CVE & Exploit Intelligence Database

Updated 36m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
719 results Clear all
CVE-2022-29032 7.8 HIGH EPSS 0.00
JT2Go, Teamcenter Visualization <13.3.0.3, 14.0.0.1 - RCE
A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The CGM_NIST_Loader.dll library contains a double free vulnerability while parsing specially crafted CGM files. An attacker could leverage this vulnerability to execute code in the context of the current process.
CWE-415 May 20, 2022
CVE-2022-28738 9.8 CRITICAL EPSS 0.00
Ruby <3.0.4, <3.1.2 - Memory Corruption
A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.
CWE-415 May 09, 2022
CVE-2020-14123 7.5 HIGH EPSS 0.00
Miui - Double Free
There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module crashing and affecting normal functionality, and if successfully exploited the vulnerability can cause elevation of privileges.
CWE-415 Apr 22, 2022
CVE-2021-42778 5.3 MEDIUM 1 Writeup EPSS 0.00
Opensc < 0.22.0 - Double Free
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
CWE-415 Apr 18, 2022
CVE-2022-29156 7.8 HIGH 1 Writeup EPSS 0.00
Linux kernel <5.16.12 - Use After Free
drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.
CWE-415 Apr 13, 2022
CVE-2022-27416 7.8 HIGH EPSS 0.00
Broadcom Tcpreplay - Double Free
Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free.
CWE-415 Apr 12, 2022
CVE-2022-25796 7.8 HIGH EPSS 0.00
Autodesk Navisworks < 2022.2 - Double Free
A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks 2022 within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
CWE-415 Apr 11, 2022
CVE-2022-28390 7.8 HIGH 1 Writeup EPSS 0.00
Linux kernel <5.17.1 - Memory Corruption
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
CWE-415 Apr 03, 2022
CVE-2022-28389 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux kernel <5.17.1 - Use After Free
mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
CWE-415 Apr 03, 2022
CVE-2022-28388 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux kernel <5.17.1 - Use After Free
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
CWE-415 Apr 03, 2022
CVE-2021-42533 7.8 HIGH EPSS 0.05
Adobe Bridge < 11.1.1 - Double Free
Adobe Bridge version 11.1.1 (and earlier) is affected by a double free vulnerability when parsing a crafted DCM file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
CWE-415 Mar 16, 2022
CVE-2021-39725 6.7 MEDIUM EPSS 0.00
Google Android - Double Free
In gasket_free_coherent_memory_all of gasket_page_table.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-151454974References: N/A
CWE-415 Mar 16, 2022
CVE-2021-23158 9.8 CRITICAL 1 Writeup EPSS 0.00
htmldoc <1.9.12 - RCE
A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.
CWE-415 Mar 16, 2022
CVE-2021-46700 6.5 MEDIUM EPSS 0.00
Libsixel <1.8.6 - Use After Free
In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.
CWE-415 Feb 19, 2022
CVE-2021-46625 7.8 HIGH EPSS 0.01
Bentley View <10.15.0.75 - RCE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of JT files. The issue results from the lack of validating the existence of an object prior to performing further free operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15455.
CWE-415 Feb 18, 2022
CVE-2021-46621 7.8 HIGH EPSS 0.01
Bentley MicroStation CONNECT 10.16.0.80 - RCE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of JT files. The issue results from the lack of validating the existence of an object prior to performing further free operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15415.
CWE-415 Feb 18, 2022
CVE-2021-4091 7.5 HIGH EPSS 0.00
389-ds-base - Memory Corruption
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
CWE-415 Feb 18, 2022
CVE-2021-22600 6.6 MEDIUM KEV 3 PoCs Analysis EPSS 0.00
Linux Kernel - Privilege Escalation
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
CWE-415 Jan 26, 2022
CVE-2022-23012 7.5 HIGH EPSS 0.01
F5 Big-ip Access Policy Manager < 14.1.4.5 - Double Free
On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE-415 Jan 25, 2022
CVE-2021-40574 7.8 HIGH 1 Writeup EPSS 0.01
Gpac MP4Box <1.0.1 - Code Execution
The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
CWE-415 Jan 13, 2022