CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
160 results Clear all
CVE-2026-28686 6.8 MEDIUM EPSS 0.00
ImageMagick <7.1.2-16/6.9.13-41 - Buffer Overflow
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, A heap-buffer-overflow vulnerability exists in the PCL encode due to an undersized output buffer allocation. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
CWE-131 Mar 10, 2026
CVE-2026-20049 7.7 HIGH EPSS 0.00
Cisco ASA/FTD - DoS
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. To exploit this vulnerability, the attacker must have valid credentials to establish a VPN connection with the affected device.
CWE-131 Mar 04, 2026
CVE-2026-2738 EPSS 0.00
ovpn-dco-win 2.8.0 - Buffer Overflow
Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag appears at the end of the encrypted packet
CWE-131 Feb 19, 2026
CVE-2025-33124 6.5 MEDIUM EPSS 0.00
IBM DB2 12.1.0.0 - Buffer Overflow
IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer size.
CWE-131 Feb 17, 2026
CVE-2026-1188 9.8 CRITICAL EPSS 0.00
Eclipse Omr < 0.8.0 - Buffer Overflow
In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly sized, failing to account for the separator when determining when a write to the buffer was safe could lead to a buffer overflow. This issue is fixed in Eclipse OMR version 0.8.0.
CWE-131 Jan 29, 2026
CVE-2026-22791 6.6 MEDIUM 1 Writeup EPSS 0.00
Opencryptoki - Buffer Overflow
openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service.
CWE-131 Jan 13, 2026
CVE-2026-21503 6.1 MEDIUM 1 Writeup EPSS 0.00
Color Iccdev < 2.3.1.2 - NULL Pointer Dereference
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV has undefined behavior due to a null pointer passed to memcpy() in CIccTagSparseMatrixArray. This issue has been patched in version 2.3.1.2.
CWE-131 Jan 07, 2026
CVE-2025-62550 8.8 HIGH EPSS 0.00
Microsoft Azure Monitor Agent < 1.35.9 - Out-of-Bounds Write
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
CWE-131 Dec 09, 2025
CVE-2025-66216 9.8 CRITICAL 1 Writeup EPSS 0.00
AIS-catcher <0.64 - Buffer Overflow
AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message class of AIS-catcher. This vulnerability allows an attacker to write approximately 1KB of arbitrary data into a 128-byte buffer. This issue has been patched in version 0.64.
CWE-131 Nov 29, 2025
CVE-2025-61661 4.8 MEDIUM EPSS 0.00
GRUB - DoS
A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited.
CWE-131 Nov 18, 2025
CVE-2025-27074 8.8 HIGH EPSS 0.00
Product <Version - Memory Corruption
Memory corruption while processing a GP command response.
CWE-131 Nov 04, 2025
CVE-2025-33126 6.5 MEDIUM EPSS 0.00
IBM DB2 High Performance Unload - DoS
IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer size.
CWE-131 Oct 28, 2025
CVE-2025-27053 7.8 HIGH EPSS 0.00
PlayReady APP < unknown - Memory Corruption
Memory corruption during PlayReady APP usecase while processing TA commands.
CWE-131 Oct 09, 2025
CVE-2025-57807 3.8 LOW 1 Writeup EPSS 0.00
Imagemagick < 6.9.13-29 - Out-of-Bounds Write
ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.
CWE-131 Sep 05, 2025
CVE-2025-55297 8.8 HIGH 1 Writeup EPSS 0.00
ESP-IDF - Memory Corruption
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.
CWE-131 Aug 21, 2025
CVE-2025-52955 6.5 MEDIUM EPSS 0.00
Juniper Junos < 21.2 - Denial of Service
An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a memory corruption that leads to a rpd crash.  When the logical interface using a routing instance flaps continuously, specific updates are sent to the jflow/sflow modules. This results in memory corruption, leading to an rpd crash and restart.  Continued receipt of these specific updates will cause a sustained Denial of Service condition. This issue affects Junos OS: * All versions before 21.2R3-S9, * All versions of 21.4, * All versions of 22.2, * from 22.4 before 22.4R3-S7, * from 23.2 before 23.2R2-S3, * from 23.4 before 23.4R2-S4, * from 24.2 before 24.2R2. Junos OS Evolved:  * All versions of 21.2-EVO,  * All versions of 21.4-EVO,  * All versions of 22.2-EVO,  * from 22.4 before 22.4R3-S7-EVO,  * from 23.2 before 23.2R2-S3-EVO,  * from 23.4 before 23.4R2-S4-EVO,  * from 24.2 before 24.2R2-EVO.
CWE-131 Jul 11, 2025
CVE-2025-27042 7.8 HIGH EPSS 0.00
Firmware <unknown> - Memory Corruption
Memory corruption while processing video packets received from video firmware.
CWE-131 Jul 08, 2025
CVE-2025-46723 1 Writeup EPSS 0.01
OpenVM 1.0.0 - Buffer Overflow
OpenVM is a performant and modular zkVM framework built for customization and extensibility. In version 1.0.0, OpenVM is vulnerable to overflow through byte decomposition of pc in AUIPC chip. A typo results in the highest limb of pc being range checked to 8-bits instead of 6-bits. This results in the if statement never being triggered because the enumeration gives i=0,1,2, when instead the enumeration should give i=1,2,3, leaving pc_limbs[3] range checked to 8-bits instead of 6-bits. This leads to a vulnerability where the pc_limbs decomposition differs from the true pc, which means a malicious prover can make the destination register take a different value than the AUIPC instruction dictates, by making the decomposition overflow the BabyBear field. This issue has been patched in version 1.1.0.
CWE-131 May 02, 2025
CVE-2025-46688 5.6 MEDIUM 2 Writeups EPSS 0.00
QuickJS <2025-04-26 - Buffer Overflow
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
CWE-131 Apr 27, 2025
CVE-2025-46393 2.9 LOW 2 Writeups EPSS 0.00
ImageMagick <7.1.1-44 - Buffer Overflow
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).
CWE-131 Apr 23, 2025