Vulnerabilities Exploited in the Wild with Public PoC

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
2,390 results Clear all
CVE-2008-2463 EXPLOITED 3 PoCs Analysis EPSS 0.84
Microsoft Office Snapshot Viewer Activex - Code Injection
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
CWE-94 Jul 07, 2008
CVE-2008-0081 9.8 CRITICAL EXPLOITED 1 PoC Analysis EPSS 0.82
Microsoft Excel - Use of Uninitialized Resource
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
CWE-908 Jan 16, 2008
CVE-2008-3681 EXPLOITED 1 PoC Analysis EPSS 0.55
Joomla! <1.5.6 - Info Disclosure
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" password, typically for the administrator.
CWE-264 Aug 14, 2008
CVE-2007-0885 EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.01
Rainbow/Zen - XSS
Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Feb 12, 2007
CVE-2007-5659 7.8 HIGH KEV 3 PoCs Analysis EPSS 0.93
Adobe Acrobat < 8.1.2 - Buffer Overflow
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
CWE-120 Feb 12, 2008
CVE-2007-3010 9.8 CRITICAL KEV 4 PoCs Analysis NUCLEI EPSS 0.94
Al-enterprise Omnipcx Enterprise Comm... - Command Injection
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
CWE-77 Sep 18, 2007
CVE-2007-1036 EXPLOITED RANSOMWARE 4 PoCs Analysis EPSS 0.90
JBoss - Auth Bypass
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
CWE-264 Feb 21, 2007
CVE-2007-5587 EXPLOITED 1 PoC Analysis EPSS 0.00
Macrovision Safedisc - Memory Corruption
Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.
CWE-119 Oct 19, 2007
CVE-2007-5633 EXPLOITED 1 PoC Analysis EPSS 0.00
Alfredo Milani Comparetti SpeedFan <4.33 - Privilege Escalation
Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, allows local users to read or write arbitrary MSRs, and gain privileges and load unsigned drivers, via the (1) IOCTL_RDMSR 0x9C402438 and (2) IOCTL_WRMSR 0x9C40243C IOCTLs to \Device\speedfan, as demonstrated by an IOCTL_WRMSR action on MSR_LSTAR.
Oct 23, 2007
CVE-2007-5722 EXPLOITED 1 PoC Analysis EPSS 0.07
Ourgame.com Globallink - Memory Corruption
Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly other products, allows remote attackers to execute arbitrary code via a long first argument to the ConnectAndEnterRoom method, possibly involving the GLCHAT.GLChatCtrl.1 control, as originally exploited in the wild in October 2007. NOTE: some of these details are obtained from third party information. NOTE: this was originally reported as a heap-based issue by some sources.
CWE-119 Oct 30, 2007
CVE-2007-1675 EXPLOITED 3 PoCs Analysis EPSS 0.77
IBM Lotus Domino - Buffer Overflow
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.
Mar 28, 2007
CVE-2007-4816 EXPLOITED 1 PoC Analysis EPSS 0.13
Baofeng Storm - Memory Corruption
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a long first argument to the advancedOpen method; a long argument to the (5) isDVDPath or (6) rawParse method; or (7) a .smpl file with a long path attribute in an item element in a PlayList.
CWE-119 Sep 11, 2007
CVE-2007-4748 EXPLOITED 1 PoC Analysis EPSS 0.06
Ppstream - Memory Corruption
Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitrary code via a long Logo parameter.
CWE-119 Sep 06, 2007
CVE-2007-4105 EXPLOITED 1 PoC Analysis EPSS 0.07
BaiduBar.dll - RCE
A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a link to download and a file to execute," possibly involving remote file inclusion.
Jul 31, 2007
CVE-2007-6166 EXPLOITED 10 PoCs Analysis EPSS 0.84
Apple QuickTime <7.3.1 - Buffer Overflow
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.
CWE-119 Nov 29, 2007
CVE-2007-5601 EXPLOITED 3 PoCs Analysis EPSS 0.68
Realnetworks Realplayer - Memory Corruption
Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll.
CWE-119 Oct 20, 2007
CVE-2007-3147 EXPLOITED 4 PoCs Analysis EPSS 0.69
Yahoo Messenger - Memory Corruption
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the send method. NOTE: some of these details are obtained from third party information.
CWE-119 Jun 11, 2007
CVE-2007-3148 EXPLOITED 2 PoCs Analysis EPSS 0.63
Yahoo Messenger - Memory Corruption
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method.
CWE-119 Jun 11, 2007
CVE-2007-2987 EXPLOITED 4 PoCs Analysis EPSS 0.74
Zenturi Programchecker - Memory Corruption
Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the (1) DebugMsgLog or (2) DoFileProperties methods.
CWE-119 Jun 01, 2007
CVE-2007-2496 EXPLOITED 1 PoC Analysis EPSS 0.07
WordViewer.ocx 3.2.0.5 - DoS
The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.
May 04, 2007