CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
13,513 results Clear all
CVE-2025-1924 8.2 HIGH EPSS 0.00
Yokogawa Electric Corporation - DoS
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciously crafted packets, a DoS attack may cause Vnet/IP communication functions to stop or arbitrary programs to be executed. The affected products and versions are as follows: Vnet/IP Interface Package (for CENTUM VP R6 VP6C3300, CENTUM VP R7 VP7C3300) R1.07.00 or earlier
CWE-191 Feb 13, 2026
CVE-2026-26011 9.8 CRITICAL 1 Writeup EPSS 0.00
Nav2 AMCL <1.3.11 - Memory Corruption
navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering logic. By publishing a single crafted geometry_msgs/PoseWithCovarianceStamped message with extreme covariance values to the /initialpose topic, an unauthenticated attacker on the same ROS 2 DDS domain can trigger a negative index write (set->clusters[-1]) into heap memory preceding the allocated buffer. In Release builds, the sole boundary check (assert) is compiled out, leaving zero runtime protection. This primitive allows controlled corruption of the heap chunk metadata(at least the size of the heap chunk where the set->clusters is in is controllable by the attacker), potentially leading to further exploitation. At minimum, it provides a reliable single-packet denial of service that kills localization and halts all navigation.
CWE-787 Feb 12, 2026
CVE-2026-20644 6.5 MEDIUM EPSS 0.00
macOS Tahoe <26.3 - Memory Corruption
The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
CWE-119 Feb 11, 2026
CVE-2026-20616 6.5 MEDIUM EPSS 0.00
iOS <18.7.5 - Memory Corruption
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3, macOS Sonoma 14.8.4, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app termination.
CWE-787 Feb 11, 2026
CVE-2026-25990 7.5 HIGH 1 Writeup EPSS 0.00
Python Pillow < 12.1.1 - Out-of-Bounds Write
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
CWE-787 Feb 11, 2026
CVE-2020-37208 7.5 HIGH 1 PoC Analysis EPSS 0.00
SpotFTP 3.0.0.0 - Buffer Overflow
SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service.
CWE-787 Feb 11, 2026
CVE-2026-2314 8.8 HIGH EPSS 0.00
Google Chrome <145.0.7632.45 - Buffer Overflow
Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE-122 Feb 11, 2026
CVE-2025-48518 EPSS 0.00
AMD Graphics Driver - Memory Corruption
Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service.
CWE-787 Feb 11, 2026
CVE-2024-36324 8.8 HIGH EPSS 0.00
AMD Graphics Driver - RCE
Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution.
CWE-787 Feb 11, 2026
CVE-2025-57709 8.1 HIGH EPSS 0.00
Qnap Qsync Central < 5.0.0.4 - Out-of-Bounds Write
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
CWE-122 Feb 11, 2026
CVE-2025-30276 8.8 HIGH EPSS 0.00
Qsync Central <5.0.0.4 - Memory Corruption
An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
CWE-787 Feb 11, 2026
CVE-2026-21349 7.8 HIGH EPSS 0.00
Lightroom Desktop <15.1 - RCE
Lightroom Desktop versions 15.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CWE-787 Feb 10, 2026
CVE-2025-29949 EPSS 0.00
AMD Secure Processor - Memory Corruption
Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to write out-of-bounds to corrupt Secure DRAM potentially resulting in denial of service.
CWE-787 Feb 10, 2026
CVE-2024-36355 EPSS 0.00
SMM - Memory Corruption
Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify execution flow for S3 (sleep) wake up, potentially resulting in arbitrary code execution.
CWE-787 Feb 10, 2026
CVE-2026-25506 7.7 HIGH 1 Writeup EPSS 0.00
MUNGE 0.5-0.5.17 - Buffer Overflow
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
CWE-787 Feb 10, 2026
CVE-2026-21352 7.8 HIGH EPSS 0.00
Adobe Dng Software Development Kit < 1.7.2 - Out-of-Bounds Write
DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CWE-787 Feb 10, 2026
CVE-2026-21346 7.8 HIGH EPSS 0.00
Adobe Bridge < 15.1.4 - Out-of-Bounds Write
Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CWE-787 Feb 10, 2026
CVE-2026-21342 7.8 HIGH EPSS 0.00
Adobe Substance 3D Stager < 3.1.7 - Out-of-Bounds Write
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CWE-787 Feb 10, 2026
CVE-2026-21341 7.8 HIGH EPSS 0.00
Adobe Substance 3D Stager < 3.1.7 - Out-of-Bounds Write
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CWE-787 Feb 10, 2026
CVE-2026-21358 5.5 MEDIUM EPSS 0.00
Adobe Indesign < 20.5.2 - Out-of-Bounds Write
InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CWE-122 Feb 10, 2026