CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,867 CVEs tracked 53,243 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,925 Nuclei templates 37,802 vendors 42,500 researchers
441 results Clear all
CVE-2020-0647 5.4 MEDIUM EPSS 0.01
Microsoft Office Online Server - Origin Validation Error
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'.
CWE-346 Jan 14, 2020
CVE-2019-11762 6.1 MEDIUM EPSS 0.00
Firefox <70, Thunderbird <68.2, Firefox ESR <68.2 - CSRF
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
CWE-346 Jan 08, 2020
CVE-2019-20329 8.1 HIGH 1 Writeup EPSS 0.00
Openlambda - Origin Validation Error
OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000.
CWE-346 Jan 03, 2020
CVE-2019-5062 6.5 MEDIUM EPSS 0.00
Hostapd 2.6 - DoS
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of service.
CWE-346 Dec 12, 2019
CVE-2019-13740 6.5 MEDIUM EPSS 0.01
Google Chrome <79.0.3945.79 - CSRF
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CWE-346 Dec 10, 2019
CVE-2019-19545 6.3 MEDIUM EPSS 0.00
Norton Password Manager <6.6.2.5 - CSRF
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.
CWE-346 Dec 05, 2019
CVE-2019-18381 6.3 MEDIUM EPSS 0.00
Norton Password Manager < 6.6.2.5 - Origin Validation Error
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.
CWE-346 Dec 05, 2019
CVE-2019-19019 7.5 HIGH EPSS 0.01
TitanHQ WebTitan <5.18 - RCE
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which downloads a shell script via HTTP, and then executes it as root. This is analogous to CVE-2019-6800 but for a different product.
CWE-346 Dec 02, 2019
CVE-2019-5227 5.5 MEDIUM EPSS 0.00
Huawei P30/P30 Pro/Mate 20 < ELLE-AL00B 9.1.0.193(C00E190R2P1) - Ve...
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.
CWE-346 Nov 29, 2019
CVE-2019-5226 5.5 MEDIUM EPSS 0.00
Huawei P30/P30 Pro/Mate 20 < ELLE-AL00B 9.1.0.193(C00E190R2P1) - Ve...
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.
CWE-346 Nov 29, 2019
CVE-2019-13664 6.5 MEDIUM EPSS 0.00
Google Chrome <77.0.3865.75 - CSRF
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CWE-346 Nov 25, 2019
CVE-2019-1447 5.4 MEDIUM EPSS 0.01
Microsoft Office Online Server - Origin Validation Error
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445.
CWE-346 Nov 12, 2019
CVE-2019-1445 5.4 MEDIUM EPSS 0.01
Microsoft Office Online Server - Origin Validation Error
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447.
CWE-346 Nov 12, 2019
CVE-2019-1442 5.5 MEDIUM EPSS 0.07
Microsoft Sharepoint Server - Origin Validation Error
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
CWE-346 Nov 12, 2019
CVE-2019-1413 4.3 MEDIUM EPSS 0.02
Microsoft Edge - Origin Validation Error
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
CWE-346 Nov 12, 2019
CVE-2019-15020 9.8 CRITICAL EPSS 0.02
Zingbox Inspector < 1.293 - Origin Validation Error
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.
CWE-346 Oct 09, 2019
CVE-2019-3980 9.8 CRITICAL EXPLOITED 4 PoCs Analysis EPSS 0.41
Solarwinds Dameware Mini Remote Control - Origin Validation Error
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.
CWE-346 Oct 08, 2019
CVE-2019-16275 6.5 MEDIUM EPSS 0.01
hostapd <2.10, wpa_supplicant <2.10 - DoS
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.
CWE-346 Sep 12, 2019
CVE-2019-8069 9.8 CRITICAL EPSS 0.03
Adobe Flash Player Desktop Runtime - Origin Validation Error
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
CWE-346 Sep 12, 2019
CVE-2019-1235 7.8 HIGH EPSS 0.00
Microsoft Windows 10 - Origin Validation Error
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
CWE-346 Sep 11, 2019