CVE & Exploit Intelligence Database

Updated 26m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,223 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,429 researchers
16 results Clear all
CVE-2025-5001 3.3 LOW EPSS 0.00
GNU PSPP <82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb - Integer Overflow
A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
CWE-190 May 20, 2025
CVE-2025-48188 2.9 LOW EPSS 0.00
GNU Pspp < 2.0.1 - Out-of-Bounds Read
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
CWE-125 May 16, 2025
CVE-2025-47816 2.9 LOW EPSS 0.00
GNU Pspp < 2.0.1 - Out-of-Bounds Read
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.
CWE-125 May 10, 2025
CVE-2025-47815 4.5 MEDIUM EPSS 0.00
GNU Pspp < 2.0.1 - Out-of-Bounds Write
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.
CWE-122 May 10, 2025
CVE-2025-47814 4.5 MEDIUM EPSS 0.00
GNU Pspp < 2.0.1 - Out-of-Bounds Write
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.
CWE-122 May 10, 2025
CVE-2025-47229 2.9 LOW EPSS 0.00
GNU Pspp < 2.0.1 - Reachable Assertion
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/dictionary.c code into src/data/variable.c code.
CWE-617 May 03, 2025
CVE-2022-39832 7.8 HIGH EPSS 0.00
GNU Pspp - Out-of-Bounds Write
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
CWE-787 Sep 05, 2022
CVE-2022-39831 7.8 HIGH EPSS 0.00
GNU Pspp - Out-of-Bounds Write
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.
CWE-787 Sep 05, 2022
CVE-2019-9211 6.5 MEDIUM EPSS 0.00
GNU Pspp - Reachable Assertion
There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.
CWE-617 Feb 27, 2019
CVE-2018-20230 7.8 HIGH EPSS 0.00
PSPP 1.2.0 - Buffer Overflow
An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
CWE-787 Dec 19, 2018
CVE-2017-12961 7.5 HIGH EPSS 0.00
GNU Pspp - Improper Input Validation
There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
CWE-20 Aug 18, 2017
CVE-2017-12960 7.5 HIGH EPSS 0.00
GNU Pspp - Reachable Assertion
There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
CWE-617 Aug 18, 2017
CVE-2017-12959 7.5 HIGH EPSS 0.00
GNU Pspp - Reachable Assertion
There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.
CWE-617 Aug 18, 2017
CVE-2017-12958 7.5 HIGH EPSS 0.00
GNU Pspp - Out-of-Bounds Read
There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
CWE-125 Aug 18, 2017
CVE-2017-10792 6.5 MEDIUM EPSS 0.00
GNU Pspp - NULL Pointer Dereference
There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.
CWE-476 Jul 02, 2017
CVE-2017-10791 6.5 MEDIUM EPSS 0.00
GNU Pspp - Integer Overflow
There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.
CWE-190 Jul 02, 2017