CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
688 results Clear all
CVE-2023-1402 4.3 MEDIUM EPSS 0.00
Moodle - Information Disclosure via Course Participation Report
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
CWE-200 Mar 23, 2023
CVE-2023-28433 8.8 HIGH 1 Writeup EPSS 0.00
Minio <RELEASE.2023-03-20T20-16-18Z - Privilege Escalation
Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds.
CWE-668 Mar 22, 2023
CVE-2023-1562 3.5 LOW EPSS 0.00
Mattermost - Info Disclosure
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
CWE-200 Mar 22, 2023
CVE-2020-22647 9.1 CRITICAL 1 Writeup EPSS 0.00
DepositGame 1.0 - Info Disclosure
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.
CWE-668 Mar 16, 2023
CVE-2023-24906 6.5 MEDIUM EPSS 0.02
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CWE-190 Mar 14, 2023
CVE-2023-24870 6.5 MEDIUM EPSS 0.02
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CWE-126 Mar 14, 2023
CVE-2023-24866 6.5 MEDIUM EPSS 0.02
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CWE-20 Mar 14, 2023
CVE-2023-24863 6.5 MEDIUM EPSS 0.02
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CWE-190 Mar 14, 2023
CVE-2023-23409 5.5 MEDIUM EPSS 0.01
Microsoft Windows 10 1507 < 10.0.10240.19805 - Exposure to Wrong Actor
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
CWE-20 Mar 14, 2023
CVE-2023-23394 5.5 MEDIUM EPSS 0.01
Microsoft Windows 10 1507 < 10.0.10240.19805 - Information Disclosure
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
CWE-822 Mar 14, 2023
CVE-2023-25802 7.5 HIGH 1 Writeup EPSS 0.01
Roxy-wi < 6.3.6.0 - Path Traversal
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information about a server. Version 6.3.6.0 has a patch for this issue.
CWE-22 Mar 13, 2023
CVE-2023-22892 7.5 HIGH EPSS 0.00
Smartbear Zephyr Enterprise < 7.15 - Exposure to Wrong Actor
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
CWE-668 Mar 08, 2023
CVE-2022-46257 4.3 MEDIUM EPSS 0.00
GitHub Enterprise Server - Info Disclosure
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the repository names being shown in the UI. To exploit this vulnerability, an attacker would need access to the GHES instance, permissions to modify GitHub Actions runner groups, and successfully guess the obfuscated ID of private repositories. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7 and was fixed in versions 3.3.17, 3.4.12, 3.5.9, 3.6.5. This vulnerability was reported via the GitHub Bug Bounty program.
CWE-200 Mar 07, 2023
CVE-2023-20061 6.5 MEDIUM EPSS 0.01
Cisco Unified Intelligence Center - SSRF
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.
CWE-200 Mar 03, 2023
CVE-2023-25536 6.7 MEDIUM EPSS 0.00
Dell Powerscale Onefs < 9.4.0.11 - Information Disclosure
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover.
CWE-200 Mar 02, 2023
CVE-2023-25544 7.5 HIGH EPSS 0.00
Dell Emc Networker < 19.6 - Information Disclosure
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.
CWE-200 Mar 01, 2023
CVE-2023-24567 7.5 HIGH EPSS 0.00
Dell NetWorker <19.5 - Info Disclosure
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.
CWE-200 Mar 01, 2023
CVE-2023-22777 4.9 MEDIUM EPSS 0.00
Arubanetworks Sd-wan < 8.7.0.0-2.3.0.8 - Exposure to Wrong Actor
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.
CWE-668 Mar 01, 2023
CVE-2023-22775 6.5 MEDIUM EPSS 0.00
Arubanetworks Sd-wan < 8.7.0.0-2.3.0.8 - Exposure to Wrong Actor
A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
CWE-668 Mar 01, 2023
CVE-2023-26041 2.6 LOW EPSS 0.00
Nextcloud Talk <15.0.3 - Info Disclosure
Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. It is recommended that the Nextcloud Talk is upgraded to 15.0.3. There are no workaround available.
CWE-359 Feb 27, 2023