Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,484 CVEs tracked 53,337 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,229 vendors 42,825 researchers
111,579 results Clear all
CVE-2017-11534 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.6-1 - Memory Corruption
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the lite_font_map() function in coders/wmf.c.
CWE-772 Jul 23, 2017
CVE-2017-11533 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.6-1 - Buffer Overflow
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteUILImage() function in coders/uil.c.
CWE-125 Jul 23, 2017
CVE-2017-11532 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.6-1 - Memory Corruption
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteMPCImage() function in coders/mpc.c.
CWE-772 Jul 23, 2017
CVE-2017-11531 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.6-1 - Memory Corruption
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteHISTOGRAMImage() function in coders/histogram.c.
CWE-772 Jul 23, 2017
CVE-2017-11530 6.5 MEDIUM EPSS 0.01
ImageMagick <6.9.9-0, <7.0.6-1 - DoS
The ReadEPTImage function in coders/ept.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
CWE-400 Jul 23, 2017
CVE-2017-11529 6.5 MEDIUM EPSS 0.01
ImageMagick <6.9.9-0, <7.0.6-1 - DoS
The ReadMATImage function in coders/mat.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Jul 23, 2017
CVE-2017-11528 6.5 MEDIUM EPSS 0.01
ImageMagick <6.9.9-0, <7.0.6-1 - DoS
The ReadDIBImage function in coders/dib.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Jul 23, 2017
CVE-2017-11527 6.5 MEDIUM EPSS 0.01
ImageMagick <6.9.9-0, <7.0.6-1 - DoS
The ReadDPXImage function in coders/dpx.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
CWE-400 Jul 23, 2017
CVE-2017-11526 6.5 MEDIUM EPSS 0.01
ImageMagick <6.9.9-0, <7.0.6-1 - DoS
The ReadOneMNGImage function in coders/png.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted file.
CWE-400 Jul 23, 2017
CVE-2017-11525 6.5 MEDIUM EPSS 0.01
ImageMagick <6.9.9-0, <7.0.6-1 - DoS
The ReadCINImage function in coders/cin.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
CWE-770 Jul 23, 2017
CVE-2017-11524 6.5 MEDIUM EPSS 0.01
ImageMagick <6.9.8-10, <7.6.0-0 - DoS
The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.
CWE-617 Jul 23, 2017
CVE-2017-11523 6.5 MEDIUM 1 Writeup EPSS 0.01
ImageMagick <7.0.6.1 - DoS
The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted file, because the end-of-file condition is not considered.
CWE-835 Jul 22, 2017
CVE-2017-11522 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageMagick <7.0.6.1 - DoS
The WriteOnePNGImage function in coders/png.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Jul 22, 2017
CVE-2017-2274 6.1 MEDIUM EPSS 0.00
WMR-433 <1.02 & WMR-433W <1.40 - XSS
Cross-site scripting vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jul 22, 2017
CVE-2017-1374 6.5 MEDIUM EPSS 0.00
IBM TRIRIGA App Plat <3.5 - Info Disclosure
Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to the system. IBM X-Force ID: 126867.
CWE-200 Jul 21, 2017
CVE-2017-1372 5.4 MEDIUM EPSS 0.00
IBM TRIRIGA Application Platform <3.6 - XSS
IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126865.
CWE-79 Jul 21, 2017
CVE-2017-11516 6.1 MEDIUM EPSS 0.00
Yii Framework 2.0.12 - XSS
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.
CWE-79 Jul 21, 2017
CVE-2017-7542 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux kernel <4.12.3 - DoS
The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (integer overflow and infinite loop) by leveraging the ability to open a raw socket.
CWE-190 Jul 21, 2017
CVE-2017-11505 6.5 MEDIUM EPSS 0.01
ImageMagick <7.0.6.1 - DoS
The ReadOneJNGImage function in coders/png.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a malformed JNG file.
CWE-834 Jul 21, 2017
CVE-2015-3421 6.1 MEDIUM EPSS 0.00
Wordpress Eshop <6.3.11 - XSS
The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.
CWE-79 Jul 21, 2017