Exploit Intelligence Platform

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,480 CVEs tracked 53,336 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,227 vendors 42,821 researchers
111,578 results Clear all
CVE-2017-1000006 6.1 MEDIUM EPSS 0.01
Plotly, Inc. plotly.js <1.16.0 - XSS
Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.
CWE-79 Jul 17, 2017
CVE-2017-1000005 6.1 MEDIUM 1 Writeup EPSS 0.00
PHPMiniAdmin <1.9.160630 - XSS
PHPMiniAdmin version 1.9.160630 is vulnerable to stored XSS in the name of databases, tables and columns resulting in potential account takeover and scraping of data (stealing data).
CWE-79 Jul 17, 2017
CVE-2017-0196 6.5 MEDIUM 1 Writeup EPSS 0.19
Microsoft Edge - Information Disclosure
An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
CWE-200 Jul 17, 2017
CVE-2016-6312 6.5 MEDIUM EPSS 0.01
Apache mod_dontdothat - DoS
The mod_dontdothat component of the mod_dav_svn Apache module in Subversion as packaged in Red Hat Enterprise Linux 5.11 does not properly detect recursion during entity expansion, which allows remote authenticated users with access to the webdav repository to cause a denial of service (memory consumption and httpd crash). NOTE: Exists as a regression to CVE-2009-1955.
CWE-400 Jul 17, 2017
CVE-2016-4984 4.7 MEDIUM EPSS 0.00
Openldap-servers - Race Condition
/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.
CWE-362 Jul 17, 2017
CVE-2016-4982 4.7 MEDIUM EPSS 0.00
Teether Authd - Race Condition
authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.
CWE-362 Jul 17, 2017
CVE-2016-10398 6.2 MEDIUM EPSS 0.00
Google Android - Access Control
Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by a weak challenge. This allows adversaries to replay previously captured responses and use the TEE without authenticating. All apps using authentication-gated cryptography are vulnerable to this attack, which was confirmed on the LG Nexus 5X.
CWE-264 Jul 17, 2017
CVE-2016-0764 6.2 MEDIUM EPSS 0.00
Red Hat Network Manager <1.0.12 - Info Disclosure
Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes.
CWE-362 Jul 17, 2017
CVE-2017-7672 5.9 MEDIUM EPSS 0.01
Apache Struts <2.5.12 - DoS
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.
CWE-20 Jul 13, 2017
CVE-2017-1308 6.5 MEDIUM EPSS 0.00
IBM Daeja ViewONE <5.0 - Info Disclosure
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.
CWE-552 Jul 13, 2017
CVE-2016-8952 5.4 MEDIUM EPSS 0.00
IBM Emptoris Strategic Supply Management Platform <10.1.1.x - XSS
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118839.
CWE-79 Jul 13, 2017
CVE-2016-6019 5.4 MEDIUM EPSS 0.00
IBM Emptoris Strategic Supply Management Platform <10.1.1.x - XSS
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116739.
CWE-79 Jul 13, 2017
CVE-2017-11202 6.1 MEDIUM EPSS 0.00
Finecms - XSS
FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during logging or during the reading of logs, a different vulnerability than CVE-2017-11180.
CWE-79 Jul 13, 2017
CVE-2017-11201 5.4 MEDIUM EPSS 0.00
Finecms - XSS
application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action.
CWE-79 Jul 13, 2017
CVE-2017-11198 6.1 MEDIUM EPSS 0.00
Finecms - XSS
Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or name parameter.
CWE-79 Jul 13, 2017
CVE-2017-11195 6.1 MEDIUM EPSS 0.00
Pulsesecure Pulse Connect Secure - XSS
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this.
CWE-79 Jul 12, 2017
CVE-2017-11194 6.1 MEDIUM EPSS 0.00
Pulsesecure Pulse Connect Secure - XSS
Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cgi is reflected in the application's response and is not properly sanitized, allowing an attacker to inject tags. An attacker could come up with clever payloads to make the system run commands such as ping, ping6, traceroute, nslookup, arp, etc.
CWE-79 Jul 12, 2017
CVE-2017-1321 6.1 MEDIUM EPSS 0.00
IBM InfoSphere Information Server <11.5 - XSS
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916.
CWE-79 Jul 12, 2017
CVE-2017-1285 6.5 MEDIUM EPSS 0.00
IBM Websphere MQ - Improper Input Validation
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to remain in a running state but not process messages. IBM X-Force ID: 125146.
CWE-20 Jul 12, 2017
CVE-2016-8953 5.4 MEDIUM EPSS 0.00
IBM Emptoris Sourcing <10.1.x - Open Redirect
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118840.
CWE-601 Jul 12, 2017