Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,484 CVEs tracked 53,337 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,229 vendors 42,825 researchers
111,579 results Clear all
CVE-2015-3170 5.5 MEDIUM EPSS 0.00
selinux-policy - DoS
selinux-policy when sysctl fs.protected_hardlinks are set to 0 allows local users to cause a denial of service (SSH login prevention) by creating a hardlink to /etc/passwd from a directory named .config, and updating selinux-policy.
CWE-254 Jul 21, 2017
CVE-2015-1323 5.5 MEDIUM EPSS 0.00
aptdaemon <1.1.1 - Info Disclosure
The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0ubuntu1.1 as packaged in Ubuntu 14.10, before 1.1.1-1ubuntu5.2 as packaged in Ubuntu 14.04 LTS, before 0.43+bzr805-0ubuntu10 as packaged in Ubuntu 12.04 LTS allows local users to obtain sensitive information, or access files with root permissions.
CWE-200 Jul 21, 2017
CVE-2017-9931 6.1 MEDIUM EPSS 0.00
Greenpacket Dx-350 Firmware - XSS
Cross-Site Scripting (XSS) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by the action parameter to ajax.cgi.
CWE-79 Jul 21, 2017
CVE-2017-11503 6.1 MEDIUM 1 PoC EPSS 0.02
PHPMailer 5.2.23 - XSS
PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.
CWE-79 Jul 20, 2017
CVE-2017-11501 5.9 MEDIUM EPSS 0.00
NixOS <17.03 - Info Disclosure
NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers via a PAM module. It was found that if TLS is enabled to connect to the LDAP server with users.ldap.useTLS, peer verification will be unconditionally disabled in /etc/ldap.conf.
CWE-295 Jul 20, 2017
CVE-2017-0378 6.1 MEDIUM EPSS 0.01
Phamm < 0.6.6 - XSS
XSS exists in the login_form function in views/helpers.php in Phamm before 0.6.7, exploitable via the PATH_INFO to main.php.
CWE-79 Jul 20, 2017
CVE-2017-7067 5.5 MEDIUM EPSS 0.00
Apple <10.12.6 - Info Disclosure
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
Jul 20, 2017
CVE-2017-7064 5.5 MEDIUM 1 PoC Analysis EPSS 0.03
Apple <10.3.3, <10.1.2, <6.2.2, <12.6.2 - Info Disclosure
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
CWE-20 Jul 20, 2017
CVE-2017-7060 6.5 MEDIUM EPSS 0.01
Apple <10.3.3, <10.1.2 - DoS
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "Safari Printing" component. It allows remote attackers to cause a denial of service (excessive print dialogs) via a crafted web site.
CWE-20 Jul 20, 2017
CVE-2017-7059 6.1 MEDIUM EPSS 0.00
Apple - XSS
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
CWE-79 Jul 20, 2017
CVE-2017-7045 5.5 MEDIUM EPSS 0.00
Apple <10.12.6 - Info Disclosure
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
CWE-20 Jul 20, 2017
CVE-2017-7038 6.1 MEDIUM 1 PoC Analysis EPSS 0.06
Apple - XSS
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
CWE-79 Jul 20, 2017
CVE-2017-7036 5.5 MEDIUM EPSS 0.00
Apple <10.12.6 - Info Disclosure
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
CWE-125 Jul 20, 2017
CVE-2017-7029 5.5 MEDIUM EPSS 0.00
Apple <10.3.3, <10.12.6, <10.2.2, <3.2.3 - Info Disclosure
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
CWE-200 Jul 20, 2017
CVE-2017-7028 5.5 MEDIUM EPSS 0.00
Apple <10.3.3, <10.12.6, <10.2.2, <3.2.3 - Info Disclosure
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
CWE-200 Jul 20, 2017
CVE-2017-7011 6.5 MEDIUM EPSS 0.01
Apple <10.3.3, <10.1.2 - XSS
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site that uses FRAME elements.
CWE-20 Jul 20, 2017
CVE-2017-7006 5.3 MEDIUM EPSS 0.01
Apple <10.3.3, <10.1.2, <10.2.2 - Info Disclosure
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing side-channel attack to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses SVG filters.
CWE-203 Jul 20, 2017
CVE-2017-2517 6.5 MEDIUM EPSS 0.01
Apple Iphone OS < 10.3.2 - Improper Input Validation
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
CWE-20 Jul 20, 2017
CVE-2017-11478 6.5 MEDIUM EPSS 0.01
ImageMagick <7.0.6.1 - DoS
The ReadOneDJVUImage function in coders/djvu.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed DJVU image.
CWE-835 Jul 20, 2017
CVE-2017-10676 6.1 MEDIUM EPSS 0.00
D-link Dir-600m Firmware - XSS
On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter.
CWE-79 Jul 20, 2017