frame of the file drivers/net/macvlan.c of the component skb. The manipulation leads to memory leak. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211024.
CWE-401 Oct 16, 2022
CVE-2022-3524 4.3 MEDIUM EPSS 0.00
Linux Kernel - Memory Leak
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211021 was assigned to this vulnerability.
CWE-401 Oct 16, 2022
CVE-2022-2963 7.5 HIGH EPSS 0.00
Jasper - Memory Leak
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
CWE-401 Oct 14, 2022
CVE-2022-38371 7.5 HIGH EPSS 0.01
APOGEE MBC/MEC/PXC Compact/Modular & Desigo - Info Disclosure
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.7), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.21), APOGEE PXC Modular (BACnet) (All versions < V3.5.7), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.21), Desigo PXC00-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC00-U (All versions >= V2.3 < V6.30.37), Desigo PXC001-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC100-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC12-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC128-U (All versions >= V2.3 < V6.30.37), Desigo PXC200-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC22-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC22.1-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC36.1-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC50-E.D (All versions >= V2.3 < V6.30.37), Desigo PXC64-U (All versions >= V2.3 < V6.30.37), Desigo PXM20-E (All versions >= V2.3 < V6.30.37), Nucleus NET for Nucleus PLUS V1 (All versions < V5.2a), Nucleus NET for Nucleus PLUS V2 (All versions < V5.4), Nucleus ReadyStart V3 V2012 (All versions < V2012.08.1), Nucleus ReadyStart V3 V2017 (All versions < V2017.02.4), Nucleus Source Code (All versions including affected FTP server), TALON TC Compact (BACnet) (All versions < V3.5.7), TALON TC Modular (BACnet) (All versions < V3.5.7). The FTP server does not properly release memory resources that were reserved for incomplete connection attempts by FTP clients. This could allow a remote attacker to generate a denial of service condition on devices that incorporate a vulnerable version of the FTP server.
CWE-401 Oct 11, 2022
CVE-2022-41556 7.5 HIGH EPSS 0.02
lighttpd <1.4.67 - DoS
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
CWE-401 Oct 06, 2022
CVE-2022-41427 6.5 MEDIUM EPSS 0.00
Bento4 <1.6.0-639 - Memory Corruption
Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.
CWE-401 Oct 03, 2022
CVE-2022-41426 6.5 MEDIUM EPSS 0.00
Bento4 <1.6.0-639 - Memory Corruption
Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4split.
CWE-401 Oct 03, 2022
CVE-2022-41424 6.5 MEDIUM EPSS 0.00
Bento4 <1.6.0-639 - Memory Corruption
Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.
CWE-401 Oct 03, 2022
CVE-2022-41419 6.5 MEDIUM EPSS 0.00
Bento4 <1.6.0-639 - Memory Corruption
Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.
CWE-401 Oct 03, 2022
CVE-2022-41847 5.5 MEDIUM EPSS 0.00
Bento4 1.6.0-639 - Memory Corruption
An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.
CWE-401 Sep 30, 2022
CVE-2022-35894 6.0 MEDIUM EPSS 0.00
Insyde InsydeH2O <5.5 - Info Disclosure
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclosure.
CWE-401 Sep 22, 2022
CVE-2022-38178 7.5 HIGH EPSS 0.01
named - Memory Corruption
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
CWE-401 Sep 21, 2022
CVE-2022-38177 7.5 HIGH EPSS 0.01
named - Memory Corruption
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
CWE-401 Sep 21, 2022
CVE-2022-2906 7.5 HIGH EPSS 0.01
ISC Bind < 9.18.7 - Memory Leak
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
CWE-401 Sep 21, 2022
CVE-2022-35085 5.5 MEDIUM EPSS 0.00
Swftools - Memory Leak
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
CWE-401 Sep 21, 2022
CVE-2022-39005 7.5 HIGH EPSS 0.00
MPTCP - Memory Corruption
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
CWE-401 Sep 16, 2022
CVE-2022-39004 7.5 HIGH EPSS 0.00
MPTCP - Memory Corruption
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
CWE-401 Sep 16, 2022
CVE-2022-38600 5.5 MEDIUM EPSS 0.00
Mplayer SVN-r38374-13.0.1 - Memory Corruption
Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c.
CWE-401 Sep 15, 2022
CVE-2022-40439 6.5 MEDIUM EPSS 0.00
Axiosys Bento4 - Memory Leak
An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file.
CWE-401 Sep 14, 2022
CVE-2022-31222 2.3 LOW EPSS 0.00
Dell BIOS - Memory Corruption
Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order to cause the application to crash.
CWE-772 Sep 12, 2022