CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
557 results Clear all
CVE-2021-1356 4.3 MEDIUM EPSS 0.00
Cisco Ios XE - Improper Exception Handling
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient error handling in the web UI. An attacker could exploit these vulnerabilities by sending crafted HTTP packets to an affected device. A successful exploit could allow the attacker to cause the web UI software to become unresponsive and consume all available vty lines, preventing new session establishment and resulting in a DoS condition. Manual intervention would be required to regain web UI and vty session functionality. Note: These vulnerabilities do not affect the console connection.
CWE-755 Mar 24, 2021
CVE-2021-28971 5.5 MEDIUM EPSS 0.00
Linux Kernel < 5.11.8 - Improper Exception Handling
In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.
CWE-755 Mar 22, 2021
CVE-2021-28831 7.5 HIGH EPSS 0.01
Busybox < 1.32.1 - Improper Exception Handling
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
CWE-755 Mar 19, 2021
CVE-2021-3127 7.5 HIGH EPSS 0.00
Nats Jwt Library < 2.0.1 - Improper Exception Handling
NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.
CWE-755 Mar 16, 2021
CVE-2020-25236 5.5 MEDIUM EPSS 0.00
Siemens Logo! 8 BM Firmware - Improper Exception Handling
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA1) (All versions), LOGO! 24CEo (6ED1052-2CC08-0BA1) (All versions), LOGO! 24RCE (6ED1052-1HB08-0BA1) (All versions), LOGO! 24RCEo (6ED1052-2HB08-0BA1) (All versions), SIPLUS LOGO! 12/24RCE (6AG1052-1MD08-7BA1) (All versions), SIPLUS LOGO! 12/24RCEo (6AG1052-2MD08-7BA1) (All versions), SIPLUS LOGO! 230RCE (6AG1052-1FB08-7BA1) (All versions), SIPLUS LOGO! 230RCEo (6AG1052-2FB08-7BA1) (All versions), SIPLUS LOGO! 24CE (6AG1052-1CC08-7BA1) (All versions), SIPLUS LOGO! 24CEo (6AG1052-2CC08-7BA1) (All versions), SIPLUS LOGO! 24RCE (6AG1052-1HB08-7BA1) (All versions), SIPLUS LOGO! 24RCEo (6AG1052-2HB08-7BA1) (All versions). The control logic (CL) the LOGO! 8 executes could be manipulated in a way that could cause the device executing the CL to improperly handle the manipulation and crash. After successful execution of the attack, the device needs to be manually reset.
CWE-755 Mar 15, 2021
CVE-2020-27543 7.5 HIGH 2 Writeups EPSS 0.02
restify-paginate 0.0.5 - DoS
The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP Host header. A Restify-based web service would crash with an uncaught exception.
CWE-755 Feb 25, 2021
CVE-2020-26195 5.3 MEDIUM EPSS 0.01
Dell Emc Powerscale Onefs - Improper Exception Handling
Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directory for a user. A remote unauthenticated attacker may take advantage of this issue to slow down the system.
CWE-755 Feb 09, 2021
CVE-2020-13859 9.8 CRITICAL EPSS 0.00
Mofinetwork Mofi4500-4gxelte Firmware - Improper Exception Handling
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to the cgi-bin/luci/quick/wizard management interface without a password by abusing a forgotten-password feature.
CWE-755 Feb 01, 2021
CVE-2020-5807 7.5 HIGH EPSS 0.01
FactoryTalk Diagnostics <6.11 - Info Disclosure
An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer (FTDiagViewer.exe) to view the log entry. Observed in FactoryTalk Diagnostics 6.11. All versions of FactoryTalk Diagnostics are affected.
CWE-755 Dec 29, 2020
CVE-2020-5801 7.5 HIGH EPSS 0.00
FactoryTalk Linx - Process Termination
An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
CWE-755 Dec 29, 2020
CVE-2020-2505 2.3 LOW EPSS 0.00
Qnap Qes < 2.1.1 - Error Information Exposure
If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
CWE-755 Dec 24, 2020
CVE-2020-14270 5.3 MEDIUM EPSS 0.00
Hcltech Domino < 10.0.0 - Improper Exception Handling
HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages software running on the Domino server.
CWE-755 Dec 22, 2020
CVE-2020-2020 5.5 MEDIUM EPSS 0.00
Paloaltonetworks Cortex Xdr Agent - Improper Exception Handling
An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the software's internal program directory that prevents the Cortex XDR Agent from starting. The exceptional condition is persistent and prevents Cortex XDR Agent from starting when the software or machine is restarted. This issue impacts: Cortex XDR Agent 5.0 versions earlier than 5.0.10; Cortex XDR Agent 6.1 versions earlier than 6.1.7; Cortex XDR Agent 7.0 versions earlier than 7.0.3; Cortex XDR Agent 7.1 versions earlier than 7.1.2.
CWE-755 Dec 09, 2020
CVE-2020-29561 5.5 MEDIUM EPSS 0.00
SonicBOOM riscv-boom <3.0.0 - Use After Free
An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case where a load translates successfully but still generates an exception.
CWE-755 Dec 04, 2020
CVE-2020-28896 5.3 MEDIUM 1 Writeup EPSS 0.00
Mutt < 2.0.2 - Improper Exception Handling
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.
CWE-755 Nov 23, 2020
CVE-2020-7926 6.5 MEDIUM EPSS 0.00
MongoDB Server <4.4.1 - DoS
A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem. This issue affects MongoDB Server v4.4 versions prior to 4.4.1. Versions before 4.4 are not affected.
CWE-755 Nov 23, 2020
CVE-2020-8767 5.5 MEDIUM EPSS 0.00
Intel(R) 50GbE IP Core <20.2 - DoS
Uncaught exception in the Intel(R) 50GbE IP Core for Intel(R) Quartus Prime before version 20.2 may allow an authenticated user to potentially enable denial of service via local access.
CWE-755 Nov 12, 2020
CVE-2020-0443 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Google Android - Improper Exception Handling
In LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. This could lead to local denial of service requiring factory reset to restore with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-152410253
CWE-755 Nov 10, 2020
CVE-2020-27121 4.3 MEDIUM EPSS 0.01
Cisco Unified Communications Manager IM & Presence Service - DoS
A vulnerability in Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) Software could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Service on an affected device to restart, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of login requests. An attacker could exploit this vulnerability by sending a crafted client login request to an affected device. A successful exploit could allow the attacker to cause a process to crash, resulting in a DoS condition for new login attempts. Users who are authenticated at the time of the attack would not be affected. There are workarounds that address this vulnerability.
CWE-755 Nov 06, 2020
CVE-2020-16005 8.8 HIGH EPSS 0.01
Google Chrome < 86.0.4240.183 - Out-of-Bounds Write
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-755 Nov 03, 2020