CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,098 CVEs tracked 53,218 with exploits 4,684 exploited in wild 1,536 CISA KEV 3,912 Nuclei templates 37,750 vendors 42,417 researchers
3 results Clear all
CVE-2025-8454 9.8 CRITICAL EPSS 0.00
Debian Devscripts - Signature Verification Bypass
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.
CWE-347 Aug 01, 2025
CVE-2013-7325 8.8 HIGH EPSS 0.01
uscan <2.13.19 - RCE
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
Dec 03, 2019
CVE-2018-13043 9.8 CRITICAL EPSS 0.01
Debian Devscripts < 2.18.3 - Code Injection
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.
CWE-94 Jul 01, 2018