CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
403 results Clear all
CVE-2024-30041 5.4 MEDIUM EPSS 0.02
Microsoft Bing < - Open Redirect
Microsoft Bing Search Spoofing Vulnerability
CWE-693 May 14, 2024
CVE-2024-34144 9.8 CRITICAL 1 PoC Analysis EPSS 0.50
Jenkins Script Security Plugin <1335.vf07d9ce377a_e - Privilege Esc...
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
CWE-693 May 02, 2024
CVE-2024-33903 5.9 MEDIUM 1 Writeup EPSS 0.00
CARLA <0.9.15.2 - Info Disclosure
In CARLA through 0.9.15.2, the collision sensor mishandles some situations involving pedestrians or bicycles, in part because the collision sensor function is not exposed to the Blueprint library.
CWE-693 Apr 29, 2024
CVE-2024-33883 4.0 MEDIUM 1 PoC Analysis EPSS 0.01
ejs <3.1.10 - XSS
The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
CWE-693 Apr 28, 2024
CVE-2022-48611 7.8 HIGH EPSS 0.00
iTunes <12.12.4 - Privilege Escalation
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate their privileges.
CWE-693 Apr 26, 2024
CVE-2024-29988 8.8 HIGH KEV 1 PoC Analysis EPSS 0.67
SmartScreen Prompt - Privilege Escalation
SmartScreen Prompt Security Feature Bypass Vulnerability
CWE-693 Apr 09, 2024
CVE-2024-28921 6.7 MEDIUM EPSS 0.00
Secure Boot - Privilege Escalation
Secure Boot Security Feature Bypass Vulnerability
CWE-693 Apr 09, 2024
CVE-2024-28920 7.8 HIGH EPSS 0.00
Secure Boot - Privilege Escalation
Secure Boot Security Feature Bypass Vulnerability
CWE-693 Apr 09, 2024
CVE-2024-28919 6.7 MEDIUM EPSS 0.00
Secure Boot - Privilege Escalation
Secure Boot Security Feature Bypass Vulnerability
CWE-693 Apr 09, 2024
CVE-2024-28903 6.7 MEDIUM EPSS 0.00
Secure Boot - Privilege Escalation
Secure Boot Security Feature Bypass Vulnerability
CWE-693 Apr 09, 2024
CVE-2024-26250 6.7 MEDIUM EPSS 0.00
Secure Boot - Privilege Escalation
Secure Boot Security Feature Bypass Vulnerability
CWE-693 Apr 09, 2024
CVE-2024-20669 6.7 MEDIUM EPSS 0.00
Secure Boot - Privilege Escalation
Secure Boot Security Feature Bypass Vulnerability
CWE-693 Apr 09, 2024
CVE-2024-20665 6.1 MEDIUM EPSS 0.01
Microsoft Windows BitLocker - Security Feature Bypass
BitLocker Security Feature Bypass Vulnerability
CWE-693 Apr 09, 2024
CVE-2024-30370 4.3 MEDIUM EPSS 0.00
RARLAB WinRAR - Code Injection
RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must perform a specific action on a malicious page. The specific flaw exists within the archive extraction functionality. A crafted archive entry can cause the creation of an arbitrary file without the Mark-Of-The-Web. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current user. Was ZDI-CAN-23156.
CWE-693 Apr 02, 2024
CVE-2024-28248 7.2 HIGH EPSS 0.01
Cilium <1.13.9, <1.14.8, <1.15.2 - Info Disclosure
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 and prior to versions 1.13.13, 1.14.8, and 1.15.2, Cilium's HTTP policies are not consistently applied to all traffic in the scope of the policies, leading to HTTP traffic being incorrectly and intermittently forwarded when it should be dropped. This issue has been patched in Cilium 1.15.2, 1.14.8, and 1.13.13. There are no known workarounds for this issue.
CWE-693 Mar 18, 2024
CVE-2024-26163 4.7 MEDIUM EPSS 0.01
Microsoft Edge < - SSRF
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CWE-693 Mar 14, 2024
CVE-2024-24562 5.4 MEDIUM 1 Writeup EPSS 0.00
vantage6-UI - Info Disclosure
vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa6614` which is expected to be included in future releases. Users are advised to upgrade when a new release is made. While an upgrade path is not available users may modify the docker image build to insert the headers into nginx.
CWE-693 Mar 14, 2024
CVE-2023-42938 7.8 HIGH EPSS 0.00
iTunes <12.13.1 - Privilege Escalation
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.
CWE-693 Mar 14, 2024
CVE-2023-39368 6.5 MEDIUM EPSS 0.00
Intel(R) Processors - DoS
Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.
CWE-693 Mar 14, 2024
CVE-2023-22655 6.1 MEDIUM EPSS 0.00
Intel Xeon Processors - Privilege Escalation
Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
CWE-693 Mar 14, 2024