CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,555 researchers
557 results Clear all
CVE-2018-21088 7.5 HIGH EPSS 0.00
Google Android - Improper Exception Handling
An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can cause a reboot because InputMethodManagerService has an unprotected system service. The Samsung ID is SVE-2017-9995 (January 2018).
CWE-755 Apr 08, 2020
CVE-2018-21091 7.5 HIGH EPSS 0.00
Google Android - Improper Exception Handling
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. Telecom has a System Crash via abnormal exception handling. The Samsung ID is SVE-2017-10906 (January 2018).
CWE-755 Apr 08, 2020
CVE-2017-18682 7.5 HIGH EPSS 0.00
Samsung KK-LN - System Crash
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Because of incorrect exception handling and an unprotected intent, AudioService can cause a system crash, The Samsung IDs are SVE-2017-8114, SVE-2017-8116, and SVE-2017-8117 (March 2017).
CWE-755 Apr 07, 2020
CVE-2017-18678 7.5 HIGH EPSS 0.00
Samsung KK-LN - Use After Free
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. An attacker can crash system processes via a Serializable object because of missing exception handling. The Samsung IDs are SVE-2017-8109, SVE-2017-8110, SVE-2017-8115, SVE-2017-8118, and SVE-2017-8119 (April 2017).
CWE-755 Apr 07, 2020
CVE-2017-18672 5.5 MEDIUM EPSS 0.00
Samsung mobile devices <5.1 - DoS
An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.x) software. Because of incorrect exception handling for Intents, a local attacker can force a reboot within framework.jar. The Samsung ID is SVE-2017-8390 (May 2017).
CWE-755 Apr 07, 2020
CVE-2017-18671 7.5 HIGH EPSS 0.00
Samsung mobile devices <5.1 - DoS
An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.x) software. Intents related to Wi-Fi have incorrect exception handling, leading to a crash of system processes. The Samsung ID is SVE-2017-8389 (May 2017).
CWE-755 Apr 07, 2020
CVE-2017-18670 7.5 HIGH EPSS 0.00
Samsung KK-LM - RCE
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. android.intent.action.SIOP_LEVEL_CHANGED allows a serializable intent reboot. The Samsung ID is SVE-2017-8363 (May 2017).
CWE-755 Apr 07, 2020
CVE-2017-18663 7.5 HIGH EPSS 0.00
Samsung N(7.x) - Info Disclosure
An issue was discovered on Samsung mobile devices with N(7.x) software. Because of missing Intent exception handling, system_server can have a NullPointerException with a crash of a system process. The Samsung IDs are SVE-2017-9122, SVE-2017-9123, SVE-2017-9124, and SVE-2017-9126 (July 2017).
CWE-755 Apr 07, 2020
CVE-2017-18659 5.3 MEDIUM EPSS 0.00
Samsung KK-LN - DoS
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can crash system processes via a broadcast to AdaptiveDisplayColorService. The Samsung ID is SVE-2017-8290 (July 2017).
CWE-755 Apr 07, 2020
CVE-2016-11034 6.5 MEDIUM EPSS 0.00
Google Android - Improper Exception Handling
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).
CWE-755 Apr 07, 2020
CVE-2016-11026 7.5 HIGH EPSS 0.00
Google Android - Improper Exception Handling
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. BootReceiver allows attackers to trigger a system crash because of incorrect exception handling. The Samsung ID is SVE-2016-7118 (December 2016).
CWE-755 Apr 07, 2020
CVE-2020-1744 5.6 MEDIUM EPSS 0.00
Keycloak <9.0.1 - Info Disclosure
A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.
CWE-755 Mar 24, 2020
CVE-2020-0511 5.5 MEDIUM EPSS 0.00
Intel Graphics Driver < 15.40.44.5107 - Improper Exception Handling
Uncaught exception in system driver for Intel(R) Graphics Drivers before version 15.40.44.5107 may allow an authenticated user to potentially enable a denial of service via local access.
CWE-755 Mar 12, 2020
CVE-2020-10101 7.5 HIGH EPSS 0.01
Zammad < 3.2.0 - Improper Exception Handling
An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message format is not properly checked and parsing errors not handled. This leads to a crash of the service process.
CWE-755 Mar 05, 2020
CVE-2020-5403 7.5 HIGH EPSS 0.00
Pivotal Reactor Netty < 0.9.5 - Improper Exception Handling
Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of producing a 400 response.
CWE-755 Mar 03, 2020
CVE-2019-16302 7.5 HIGH EPSS 0.01
ONOS 1.14 - Info Disclosure
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the Ethernet VPN application (org.onosproject.evpnopenflow), the host event listener does not handle the following event types: HOST_MOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of intended code execution.
CWE-755 Feb 20, 2020
CVE-2019-16301 7.5 HIGH EPSS 0.01
Open Network Operating System <1.14 - Privilege Escalation
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual tenant network application (org.onosproject.vtn), the host event listener does not handle the following event types: HOST_MOVED. In combination with other applications, this could lead to the absence of intended code execution.
CWE-755 Feb 20, 2020
CVE-2019-16300 7.5 HIGH EPSS 0.01
Open Network Operating System <1.14 - Privilege Escalation
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the access control application (org.onosproject.acl), the host event listener does not handle the following event types: HOST_REMOVED. In combination with other applications, this could lead to the absence of intended code execution.
CWE-755 Feb 20, 2020
CVE-2019-16299 7.5 HIGH EPSS 0.01
ONOS 1.14 - Info Disclosure
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the mobility application (org.onosproject.mobility), the host event listener does not handle the following event types: HOST_ADDED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of intended code execution.
CWE-755 Feb 20, 2020
CVE-2019-16298 7.5 HIGH EPSS 0.01
ONOS 1.14 - Info Disclosure
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual broadband network gateway application (org.onosproject.virtualbng), the host event listener does not handle the following event types: HOST_MOVED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of intended code execution.
CWE-755 Feb 20, 2020