CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
442 results Clear all
CVE-2023-23578 7.5 HIGH EPSS 0.00
Seiko-sol Skybridge Mb-a200 Firmware - Origin Validation Error
Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenticated attacker to connect to the product's ADB port.
CWE-346 May 10, 2023
CVE-2023-28318 5.3 MEDIUM EPSS 0.00
Rocket.chat - Improper Authorization
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.
CWE-346 May 09, 2023
CVE-2023-27962 5.5 MEDIUM EPSS 0.00
Apple Macos < 11.7.5 - Origin Validation Error
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to modify protected parts of the file system.
CWE-346 May 08, 2023
CVE-2023-27944 8.6 HIGH EPSS 0.00
Apple Macos < 11.7.5 - Origin Validation Error
This issue was addressed with a new entitlement. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to break out of its sandbox.
CWE-346 May 08, 2023
CVE-2023-27932 5.5 MEDIUM EPSS 0.00
Apple Safari < 16.4 - Origin Validation Error
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.
CWE-346 May 08, 2023
CVE-2023-29868 6.5 MEDIUM EPSS 0.00
Zammad < 5.4.0 - Origin Validation Error
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
CWE-346 May 02, 2023
CVE-2023-29867 6.5 MEDIUM EPSS 0.00
Zammad < 5.4.0 - Origin Validation Error
Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.
CWE-346 May 02, 2023
CVE-2023-2445 4.9 MEDIUM EPSS 0.00
Devolutions Server < 2023.1.3.0 - Origin Validation Error
Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.
CWE-346 May 02, 2023
CVE-2023-30856 8.3 HIGH 1 Writeup EPSS 0.00
Edex-ui < 2.2.8 - Origin Validation Error
eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control websocket, and send arbitrary commands to the shell. The project has been archived since 2021, and as of time of publication there are no plans to patch this issue and release a new version. Some workarounds are available, including shutting down eDEX-UI when browsing the web and ensuring the eDEX terminal runs with lowest possible privileges.
CWE-346 Apr 28, 2023
CVE-2023-26114 8.2 HIGH 1 Writeup EPSS 0.00
code-server <4.10.1 - Info Disclosure
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.
CWE-346 Mar 23, 2023
CVE-2023-0957 8.2 HIGH 1 Writeup EPSS 0.00
Gitpod < 2022.11.2 - Origin Validation Error
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace.
CWE-346 Mar 03, 2023
CVE-2022-45139 5.3 MEDIUM EPSS 0.00
Wago 751-9301 Firmware < 22 - Origin Validation Error
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.
CWE-346 Feb 27, 2023
CVE-2021-33959 7.5 HIGH 1 PoC Analysis EPSS 0.09
Plex Media Server < 1.21 - Origin Validation Error
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
CWE-346 Jan 18, 2023
CVE-2023-0132 6.5 MEDIUM EPSS 0.00
Google Chrome <109.0.5414.74 - RCE
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
CWE-346 Jan 10, 2023
CVE-2023-22899 5.9 MEDIUM EPSS 0.00
Zip4j < 2.11.2 - Origin Validation Error
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
CWE-346 Jan 10, 2023
CVE-2014-125071 5.5 MEDIUM EPSS 0.00
Gribbit < 2014-12-31 - Origin Validation Error
A vulnerability was found in lukehutch Gribbit. It has been classified as problematic. Affected is the function messageReceived of the file src/gribbit/request/HttpRequestHandler.java. The manipulation leads to missing origin validation in websockets. The name of the patch is 620418df247aebda3dd4be1dda10fe229ea505dd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217716.
CWE-346 Jan 09, 2023
CVE-2017-20146 9.8 CRITICAL EPSS 0.00
Gorilla Handlers < 1.3.0 - CORS Header Bypass
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.
CWE-346 Dec 27, 2022
CVE-2022-42927 8.1 HIGH EPSS 0.00
Mozilla Firefox < 106.0 - Origin Validation Error
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
CWE-346 Dec 22, 2022
CVE-2022-38472 6.5 MEDIUM EPSS 0.00
Thunderbird <102.2-Firefox <104 - CSRF
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
CWE-346 Dec 22, 2022
CVE-2022-29915 4.3 MEDIUM EPSS 0.00
Mozilla Firefox < 100.0 - Origin Validation Error
The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.
CWE-346 Dec 22, 2022