CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
107 results Clear all
CVE-2016-3074 9.8 CRITICAL 1 PoC Analysis EPSS 0.55
Libgd < 5.5.35 - Buffer Overflow
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.
CWE-681 Apr 26, 2016
CVE-2010-2807 EPSS 0.05
FreeType <2.4.2 - DoS/Code Injection
FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
CWE-681 Aug 19, 2010
CVE-2009-0231 8.8 HIGH EPSS 0.65
Microsoft Windows < Vista - RCE
The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."
CWE-681 Jul 15, 2009
CVE-2008-3282 7.8 HIGH EPSS 0.01
OpenOffice.org <2.4.1 - RCE
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability than CVE-2008-2152.
CWE-681 Aug 29, 2008
CVE-2008-1721 1 PoC Analysis EPSS 0.31
Python <2.5.2 - RCE
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
CWE-681 Apr 10, 2008
CVE-2007-4268 7.8 HIGH EPSS 0.01
Apple Mac OS X <10.4.11 - RCE
Integer signedness error in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk message with a negative value, which satisfies a signed comparison during mbuf allocation but is later interpreted as an unsigned value, which triggers a heap-based buffer overflow.
CWE-681 Nov 15, 2007
CVE-2007-4988 7.8 HIGH EPSS 0.02
Imagemagick < 6.3.5-9 - Buffer Overflow
Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.
CWE-681 Sep 24, 2007