CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
719 results Clear all
CVE-2021-40573 5.5 MEDIUM 1 Writeup EPSS 0.00
Gpac 1.0.1 - Use After Free
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service.
CWE-415 Jan 13, 2022
CVE-2021-40572 5.5 MEDIUM 1 Writeup EPSS 0.00
Gpac 1.0.1 - Use After Free
The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows attackers to cause a denial of service.
CWE-415 Jan 13, 2022
CVE-2021-40571 7.8 HIGH 1 Writeup EPSS 0.00
Gpac 1.0.1 - Use After Free
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
CWE-415 Jan 13, 2022
CVE-2021-40570 7.8 HIGH 1 Writeup EPSS 0.00
Gpac 1.0.1 - Use After Free
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
CWE-415 Jan 13, 2022
CVE-2021-40569 5.5 MEDIUM 1 Writeup EPSS 0.00
Gpac <1.0.1 - Use After Free
The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.c, which allows attackers to cause a denial of service.
CWE-415 Jan 13, 2022
CVE-2021-37529 5.5 MEDIUM EPSS 0.00
Fig2dev < 3.2.8a - Double Free
A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).
CWE-415 Jan 12, 2022
CVE-2021-40038 7.5 HIGH EPSS 0.00
Huawei Harmonyos < 2.0 - Double Free
There is a Double free vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
CWE-415 Jan 10, 2022
CVE-2021-37120 9.8 CRITICAL EPSS 0.00
Huawei Emui - Double Free
There is a Double free vulnerability in Smartphone.Successful exploitation of this vulnerability may cause a kernel crash or privilege escalation.
CWE-415 Jan 03, 2022
CVE-2021-45288 5.5 MEDIUM EPSS 0.00
Gpac - Double Free
A Double Free vulnerability exists in filedump.c in GPAC 1.0.1, which could cause a Denail of Service via a crafted file in the MP4Box command.
CWE-415 Dec 21, 2021
CVE-2021-44732 9.8 CRITICAL EPSS 0.01
ARM Mbed TLS < 2.16.12 - Double Free
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
CWE-415 Dec 20, 2021
CVE-2021-37072 7.5 HIGH EPSS 0.00
Huawei Harmonyos < 2.0 - Double Free
There is a Incorrect Calculation of Buffer Size vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory crash.
CWE-415 Dec 07, 2021
CVE-2021-43268 6.5 MEDIUM EPSS 0.00
VxWorks <7 - Memory Corruption
An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free.
CWE-415 Nov 24, 2021
CVE-2021-40873 7.5 HIGH EPSS 0.01
Softing Industrial Automation OPC UA C++ SDK <5.66 - DoS
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.
CWE-415 Nov 10, 2021
CVE-2021-1119 7.1 HIGH EPSS 0.00
NVIDIA vGPU software - Use After Free
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead to denial of service. This flaw may result in a write-what-where condition, allowing an attacker to execute arbitrary code impacting integrity and availability.
CWE-415 Oct 29, 2021
CVE-2021-21797 7.8 HIGH EPSS 0.73
Gonitro Nitro Pro - Double Free
An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When closed, the document will result in the reference being released twice. This can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger this vulnerability.
CWE-415 Oct 18, 2021
CVE-2021-25477 4.4 MEDIUM EPSS 0.00
Mediatek RRC Protocol <SMR Oct-2021 Release 1 - DoS
An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.
CWE-415 Oct 06, 2021
CVE-2021-22945 9.1 CRITICAL EPSS 0.00
libcurl <= 7.73.0, 7.78.0 - Use After Free
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
CWE-415 Sep 23, 2021
CVE-2021-34769 8.6 HIGH EPSS 0.00
Cisco Ios XE - Double Free
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit the vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.
CWE-415 Sep 23, 2021
CVE-2021-34768 8.6 HIGH EPSS 0.00
Cisco Ios XE - Double Free
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit the vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.
CWE-415 Sep 23, 2021
CVE-2021-1565 8.6 HIGH EPSS 0.00
Cisco Ios XE - Double Free
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit the vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.
CWE-415 Sep 23, 2021