CVE & Exploit Intelligence Database

Updated 51m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
15 results Clear all
CVE-2025-49744 7.0 HIGH 1 PoC Analysis EPSS 0.01
Microsoft Windows 10 1507 < 10.0.10240.21073 - Race Condition
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CWE-362 Jul 08, 2025
CVE-2025-47256 5.6 MEDIUM 1 PoC Analysis EPSS 0.00
Libxmp <4.6.2 - Buffer Overflow
Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.
CWE-191 May 06, 2025
CVE-2024-11477 7.8 HIGH 1 PoC Analysis EPSS 0.38
7-Zip - RCE
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24346.
CWE-191 Nov 22, 2024
CVE-2024-38063 9.8 CRITICAL 32 PoCs Analysis EPSS 0.89
Windows TCP/IP < - RCE
Windows TCP/IP Remote Code Execution Vulnerability
CWE-191 Aug 13, 2024
CVE-2023-28293 7.8 HIGH 1 PoC Analysis EPSS 0.07
Microsoft Windows 10 1607 < 10.0.14393.5850 - Integer Underflow
Windows Kernel Elevation of Privilege Vulnerability
CWE-191 Apr 11, 2023
CVE-2022-0185 8.4 HIGH KEV 11 PoCs Analysis EPSS 0.02
Linux kernel - Privilege Escalation
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
CWE-190 Feb 11, 2022
CVE-2021-31956 7.8 HIGH KEV 5 PoCs Analysis EPSS 0.91
Microsoft Windows 10 1507 < 10.0.10240.18967 - Integer Underflow
Windows NTFS Elevation of Privilege Vulnerability
CWE-191 Jun 08, 2021
CVE-2020-24370 5.3 MEDIUM 2 PoCs Analysis EPSS 0.02
Lua 5.4.0 - Memory Corruption
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
CWE-191 Aug 17, 2020
CVE-2019-15791 7.1 HIGH 1 PoC Analysis EPSS 0.00
Linux Kernel - Integer Underflow
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. After the btrfs ioctl completes this fd is closed, which then puts a reference to that file, leading to a refcount underflow.
CWE-191 Apr 24, 2020
CVE-2017-14496 7.5 HIGH 1 PoC Analysis EPSS 0.16
dnsmasq <2.78 - DoS
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
CWE-191 Oct 03, 2017
CVE-2014-8768 1 PoC Analysis EPSS 0.28
tcpdump <4.7 - DoS
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.
CWE-191 Nov 20, 2014
CVE-2014-0497 9.8 CRITICAL KEV 2 PoCs Analysis EPSS 0.93
Adobe Flash Player Integer Underflow Remote Code Execution
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
CWE-191 Feb 05, 2014
CVE-2005-0199 9.8 CRITICAL 1 PoC Analysis EPSS 0.20
Barton Ngircd < 0.8.2 - Integer Underflow
Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.
CWE-191 May 02, 2005
CVE-2004-0816 7.5 HIGH 1 PoC Analysis EPSS 0.07
Linux <2.6.8 - DoS
Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.
CWE-191 Dec 23, 2004
CVE-2004-0184 1 PoC Analysis EPSS 0.65
Tcpdump < 3.8.1 - Integer Underflow
Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.
CWE-125 May 04, 2004