CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
688 results Clear all
CVE-2023-39039 6.5 MEDIUM EPSS 0.00
Camp Style Project Line <13.6.1 - Info Disclosure
An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
CWE-668 Sep 18, 2023
CVE-2022-20917 4.3 MEDIUM EPSS 0.00
Cisco Jabber < 12.6.6 - Exposure to Wrong Actor
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper handling of nested XMPP messages within requests that are sent to the Cisco Jabber client software. An attacker could exploit this vulnerability by connecting to an XMPP messaging server and sending crafted XMPP messages to an affected Jabber client. A successful exploit could allow the attacker to manipulate the content of XMPP messages, possibly allowing the attacker to cause the Jabber client application to perform unsafe actions.
CWE-668 Sep 15, 2023
CVE-2023-38558 5.5 MEDIUM EPSS 0.00
SIMATIC PCS neo - Info Disclosure
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the Administration Console could get the credentials, and impersonate the admin user, thereby gaining admin access to other Windows systems.
CWE-538 Sep 14, 2023
CVE-2023-38152 5.3 MEDIUM EPSS 0.02
Microsoft Windows Server 2008 - Buffer Over-read
DHCP Server Service Information Disclosure Vulnerability
CWE-126 Sep 12, 2023
CVE-2023-24965 5.8 MEDIUM EPSS 0.00
IBM Aspera Faspex < 5.0.5 - Exposure to Wrong Actor
IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713.
CWE-668 Sep 08, 2023
CVE-2023-41745 5.5 MEDIUM EPSS 0.00
Acronis Agent < c22.11 - Information Disclosure
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30991, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
CWE-200 Aug 31, 2023
CVE-2023-41742 7.5 HIGH EPSS 0.00
Acronis Agent < c22.09 - Exposure to Wrong Actor
Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
CWE-1327 Aug 31, 2023
CVE-2023-34725 6.8 MEDIUM EPSS 0.00
Jaycar La5570 Firmware - Exposure to Wrong Actor
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via a telnet connection.
CWE-668 Aug 28, 2023
CVE-2023-4230 5.3 MEDIUM EPSS 0.00
ioLogik 4000 Series <v1.6 - Info Disclosure
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulnerability may enable attackers to gather information for the purpose of assessing vulnerabilities and potential attack vectors.
CWE-200 Aug 24, 2023
CVE-2023-39974 5.3 MEDIUM EPSS 0.00
Acymailing < 8.7.0 - Information Disclosure
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.
CWE-200 Aug 17, 2023
CVE-2023-39250 7.8 HIGH EPSS 0.00
Dell Replay Manager For Vmware < 3.1.2 - Information Disclosure
Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.
CWE-540 Aug 16, 2023
CVE-2023-2916 7.5 HIGH 1 PoC Analysis EPSS 0.30
Revmakx Infinitewp Client < 1.12.1 - Exposure to Wrong Actor
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.
CWE-668 Aug 15, 2023
CVE-2023-39383 7.5 HIGH EPSS 0.00
Huawei Emui - Information Disclosure
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
CWE-200 Aug 13, 2023
CVE-2023-38830 7.5 HIGH EPSS 0.00
PHPJabbers Yacht Listing Script <1.0 - Info Disclosure
An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.
CWE-668 Aug 10, 2023
CVE-2023-39214 7.6 HIGH EPSS 0.00
Zoom Client SDK <5.15.5 - Info Disclosure
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
CWE-749 Aug 08, 2023
CVE-2023-38955 7.5 HIGH EPSS 0.00
ZKTeco BioAccess IVS <3.3.1 - Info Disclosure
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
CWE-668 Aug 03, 2023
CVE-2023-33368 6.5 MEDIUM EPSS 0.00
Control ID IDSecure <4.7.26.0 - Info Disclosure
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
CWE-668 Aug 03, 2023
CVE-2023-3670 7.3 HIGH EPSS 0.00
Codesys Development System < 3.5.17.0 - Exposure to Wrong Actor
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
CWE-668 Jul 28, 2023
CVE-2023-39155 5.3 MEDIUM EPSS 0.00
Jenkins Chef Identity Plugin <2.0.3 - Info Disclosure
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.
CWE-668 Jul 26, 2023
CVE-2022-46901 7.5 HIGH EPSS 0.00
Vocera Report Server & Voice Server <5.8 - Info Disclosure
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and backing up, loading, and clearing of the database.
CWE-668 Jul 25, 2023