Exploit Intelligence Platform

Updated 12m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,495 CVEs tracked 53,335 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,948 Nuclei templates 49,233 vendors 42,833 researchers
111,593 results Clear all
CVE-2017-11750 6.5 MEDIUM EPSS 0.01
ImageMagick <7.0.6.4 - DoS
The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Jul 30, 2017
CVE-2017-11747 5.5 MEDIUM EPSS 0.00
Tinyproxy <1.8.4 - Local Privilege Escalation
main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tinyproxy.pid modification before a root script executes a "kill `cat /run/tinyproxy/tinyproxy.pid`" command.
CWE-269 Jul 30, 2017
CVE-2017-11744 6.1 MEDIUM EPSS 0.00
MODX Revolution <2.5.7 - XSS
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.
CWE-79 Jul 30, 2017
CVE-2017-11737 6.1 MEDIUM EPSS 0.00
Rspamd <1.6.3 - XSS
interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.
CWE-79 Jul 29, 2017
CVE-2017-11734 5.5 MEDIUM EPSS 0.00
Ming 0.4.8 - Buffer Overflow
A heap-based buffer over-read was found in the function decompileCALLFUNCTION in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CWE-125 Jul 29, 2017
CVE-2017-11733 5.5 MEDIUM EPSS 0.00
Ming 0.4.8 - DoS
A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CWE-476 Jul 29, 2017
CVE-2017-11732 5.5 MEDIUM EPSS 0.00
Ming 0.4.8 - Buffer Overflow
A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CWE-119 Jul 29, 2017
CVE-2017-11731 5.5 MEDIUM EPSS 0.00
Ming 0.4.8 - Memory Corruption
An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CWE-125 Jul 29, 2017
CVE-2017-11730 5.5 MEDIUM EPSS 0.00
Ming 0.4.8 - Buffer Overflow
A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1474) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CWE-125 Jul 29, 2017
CVE-2017-11729 5.5 MEDIUM EPSS 0.00
Ming 0.4.8 - Buffer Overflow
A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1440) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CWE-125 Jul 29, 2017
CVE-2017-11728 5.5 MEDIUM EPSS 0.00
Ming 0.4.8 - Buffer Overflow
A heap-based buffer over-read was found in the function OpCode (called from decompileSETMEMBER) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CWE-125 Jul 29, 2017
CVE-2017-11725 5.4 MEDIUM EPSS 0.00
Thycotic Secret Server <10.2.000019 - CSRF
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
CWE-601 Jul 29, 2017
CVE-2017-11724 6.5 MEDIUM EPSS 0.00
ImageMagick <7.0.6.3 - Memory Corruption
The ReadMATImage function in coders/mat.c in ImageMagick through 6.9.9-3 and 7.x through 7.0.6-3 has memory leaks involving the quantum_info and clone_info data structures.
CWE-772 Jul 29, 2017
CVE-2015-5191 6.7 MEDIUM EPSS 0.00
Vmware Tools < 10.0.8 - Race Condition
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-362 Jul 28, 2017
CVE-2017-6260 6.5 MEDIUM EPSS 0.00
Nvidia Gpu Driver - Memory Corruption
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer helper function where an incorrect calculation of string length may lead to denial of service.
CWE-119 Jul 28, 2017
CVE-2017-6259 6.1 MEDIUM EPSS 0.01
Nvidia Gpu Driver - Denial of Service
NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect detection and recovery from an invalid state produced by specific user actions may lead to denial of service.
Jul 28, 2017
CVE-2017-11722 6.5 MEDIUM EPSS 0.01
GraphicsMagick 1.3.26 - DoS
The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its indentation. This resulted in a logging statement executing outside of a loop, and consequently using an invalid array index corresponding to the loop's exit condition.
CWE-125 Jul 28, 2017
CVE-2017-11718 6.1 MEDIUM EPSS 0.00
MetInfo <5.3.17 - Open Redirect
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.
CWE-601 Jul 28, 2017
CVE-2017-11716 6.1 MEDIUM EPSS 0.00
MetInfo <5.3.17 - XSS
MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.
CWE-79 Jul 28, 2017
CVE-2017-11705 6.5 MEDIUM EPSS 0.00
Ming 0.4.8 - Memory Corruption
A memory leak was found in the function parseSWF_SHAPEWITHSTYLE in util/parser.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
CWE-772 Jul 28, 2017