CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,223 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,429 researchers
5,317 results Clear all
CVE-2007-5653 1 PoC Analysis EPSS 0.03
Php < 5.2.4 - OS Command Injection
The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill bit set in the corresponding ActiveX control Compatibility Flags, executing programs via a function in compatUI.dll, invoking wscript.shell via wscript.exe, invoking Scripting.FileSystemObject via wshom.ocx, and adding users via a function in shgina.dll, related to the com_load_typelib function.
CWE-78 Oct 23, 2007
CVE-2007-5322 1 PoC Analysis EPSS 0.35
Microsoft Visual Foxpro - OS Command Injection
Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function.
CWE-78 Oct 09, 2007
CVE-2007-4673 EPSS 0.01
Apple QuickTime 7.2 - Command Injection
Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote attackers to execute arbitrary commands via a URL in the qtnext field in a crafted QTL file. NOTE: this issue may be related to CVE-2006-4965 or CVE-2007-5045.
CWE-78 Oct 04, 2007
CVE-2007-4891 1 PoC Analysis EPSS 0.52
Microsoft Visual Studio - OS Command Injection
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.
CWE-78 Sep 14, 2007
CVE-2007-4560 6 PoCs Analysis EPSS 0.86
ClamAV <0.91.2 - RCE
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."
CWE-78 Aug 28, 2007
CVE-2007-4041 EPSS 0.11
Mozilla Firefox <3.0alpha - Command Injection
Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.
CWE-78 Jul 27, 2007
CVE-2006-6427 EPSS 0.05
Xerox Workcentre - OS Command Injection
The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration. NOTE: vector 1 might be the same as CVE-2006-5290.
CWE-78 Dec 10, 2006
CVE-2006-0325 EPSS 0.03
Etomite < 0.6 - OS Command Injection
Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.
CWE-78 Jan 20, 2006
CVE-2005-2368 EPSS 0.02
Vim - OS Command Injection
vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.
CWE-78 Jul 26, 2005
CVE-2004-2732 1 PoC Analysis EPSS 0.02
Netbilling - OS Command Injection
nbmember.cgi in Netbilling 2.0 allows remote attackers to obtain sensitive information via the cmd=test option, which can be leveraged to determine the access key.
CWE-78 Dec 31, 2004
CVE-2003-0041 EPSS 0.01
MIT Kerberos FTP Client - OS Command Injection
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.
CWE-78 Feb 19, 2003
CVE-2002-1660 1 PoC Analysis EPSS 0.12
Jelsoft Vbulletin < 2.1.9 - OS Command Injection
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
CWE-78 Dec 31, 2002
CVE-2002-1898 1 PoC Analysis EPSS 0.06
Apple Terminal < 1.3.1 - OS Command Injection
Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is executed by Terminal.app window.
CWE-78 Dec 31, 2002
CVE-2002-0061 1 PoC Analysis EPSS 0.88
Apache HTTP Server < 1.3.24 - OS Command Injection
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
CWE-78 Mar 21, 2002
CVE-2001-1583 5 PoCs Analysis EPSS 0.46
Solaris 8 - RCE
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.
CWE-78 Dec 31, 2001
CVE-1999-0043 9.8 CRITICAL EPSS 0.02
ISC Inn - OS Command Injection
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
CWE-78 Dec 04, 1996
CVE-1999-0067 EPSS 0.87
Apache HTTP Server - OS Command Injection
phf CGI program allows remote command execution through shell metacharacters.
CWE-78 Mar 20, 1996