CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
32 results Clear all
CVE-2007-3715 EPSS 0.01
SUN Java System Application Server - Improper Input Validation
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.
CWE-20 Jul 11, 2007
CVE-2007-1526 EPSS 0.00
Sun Java System Web Server 6.1 <20070314 - Auth Bypass
Sun Java System Web Server 6.1 before 20070314 allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization control and access secure web server instances running under an account different from that used for the admin server via unspecified vectors.
Mar 20, 2007
CVE-2007-1488 EPSS 0.01
Sun Java System Web Server <20070315 - Info Disclosure
Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.
Mar 16, 2007
CVE-2006-6276 EPSS 0.01
Sun Java System Proxy Server <20061130 - SSRF/XSS
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.
CWE-444 Dec 04, 2006
CVE-2006-5654 EPSS 0.01
SUN Java System Web Server < 7.0 - Denial of Service
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.
Nov 03, 2006
CVE-2006-3921 EPSS 0.01
Sun Java System Application Server <9 - Info Disclosure
Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI.
Jul 28, 2006
CVE-2006-2501 EPSS 0.06
SUN Java System Application Server < 7.0 - XSS
Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and earlier, and Java System Application Server 7 2004Q2 Standard and Enterprise Edition Update 2 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving error messages.
May 20, 2006
CVE-2005-1889 EPSS 0.00
Sun ONE App Server <6.5.6 - Info Disclosure
Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files.
Jun 07, 2005
CVE-2005-1150 EPSS 0.01
Sun Java System Web Server <6.0 SP7 - DoS
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).
May 02, 2005
CVE-2004-2216 EPSS 0.01
Sun Java System Web Server & App Server - DoS
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (crash) via a malformed client certificate.
Dec 31, 2004
CVE-2000-0812 EPSS 0.03
Sun Java Web Server - RCE
The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.
Nov 14, 2000
CVE-2000-0629 EPSS 0.02
Sun Java Web Server <2.0 - RCE
The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.
Jul 12, 2000