CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
719 results Clear all
CVE-2023-29469 6.5 MEDIUM EPSS 0.00
Xmlsoft Libxml2 < 2.10.4 - Double Free
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the '\0' value).
CWE-415 Apr 24, 2023
CVE-2022-33231 9.3 CRITICAL EPSS 0.00
Product <Version - Memory Corruption
Memory corruption due to double free in core while initializing the encryption key.
CWE-415 Apr 13, 2023
CVE-2023-28296 7.8 HIGH EPSS 0.01
Microsoft Visual Studio 2017 < 15.9.54 - Double Free
Visual Studio Remote Code Execution Vulnerability
CWE-415 Apr 11, 2023
CVE-2023-28464 7.8 HIGH EPSS 0.00
Linux kernel <6.2.9 - Use After Free
hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation.
CWE-415 Mar 31, 2023
CVE-2022-4744 7.8 HIGH EPSS 0.00
Linux Kernel < 5.10.136 - Double Free
A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.
CWE-415 Mar 30, 2023
CVE-2023-27537 5.9 MEDIUM EPSS 0.00
Haxx Libcurl < 8.2.12 - Double Free
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.
CWE-415 Mar 30, 2023
CVE-2023-25801 8.0 HIGH 1 Writeup EPSS 0.00
Google Tensorflow < 2.12.0 - Double Free
TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter `pooling_ratio` to be equal to 1.0, as pooling on batch and channel dimensions is not supported. A fix is included in TensorFlow 2.12.0 and 2.11.1.
CWE-415 Mar 25, 2023
CVE-2023-21030 7.8 HIGH EPSS 0.00
Google Android - Double Free
In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226234140
CWE-415 Mar 24, 2023
CVE-2023-1449 5.3 MEDIUM 1 Writeup EPSS 0.00
GPAC 2.3-DEV-rev35-gbbca86917-master - Double Free
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223294 is the identifier assigned to this vulnerability.
CWE-415 Mar 17, 2023
CVE-2023-23402 7.8 HIGH EPSS 0.01
Microsoft Windows 10 1507 < 10.0.10240.19805 - Double Free
Windows Media Remote Code Execution Vulnerability
CWE-415 Mar 14, 2023
CVE-2022-40515 7.3 HIGH EPSS 0.00
Qualcomm Apq8009 Firmware - Double Free
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
CWE-415 Mar 10, 2023
CVE-2022-3707 5.5 MEDIUM EPSS 0.00
Linux Kernel < 6.1 - Double Free
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.
CWE-415 Mar 06, 2023
CVE-2023-27320 7.2 HIGH EPSS 0.00
Sudo < 1.9.13 - Double Free
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
CWE-415 Feb 28, 2023
CVE-2023-26545 4.7 MEDIUM 1 Writeup EPSS 0.00
Linux kernel <6.1.13 - Use After Free
In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.
CWE-415 Feb 25, 2023
CVE-2022-20803 8.6 HIGH EPSS 0.02
Clamav < 0.104.3 - Double Free
A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that may result in a double-free. An attacker could exploit this vulnerability by submitting a crafted OLE2 file to be scanned by ClamAV on the affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.
CWE-415 Feb 17, 2023
CVE-2022-40683 7.8 HIGH EPSS 0.00
Fortinet Fortiweb < 7.0.3 - Double Free
A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands
CWE-415 Feb 16, 2023
CVE-2021-33304 9.8 CRITICAL EPSS 0.01
virtualsquare picoTCP <2.1 - RCE
Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code.
CWE-415 Feb 15, 2023
CVE-2022-4450 7.5 HIGH EPSS 0.00
Openssl < 1.1.1t - Double Free
The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is responsible for freeing those buffers. It is possible to construct a PEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex() will return a failure code but will populate the header argument with a pointer to a buffer that has already been freed. If the caller also frees this buffer then a double free will occur. This will most likely lead to a crash. This could be exploited by an attacker who has the ability to supply malicious PEM files for parsing to achieve a denial of service attack. The functions PEM_read_bio() and PEM_read() are simple wrappers around PEM_read_bio_ex() and therefore these functions are also directly affected. These functions are also called indirectly by a number of other OpenSSL functions including PEM_X509_INFO_read_bio_ex() and SSL_CTX_use_serverinfo_file() which are also vulnerable. Some OpenSSL internal uses of these functions are not vulnerable because the caller does not free the header argument if PEM_read_bio_ex() returns a failure code. These locations include the PEM_read_bio_TYPE() functions as well as the decoders introduced in OpenSSL 3.0. The OpenSSL asn1parse command line application is also impacted by this issue.
CWE-415 Feb 08, 2023
CVE-2023-25136 6.5 MEDIUM 11 PoCs Analysis EPSS 0.90
Openbsd Openssh - Double Free
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
CWE-415 Feb 03, 2023
CVE-2022-3806 9.8 CRITICAL EPSS 0.00
Bluetooth HCI - Use After Free
Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer.
CWE-415 Jan 25, 2023