CVE & Exploit Intelligence Database
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
2,435 results
Clear all
CVE-2018-1000824
9.8
CRITICAL
EPSS 0.02
MegaMek < 0.45.1 - Remote Code Execution
CWE-502
Dec 20, 2018
CVE-2018-20148
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.55
WordPress <4.9.9, 5.x <5.0.1 - Code Injection
CWE-502
Dec 14, 2018
CVE-2018-1904
8.1
HIGH
EPSS 0.01
IBM WebSphere Application Server <9.0 - RCE
CWE-502
Dec 11, 2018
CVE-2018-1000861
9.8
CRITICAL
KEV
RANSOMWARE
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Jenkins <2.153 - RCE
CWE-502
Dec 10, 2018
CVE-2018-16476
7.5
HIGH
EPSS 0.01
Rails < 4.2.11 - Improper Access Control
CWE-284
Nov 30, 2018
CVE-2018-18987
8.8
HIGH
EPSS 0.01
Invt Vt-designer - Insecure Deserialization
CWE-502
Nov 30, 2018
CVE-2018-19499
7.2
HIGH
EPSS 0.02
Vanilla <2.5.5, <2.6 - RCE
CWE-502
Nov 23, 2018
CVE-2018-19396
7.5
HIGH
EPSS 0.02
PHP <7.1.24 - DoS
CWE-502
Nov 20, 2018
CVE-2018-19274
7.2
HIGH
EPSS 0.14
phpBB <3.2.4 - RCE
CWE-502
Nov 17, 2018
CVE-2018-19296
8.8
HIGH
EPSS 0.01
PHPMailer <5.2.27, <6.0.6 - Code Injection
CWE-502
Nov 16, 2018
CVE-2018-15381
9.8
CRITICAL
EPSS 0.28
Cisco Unity Express - Use After Free
CWE-502
Nov 08, 2018
CVE-2018-8021
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.70
Superset <0.23 - Code Injection
CWE-502
Nov 07, 2018
CVE-2018-1851
7.3
HIGH
EPSS 0.04
IBM Websphere Application Server < 18.0.0.3 - Insecure Deserialization
CWE-502
Oct 31, 2018
CVE-2018-15686
7.8
HIGH
2 PoCs
Analysis
EPSS 0.02
Canonical Ubuntu Linux < 239 - Insecure Deserialization
CWE-502
Oct 26, 2018
CVE-2018-18013
7.8
HIGH
EPSS 0.00
Citrix Xenmobile Server < 10.8.0 - Insecure Deserialization
CWE-502
Oct 24, 2018
CVE-2018-18628
9.8
CRITICAL
EPSS 0.04
Pippo < 1.12.0 - Insecure Deserialization
CWE-502
Oct 23, 2018
CVE-2018-18589
6.3
MEDIUM
EPSS 0.01
Microfocus Real User Monitoring - Insecure Deserialization
CWE-502
Oct 23, 2018
CVE-2018-15616
9.0
CRITICAL
EPSS 0.04
Avaya Aura System Platform < 6.3.9 - Insecure Deserialization
CWE-502
Oct 17, 2018
CVE-2018-3245
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.90
Oracle WebLogic Server <12.2.1.3 - RCE
CWE-502
Oct 17, 2018
CVE-2018-18240
9.8
CRITICAL
EPSS 0.03
Pippo < 1.11.0 - Insecure Deserialization
CWE-502
Oct 11, 2018