Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,500 CVEs tracked 53,315 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,948 Nuclei templates 49,254 vendors 42,840 researchers
111,618 results Clear all
CVE-2017-12777 6.1 MEDIUM EPSS 0.00
Nexusphp - XSS
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.
CWE-79 Aug 09, 2017
CVE-2017-0739 5.5 MEDIUM EPSS 0.00
Android <7.1.2 - Info Disclosure
A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37712181.
CWE-200 Aug 09, 2017
CVE-2017-0738 5.5 MEDIUM EPSS 0.00
Android <7.1.2 - Info Disclosure
A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563371.
CWE-200 Aug 09, 2017
CVE-2017-0736 5.5 MEDIUM EPSS 0.00
Android <7.1.2 - DoS
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38487564.
Aug 09, 2017
CVE-2017-0735 5.5 MEDIUM EPSS 0.00
Android <7.1.2 - DoS
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38239864.
CWE-665 Aug 09, 2017
CVE-2017-0734 5.5 MEDIUM EPSS 0.00
Android <7.1.2 - DoS
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38014992.
Aug 09, 2017
CVE-2017-0733 5.5 MEDIUM EPSS 0.00
Android <7.1.2 - DoS
A denial of service vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38391487.
CWE-404 Aug 09, 2017
CVE-2017-0730 5.5 MEDIUM EPSS 0.00
Android <7.1.2 - DoS
A denial of service vulnerability in the Android media framework (h264 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36279112.
CWE-909 Aug 09, 2017
CVE-2017-0726 5.5 MEDIUM EPSS 0.00
Android <7.1.2 - DoS
A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36389123.
CWE-772 Aug 09, 2017
CVE-2017-0725 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Android <7.1.2 - DoS
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.
CWE-125 Aug 09, 2017
CVE-2017-0724 5.5 MEDIUM EPSS 0.00
Android <7.1.2 - DoS
A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36819262.
CWE-20 Aug 09, 2017
CVE-2017-1448 5.4 MEDIUM EPSS 0.00
IBM Emptoris Strategic Supply Management - Open Redirect
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128173.
CWE-601 Aug 09, 2017
CVE-2017-1357 4.3 MEDIUM EPSS 0.00
IBM Maximo Asset Mgmt <7.6 - Privilege Escalation
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684.
CWE-20 Aug 09, 2017
CVE-2017-11368 6.5 MEDIUM 1 Writeup EPSS 0.01
Fedora - Reachable Assertion
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
CWE-617 Aug 09, 2017
CVE-2016-8949 5.4 MEDIUM EPSS 0.00
IBM Emptoris Supplier Lifecycle Management <10.2 - Open Redirect
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118836.
CWE-601 Aug 09, 2017
CVE-2016-6121 5.4 MEDIUM EPSS 0.00
IBM Emptoris Supplier Lifecycle Management <10.1.x - XSS
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118383.
CWE-79 Aug 09, 2017
CVE-2015-2687 4.7 MEDIUM EPSS 0.00
Openstack Compute < 15.0.0.0b1 - Improper Access Control
OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
CWE-284 Aug 09, 2017
CVE-2015-2674 5.9 MEDIUM EPSS 0.00
Restkit - Improper Certificate Validation
Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.
CWE-295 Aug 09, 2017
CVE-2015-0783 6.5 MEDIUM EPSS 0.01
Novell Zenworks Configuration Management - Information Disclosure
The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable.
CWE-200 Aug 09, 2017
CVE-2014-9701 6.5 MEDIUM EPSS 0.01
MantisBT <1.2.19, <1.3.0-beta.2 - XSS
Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter to permalink_page.php.
CWE-79 Aug 09, 2017