CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
120 results Clear all
CVE-2022-28319 7.8 HIGH EPSS 0.04
Bentley MicroStation CONNECT <10.16.02.034 - RCE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DM files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16340.
CWE-457 Mar 29, 2023
CVE-2022-28317 7.8 HIGH EPSS 0.03
Bentley MicroStation CONNECT 10.16.02.34 - RCE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16369.
CWE-457 Mar 29, 2023
CVE-2022-34390 7.5 HIGH EPSS 0.00
Dell Alienware Area-51 R5 Firmware - Use of Uninitialized Resource
Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
CWE-457 Oct 12, 2022
CVE-2022-2308 6.5 MEDIUM EPSS 0.00
vDPA - Info Disclosure
A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismatch, Virtio drivers config read helpers do not initialize the memory indirectly passed to vduse_vdpa_get_config() returning uninitialized memory from the stack. This could cause undefined behavior or data leaks in Virtio drivers.
CWE-457 Sep 01, 2022
CVE-2022-33716 2.3 LOW EPSS 0.00
ICCC TA <SMR Aug-2022 Release 1 - Info Disclosure
An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitialized memory.
CWE-457 Aug 05, 2022
CVE-2022-34655 7.5 HIGH EPSS 0.01
F5 Big-ip Access Policy Manager - Use of Uninitialized Resource
In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is configured on a virtual server, undisclosed traffic can cause Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE-457 Aug 04, 2022
CVE-2021-46631 7.8 HIGH EPSS 0.01
Bentley View 10.15.0.75 - RCE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF images. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15461.
CWE-457 Feb 18, 2022
CVE-2021-46617 7.8 HIGH EPSS 0.01
Bentley MicroStation CONNECT 10.16.0.80 - RCE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF images. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15411.
CWE-457 Feb 18, 2022
CVE-2021-46570 7.8 HIGH EPSS 0.01
Bentley View 10.16.0.80 - Info Disclosure
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-15364.
CWE-457 Feb 18, 2022
CVE-2021-46566 7.8 HIGH EPSS 0.01
Bentley MicroStation CONNECT 10.16.0.80 - RCE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15027.
CWE-457 Feb 18, 2022
CVE-2021-21966 5.3 MEDIUM EPSS 0.02
TI Simplelink Cc32xx Software Develop... - Use of Uninitialized Resource
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability.
CWE-457 Feb 16, 2022
CVE-2022-21217 9.8 CRITICAL EPSS 0.00
Reolink Rlc-410w Firmware - Out-of-Bounds Write
An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.
CWE-457 Jan 28, 2022
CVE-2021-40418 9.8 CRITICAL EPSS 0.01
R3D SDK - Use After Free
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUID that was parsed from a frame within the video container. Upon destruction of the object that owns it, the uninitialized member will be dereferenced and then destroyed using the object’s virtual destructor. Due to the object property being uninitialized, this can result in dereferencing an arbitrary pointer for the object’s virtual method table, which can result in code execution under the context of the application.
CWE-457 Dec 22, 2021
CVE-2021-44003 5.5 MEDIUM EPSS 0.00
Siemens Jt2go < 13.2.0.5 - Use of Uninitialized Resource
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to use of uninitialized memory while parsing user supplied TIFF files. This could allow an attacker to cause a denial-of-service condition.
CWE-457 Dec 14, 2021
CVE-2021-41253 5.9 MEDIUM 1 Writeup EPSS 0.01
Zydis <3.2.0 - Buffer Overflow
Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions provided in `zycore` in order to append untrusted user data to the formatter buffer within their custom formatter hooks can run into heap buffer overflows. Older versions of Zydis failed to properly initialize the string object within the formatter buffer, forgetting to initialize a few fields, leaving their value to chance. This could then in turn cause zycore functions like `ZyanStringAppend` to make incorrect calculations for the new target size, resulting in heap memory corruption. This does not affect the regular uncustomized Zydis formatter, because Zydis internally doesn't use the string functions in zycore that act upon these fields. However, because the zycore string functions are the intended way to work with the formatter buffer for users of the library that wish to extend the formatter, we still consider this to be a vulnerability in Zydis. This bug is patched starting in version 3.2.1. As a workaround, users may refrain from using zycore string functions in their formatter hooks until updating to a patched version.
CWE-457 Nov 08, 2021
CVE-2021-3928 7.8 HIGH 1 PoC 1 Writeup Analysis EPSS 0.00
Vim < 8.2.3582 - Use of Uninitialized Resource
vim is vulnerable to Use of Uninitialized Variable
CWE-457 Nov 05, 2021
CVE-2021-31435 7.8 HIGH EPSS 0.00
Foxit Studio Photo 3.6.6.931 - RCE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.931. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CMP files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12331.
CWE-457 Apr 29, 2021
CVE-2019-1010319 5.5 MEDIUM 1 Writeup EPSS 0.01
WavPack <5.1.0 - Use of Uninitialized Variable
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/33a0025d1d63ccd05d9dbaa6923d52b1446a62fe.
CWE-457 Jul 11, 2019
CVE-2019-1010317 5.5 MEDIUM 1 Writeup EPSS 0.01
WavPack <5.1.0 - Use of Uninitialized Variable
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseCaffHeaderConfig (caff.c:486). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/f68a9555b548306c5b1ee45199ccdc4a16a6101b.
CWE-457 Jul 11, 2019
CVE-2019-11038 5.3 MEDIUM EPSS 0.11
Libgd < 7.1.30 - Use of Uninitialized Resource
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.
CWE-457 Jun 19, 2019