CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,223 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,429 researchers
5,811 results Clear all
CVE-2002-2298 1 PoC Analysis EPSS 0.01
Atthat.com Thatware < 0.5.3 - Code Injection
PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.
CWE-94 Dec 31, 2002
CVE-2002-2297 EPSS 0.01
Atthat.com Thatware - Code Injection
PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.
CWE-94 Dec 31, 2002
CVE-2002-1750 EPSS 0.01
Cgiscript Csguestbook - Code Injection
csGuestbook.cgi in CGISCRIPT.NET csGuestbook 1.0 allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
CWE-94 Dec 31, 2002
CVE-2002-0495 1 PoC Analysis EPSS 0.15
Cgiscript Cssearch Professional < 2.3 - Code Injection
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.
CWE-94 Aug 12, 2002
CVE-2001-0307 1 PoC Analysis EPSS 0.06
Bajie Java HTTP Server < 0.79 - Code Injection
Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.
CWE-94 May 03, 2001
CVE-2001-0308 1 PoC Analysis EPSS 0.06
Bajie Java HTTP Server < 0.79 - Code Injection
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.
CWE-94 May 03, 2001
CVE-2000-0155 1 PoC Analysis EPSS 0.02
Microsoft Windows 95 - Code Injection
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.
CWE-94 Feb 18, 2000
CVE-1999-0702 1 PoC Analysis EPSS 0.36
Microsoft Internet Explorer - Code Injection
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.
CWE-94 Sep 10, 1999
CVE-1999-0891 1 PoC Analysis EPSS 0.64
Microsoft Internet Explorer - Code Injection
The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.
CWE-94 Sep 01, 1999
CVE-1999-0491 1 PoC Analysis EPSS 0.00
GNU Bash < 2.04 - Code Injection
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.
CWE-94 Apr 20, 1999
CVE-1999-0509 EPSS 0.02
Shell Interpreters - RCE
Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.
CWE-94 May 29, 1996