CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,281 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,573 researchers
2,435 results Clear all
CVE-2023-0669 7.2 HIGH KEV RANSOMWARE 8 PoCs Analysis NUCLEI EPSS 0.94
Fortra GoAnywhere MFT Unsafe Deserialization RCE
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
CWE-502 Feb 06, 2023
CVE-2023-25135 9.8 CRITICAL EXPLOITED 1 PoC Analysis NUCLEI EPSS 0.93
Vbulletin - Insecure Deserialization
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors. The fixed versions are 5.6.7 PL1, 5.6.8 PL1, and 5.6.9 PL1.
CWE-502 Feb 03, 2023
CVE-2023-24997 9.8 CRITICAL EPSS 0.01
Apache Inlong < 1.5.0 - Insecure Deserialization
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223 https://github.com/apache/inlong/pull/7223  to solve it.
CWE-502 Feb 01, 2023
CVE-2023-24162 9.8 CRITICAL EPSS 0.01
Dromara Hutool <5.8.11 - Code Injection
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
CWE-502 Jan 31, 2023
CVE-2022-44645 8.8 HIGH EPSS 0.04
Apache Linkis < 1.3.0 - Insecure Deserialization
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and malicious parameters. Therefore, the parameters in the jdbc url should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users to upgrade the version of Linkis to version 1.3.1.
CWE-502 Jan 31, 2023
CVE-2022-32521 7.1 HIGH EPSS 0.01
Schneider-electric Data Center Expert - Insecure Deserialization
A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server. Affected Products: Data Center Expert (Versions prior to V7.9.0)
CWE-502 Jan 30, 2023
CVE-2022-31710 7.5 HIGH EPSS 0.01
Vmware Vrealize Log Insight < 4.8 - Insecure Deserialization
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.
CWE-502 Jan 26, 2023
CVE-2022-45923 8.8 HIGH EPSS 0.03
Opentext Extended Ecm < 22.4 - Insecure Deserialization
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker to increase/decrease an arbitrary memory address by 1 and trigger a call to a method of a vftable with a vftable pointer value chosen by the attacker.
CWE-502 Jan 18, 2023
CVE-2023-21839 7.5 HIGH KEV 8 PoCs Analysis NUCLEI EPSS 0.94
Oracle WebLogic Server <14.1.1.0.0 - RCE
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CWE-502 Jan 18, 2023
CVE-2022-4890 6.3 MEDIUM 1 Writeup EPSS 0.01
abhilash1985 PredictApp - Deserialization
A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The patch is named b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.
CWE-502 Jan 16, 2023
CVE-2023-22850 8.8 HIGH EPSS 0.01
Tiki < 24.1 - Insecure Deserialization
Tiki before 24.1, when the Spreadsheets feature is enabled, allows lib/sheet/grid.php PHP Object Injection because of an unserialize call.
CWE-502 Jan 14, 2023
CVE-2022-46478 9.8 CRITICAL EPSS 0.01
datax-web <2.1.2 - Command Injection
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.
CWE-502 Jan 13, 2023
CVE-2022-41778 9.8 CRITICAL EPSS 0.00
Delta Electronics InfraSuite Device Master <00.00.01a - Code Injection
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.
CWE-502 Jan 13, 2023
CVE-2023-21779 7.8 HIGH EPSS 0.01
Visual Studio Code - RCE
Visual Studio Code Remote Code Execution Vulnerability
CWE-502 Jan 10, 2023
CVE-2023-21762 8.0 HIGH EPSS 0.00
Microsoft Exchange Server - SSRF
Microsoft Exchange Server Spoofing Vulnerability
CWE-502 Jan 10, 2023
CVE-2023-21745 8.0 HIGH EPSS 0.00
Microsoft Exchange Server - SSRF
Microsoft Exchange Server Spoofing Vulnerability
CWE-502 Jan 10, 2023
CVE-2023-21744 8.8 HIGH EPSS 0.29
Microsoft SharePoint Server - RCE
Microsoft SharePoint Server Remote Code Execution Vulnerability
CWE-502 Jan 10, 2023
CVE-2023-21538 7.5 HIGH EPSS 0.01
.NET - DoS
.NET Denial of Service Vulnerability
CWE-502 Jan 10, 2023
CVE-2022-47083 8.8 HIGH EPSS 0.01
Spitfire CMS <1.0.475 - Code Injection
A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application.
CWE-502 Jan 10, 2023
CVE-2021-32828 5.4 MEDIUM 1 Writeup EPSS 0.00
Nuxeo Platform <11.5.109 - XSS
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API.
CWE-502 Jan 05, 2023