CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
719 results Clear all
CVE-2023-35371 7.8 HIGH EPSS 0.01
Microsoft 365 Apps - Double Free
Microsoft Office Remote Code Execution Vulnerability
CWE-415 Aug 08, 2023
CVE-2023-33952 6.7 MEDIUM EPSS 0.00
Linux kernel - Privilege Escalation
A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which may allow a local privileged user to escalate privileges and execute code in the context of the kernel.
CWE-415 Jul 24, 2023
CVE-2023-38434 7.5 HIGH 1 PoC Analysis EPSS 0.01
xHTTP <72f812d - Use After Free
xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.
CWE-415 Jul 18, 2023
CVE-2023-33161 7.8 HIGH EPSS 0.01
Microsoft Excel - RCE
Microsoft Excel Remote Code Execution Vulnerability
CWE-415 Jul 11, 2023
CVE-2023-21629 6.8 MEDIUM EPSS 0.00
Qualcomm Modem Firmware - Memory Corruption
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
CWE-415 Jul 04, 2023
CVE-2023-37365 6.5 MEDIUM EPSS 0.00
Hnswlib - Double Free
Hnswlib 0.7.0 has a double free in init_index when the M argument is a large integer.
CWE-415 Jun 30, 2023
CVE-2023-1999 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
libwebp - Use After Free
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
CWE-415 Jun 20, 2023
CVE-2023-3312 7.5 HIGH EPSS 0.00
Linux Kernel - DoS
A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service.
CWE-415 Jun 19, 2023
CVE-2023-35784 9.8 CRITICAL 1 Writeup EPSS 0.00
Openbsd Libressl < 3.6.3 - Use After Free
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
CWE-415 Jun 16, 2023
CVE-2023-33137 7.8 HIGH 1 PoC Analysis EPSS 0.03
Microsoft Excel - RCE
Microsoft Excel Remote Code Execution Vulnerability
CWE-415 Jun 14, 2023
CVE-2023-29368 7.0 HIGH EPSS 0.00
Windows Filtering Platform - Privilege Escalation
Windows Filtering Platform Elevation of Privilege Vulnerability
CWE-415 Jun 14, 2023
CVE-2023-29366 7.8 HIGH EPSS 0.01
Windows Geolocation Service - RCE
Windows Geolocation Service Remote Code Execution Vulnerability
CWE-415 Jun 14, 2023
CVE-2022-40522 8.4 HIGH EPSS 0.00
Qualcomm Csr8811 Firmware - Double Free
Memory corruption in Linux Networking due to double free while handling a hyp-assign.
CWE-415 Jun 06, 2023
CVE-2022-40507 8.4 HIGH EPSS 0.02
Qualcomm 315 5G Iot Modem Firmware - Double Free
Memory corruption due to double free in Core while mapping HLOS address to the list.
CWE-415 Jun 06, 2023
CVE-2022-33307 8.4 HIGH EPSS 0.00
Automotive - Memory Corruption
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
CWE-415 Jun 06, 2023
CVE-2022-33227 6.7 MEDIUM EPSS 0.00
Linux Android - Use After Free
Memory corruption in Linux android due to double free while calling unregister provider after register call.
CWE-415 Jun 06, 2023
CVE-2023-21106 7.8 HIGH EPSS 0.00
Google Android - Double Free
In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-265016072References: Upstream kernel
CWE-415 May 15, 2023
CVE-2023-28411 6.3 MEDIUM EPSS 0.00
Intel Server System D50tnp1mhcrlc Firmware < 2.90 - Double Free
Double free in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.
CWE-415 May 10, 2023
CVE-2023-24903 8.1 HIGH EPSS 0.01
Windows SSTP - RCE
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CWE-362 May 09, 2023
CVE-2023-21500 6.0 MEDIUM EPSS 0.00
Samsung Android - Double Free
Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
CWE-415 May 04, 2023