CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
719 results Clear all
CVE-2019-19725 9.8 CRITICAL EPSS 0.01
sysstat <12.2.0 - Use After Free
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
CWE-415 Dec 11, 2019
CVE-2019-2266 7.8 HIGH EPSS 0.00
Possible double free issue in kernel - Memory Corruption
Possible double free issue in kernel while handling the camera sensor and its sub modules power sequence in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MSM8909, MSM8909W, Nicobar, QCA9980, QCS405, QCS605, SDM845, SDX24, SM7150, SM8150
CWE-415 Nov 21, 2019
CVE-2019-5282 7.8 HIGH EPSS 0.00
Huawei - Double Free
Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12) have a double free vulnerability. An attacker tricks the user into installing a malicious application, which frees on the same memory address twice. Successful exploit could result in malicious code execution.
CWE-415 Nov 13, 2019
CVE-2011-1803 6.5 MEDIUM EPSS 0.00
Google Chrome <Blink M11-M12 - Info Disclosure
An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.
CWE-415 Nov 12, 2019
CVE-2011-2335 7.5 HIGH EPSS 0.00
Google Blink < m12 - Double Free
A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.
CWE-415 Nov 12, 2019
CVE-2019-18874 7.5 HIGH EPSS 0.00
psutil <5.6.5 - Use After Free
psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.
CWE-415 Nov 12, 2019
CVE-2019-10565 9.8 CRITICAL EPSS 0.00
Qualcomm Apq8053 Firmware - Double Free
Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, QCN7605, QCS405, QCS605, SDM845, SDX24, SXR1130
CWE-415 Nov 06, 2019
CVE-2019-17545 9.8 CRITICAL 1 Writeup EPSS 0.02
Osgeo Gdal < 3.0.1 - Double Free
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
CWE-415 Oct 14, 2019
CVE-2019-11932 8.8 HIGH 24 PoCs Analysis EPSS 0.68
android-gif-drawable <1.2.18 - RCE
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
CWE-415 Oct 03, 2019
CVE-2019-16880 9.8 CRITICAL EPSS 0.00
linea <0.9.4 - Memory Corruption
An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements method.
CWE-415 Sep 25, 2019
CVE-2019-5481 9.8 CRITICAL EPSS 0.05
Haxx Curl < 7.65.3 - Double Free
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
CWE-415 Sep 16, 2019
CVE-2019-2115 7.8 HIGH EPSS 0.00
Android <9 - Memory Corruption
In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CWE-415 Sep 05, 2019
CVE-2017-18595 7.8 HIGH EPSS 0.00
Linux kernel <4.14.11 - Memory Corruption
An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c.
CWE-415 Sep 04, 2019
CVE-2017-18594 7.5 HIGH EPSS 0.01
Nmap <7.70 - DoS
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
CWE-415 Aug 29, 2019
CVE-2018-20996 9.8 CRITICAL EPSS 0.00
Crossbeam < 0.4.1 - Double Free
An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling.
CWE-415 Aug 26, 2019
CVE-2019-15551 9.8 CRITICAL EPSS 0.00
Servo Smallvec < 0.6.10 - Double Free
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity.
CWE-415 Aug 26, 2019
CVE-2018-20991 9.8 CRITICAL EPSS 0.00
Servo Smallvec < 0.6.3 - Double Free
An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors, leading to a double free.
CWE-415 Aug 26, 2019
CVE-2019-15504 9.8 CRITICAL EPSS 0.04
Linux Kernel < 4.19.74 - Double Free
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
CWE-415 Aug 23, 2019
CVE-2019-8044 9.8 CRITICAL 1 PoC Analysis EPSS 0.37
Adobe Acrobat DC < 15.006.30499 - Double Free
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a double free vulnerability. Successful exploitation could lead to arbitrary code execution .
CWE-415 Aug 20, 2019
CVE-2019-2126 8.8 HIGH EPSS 0.09
Android -7.0-9.0 - Use After Free
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.
CWE-415 Aug 20, 2019