CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
56 results Clear all
CVE-2023-40332 5.3 MEDIUM EPSS 0.01
Lesterchan Wp-postratings < 1.91.1 - Authentication Bypass by Spoofing
Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.
CWE-799 Jun 04, 2024
CVE-2024-24873 5.3 MEDIUM EPSS 0.00
CodePeople CP Polls <1.0.71 - DoS
: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.
CWE-799 May 17, 2024
CVE-2024-34695 6.3 MEDIUM 1 Writeup EPSS 0.00
WOWS Karma <0.17.4.1 - Info Disclosure
WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the cooldown validation, however are not refreshing a user's metrics more than once, due to concurrent karma updates. This issue is fixed in 0.17.4.1.
CWE-799 May 14, 2024
CVE-2023-27279 6.5 MEDIUM EPSS 0.00
IBM Aspera Faspex <5.0.8 - DoS
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.
CWE-799 Apr 19, 2024
CVE-2023-35621 7.5 HIGH EPSS 0.01
Microsoft Dynamics 365 - Denial of Service
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
CWE-799 Dec 12, 2023
CVE-2023-38068 6.5 MEDIUM EPSS 0.00
JetBrains YouTrack <2023.1.16597 - Info Disclosure
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
CWE-799 Jul 12, 2023
CVE-2023-2758 3.7 LOW EPSS 0.00
Contec Conprosys Hmi System < 3.5.3 - Denial of Service
A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time.
CWE-799 May 31, 2023
CVE-2021-37910 3.7 LOW 1 PoC Analysis EPSS 0.03
ASUS routers - DoS
ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerability, an unauthenticated attacker can remotely disconnect other users' connections by sending specially crafted SAE authentication frames.
CWE-799 Nov 12, 2021
CVE-2021-41177 8.1 HIGH EPSS 0.01
Nextcloud <20.0.13, 21.0.5, 22.2.0 - Info Disclosure
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (as as `AnonRateThrottle` or `UserRateThrottle`) was thus not rate limited on instances not having a memory cache backend configured. In the case of a default installation, this would notably include the rate-limits on the two factor codes. It is recommended that the Nextcloud Server be upgraded to 20.0.13, 21.0.5, or 22.2.0. As a workaround, enable a memory cache backend in `config.php`.
CWE-799 Oct 25, 2021
CVE-2021-37191 4.3 MEDIUM EPSS 0.00
SINEMA Remote Connect Server <V3.0 SP2 - Info Disclosure
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software.
CWE-799 Sep 14, 2021
CVE-2021-32741 5.3 MEDIUM EPSS 0.00
Nextcloud Server <19.0.13, <20.011, <21.0.3 - Info Disclosure
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.
CWE-799 Jul 12, 2021
CVE-2021-32705 5.3 MEDIUM EPSS 0.01
Nextcloud Server <19.0.13, 20.011, 21.0.3 - Info Disclosure
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share tokens or credentials. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.
CWE-799 Jul 12, 2021
CVE-2021-32703 5.3 MEDIUM EPSS 0.01
Nextcloud Server <19.0.13, 20.011, 21.0.3 - Info Disclosure
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.
CWE-799 Jul 12, 2021
CVE-2021-32678 3.7 LOW EPSS 0.00
Nextcloud Server <19.0.13, 20.0.11, 21.0.3 - Info Disclosure
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`) using the `@BruteForceProtection` annotation. Risk depends on the installed applications on the Nextcloud Server, but could range from bypassing authentication ratelimits or spamming other Nextcloud users. The vulnerability is patched in versions 19.0.13, 20.0.11, and 21.0.3. No workarounds aside from upgrading are known to exist.
CWE-799 Jul 12, 2021
CVE-2020-5141 6.5 MEDIUM EPSS 0.00
SonicOS - Unauthenticated RCE
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0.
CWE-799 Oct 12, 2020
CVE-2016-6543 5.9 MEDIUM EPSS 0.01
iTrack Easy - Info Disclosure
A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.
CWE-799 Jul 13, 2018