CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
441 results Clear all
CVE-2017-5593 5.9 MEDIUM EPSS 0.00
Psi-plus Psi+ - Origin Validation Error
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Psi+ (0.16.563.580 - 0.16.571.627).
CWE-346 Feb 09, 2017
CVE-2017-5592 5.9 MEDIUM 1 Writeup EPSS 0.00
Profanity - Origin Validation Error
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for profanity (0.4.7 - 0.5.0).
CWE-346 Feb 09, 2017
CVE-2017-5591 5.9 MEDIUM 1 Writeup EPSS 0.00
Sleekxmpp < 1.3.1 - Origin Validation Error
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.
CWE-346 Feb 09, 2017
CVE-2017-5590 5.9 MEDIUM 2 Writeups EPSS 0.00
Chatsecure < 1.0.11 - Origin Validation Error
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for ChatSecure (3.2.0 - 4.0.0; only iOS) and Zom (all versions up to 1.0.11; only iOS).
CWE-346 Feb 09, 2017
CVE-2017-5589 5.9 MEDIUM 1 Writeup EPSS 0.00
Yaxim Bruno - Origin Validation Error
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for yaxim and Bruno (0.8.6 - 0.8.8; Android).
CWE-346 Feb 09, 2017
CVE-2015-4495 8.8 HIGH KEV 3 PoCs Analysis EPSS 0.72
Mozilla Firefox < 39.0.3 - Origin Validation Error
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
CWE-346 Aug 08, 2015
CVE-2014-1502 EPSS 0.00
Opensuse < 28.0 - Origin Validation Error
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.
CWE-346 Mar 19, 2014
CVE-2014-1487 7.5 HIGH EPSS 0.01
Mozilla Firefox < 27.0 - Origin Validation Error
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
CWE-346 Feb 06, 2014
CVE-2012-4193 EPSS 0.01
Mozilla Firefox < 16.0.1 - Origin Validation Error
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.
CWE-346 Oct 12, 2012
CVE-2011-3072 EPSS 0.00
Google Chrome < 18.0.1025.151 - Origin Validation Error
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows.
CWE-346 Apr 05, 2012
CVE-2011-3067 EPSS 0.01
Google Chrome < 18.0.1025.151 - Origin Validation Error
Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements.
CWE-346 Apr 05, 2012
CVE-2011-3056 EPSS 0.01
Google Chrome < 17.0.963.83 - Origin Validation Error
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
CWE-346 Mar 22, 2012
CVE-2011-3956 EPSS 0.00
Google Chrome <17.0.963.46 - CSRF
The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.
CWE-346 Feb 09, 2012
CVE-2011-2856 EPSS 0.00
Google Chrome < 14.0.835.163 - Origin Validation Error
Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
CWE-346 Sep 19, 2011
CVE-2009-1185 4 PoCs Analysis EPSS 0.90
Udev < 141 - Origin Validation Error
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
CWE-346 Apr 17, 2009
CVE-2005-0877 7.5 HIGH EPSS 0.00
Thekelleys Dnsmasq < 2.21 - Origin Validation Error
Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.
CWE-346 May 02, 2005
CVE-2003-0981 6.1 MEDIUM EPSS 0.00
Freescripts Visitorbook LE - Origin Validation Error
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks.
CWE-346 Jan 05, 2004
CVE-2003-0174 9.8 CRITICAL EPSS 0.00
SGI Irix < 6.5.19 - Origin Validation Error
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
CWE-346 May 12, 2003
CVE-2001-1452 7.5 HIGH EPSS 0.04
Windows NT 4.0/2000 - Info Disclosure
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
CWE-346 Aug 31, 2001
CVE-2000-1218 9.8 CRITICAL EPSS 0.02
Microsoft Windows - Info Disclosure
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
CWE-346 Apr 14, 2000