Exploit Intelligence Platform

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,480 CVEs tracked 53,336 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,227 vendors 42,821 researchers
111,578 results Clear all
CVE-2017-1000070 6.1 MEDIUM EPSS 0.00
Bitly oauth2_proxy <2.1 - Open Redirect
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819
CWE-601 Jul 17, 2017
CVE-2017-1000065 6.1 MEDIUM 1 Writeup EPSS 0.00
OpenMediaVault 2.1 - XSS
Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.
CWE-79 Jul 17, 2017
CVE-2017-1000063 6.1 MEDIUM EPSS 0.00
kittoframework kitto <0.5.1 - XSS
kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404 page resulting in information disclosure
CWE-79 Jul 17, 2017
CVE-2017-1000059 6.1 MEDIUM EPSS 0.00
Live Helper Chat <2.06v - XSS
Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users.
CWE-79 Jul 17, 2017
CVE-2017-1000058 6.1 MEDIUM EPSS 0.00
Chevereto CMS <3.8.11 - XSS
Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.
CWE-79 Jul 17, 2017
CVE-2017-1000054 6.1 MEDIUM EPSS 0.00
Rocket.Chat >=0.8.0 - XSS
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.
CWE-79 Jul 17, 2017
CVE-2017-1000051 6.1 MEDIUM EPSS 0.00
CryptPad <1.1.1 - XSS
Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content
CWE-79 Jul 17, 2017
CVE-2017-1000043 6.1 MEDIUM EPSS 0.00
Mapbox.js <1.6.6, <2.2.4 - XSS
Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON name and map share control
CWE-79 Jul 17, 2017
CVE-2017-1000042 6.1 MEDIUM EPSS 0.00
Mapbox.js <1.6.5, <2.1.7 - XSS
Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name.
CWE-79 Jul 17, 2017
CVE-2017-1000038 6.1 MEDIUM EPSS 0.01
WordPress plugin Relevanssi <3.5.7.1 - XSS
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site
CWE-79 Jul 17, 2017
CVE-2017-1000035 6.1 MEDIUM EPSS 0.00
Tiny Tiny RSS <829d478f - XSS
Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack
CWE-79 Jul 17, 2017
CVE-2017-1000033 6.1 MEDIUM EPSS 0.02
Wordpress Plugin Vospari Forms < 1.4 - XSS
Wordpress Plugin Vospari Forms version < 1.4 is vulnerable to a reflected cross site scripting in the form submission resulting in javascript code execution in the context on the current user.
CWE-79 Jul 17, 2017
CVE-2017-1000032 6.1 MEDIUM EPSS 0.00
Cacti 0.8.8b - XSS
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.
CWE-79 Jul 17, 2017
CVE-2017-1000027 6.1 MEDIUM EPSS 0.02
Koozali Foundation SME Server <10 - Open Redirect
Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.
CWE-601 Jul 17, 2017
CVE-2017-1000023 5.4 MEDIUM EPSS 0.00
LogicalDoc CE <7.5.3 - XSS
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
CWE-79 Jul 17, 2017
CVE-2017-1000015 6.1 MEDIUM EPSS 0.01
phpMyAdmin <4.7 - Code Injection
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters
CWE-79 Jul 17, 2017
CVE-2017-1000013 6.1 MEDIUM EPSS 0.00
phpMyAdmin <4.7 - Open Redirect
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
CWE-601 Jul 17, 2017
CVE-2017-1000012 6.1 MEDIUM 1 Writeup EPSS 0.00
MySQL Dumper <1.24 - XSS
MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user
CWE-79 Jul 17, 2017
CVE-2017-1000011 6.1 MEDIUM EPSS 0.00
MyWebSQL <3.6 - XSS
MyWebSQL version 3.6 is vulnerable to stored XSS in the database manager component resulting in account takeover or stealing of information
CWE-79 Jul 17, 2017
CVE-2017-1000007 5.9 MEDIUM EPSS 0.00
txAWS - Info Disclosure
txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.
CWE-295 Jul 17, 2017