Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,497 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,202 vendors 42,818 researchers
111,546 results Clear all
CVE-2017-10972 6.5 MEDIUM EPSS 0.01
X.Org X Server <2017-06-19 - Info Disclosure
Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.
CWE-665 Jul 06, 2017
CVE-2017-10970 5.4 MEDIUM EPSS 0.00
Cacti - XSS
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.
CWE-79 Jul 06, 2017
CVE-2017-8420 6.5 MEDIUM EPSS 0.00
Swftools - Memory Corruption
SWFTools 2013-04-09-1007 on Windows has a "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x0000000000003e71" issue. This issue can be triggered by a malformed TTF file that is mishandled by font2swf. Attackers could exploit this issue for DoS (Access Violation).
CWE-119 Jul 05, 2017
CVE-2017-8387 5.5 MEDIUM EPSS 0.00
Stdutility Stdu Viewer - Memory Corruption
STDU Viewer version 1.6.375 might allow user-assisted attackers to execute code via a crafted file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands including Ctrl-+ commands.
CWE-119 Jul 05, 2017
CVE-2017-1157 4.3 MEDIUM EPSS 0.00
IBM Jazz Reporting Service - Info Disclosure
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.
CWE-200 Jul 05, 2017
CVE-2017-1096 5.4 MEDIUM EPSS 0.00
IBM Jazz Reporting Service - XSS
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120656.
CWE-79 Jul 05, 2017
CVE-2016-9989 5.4 MEDIUM EPSS 0.00
IBM Jazz Reporting Service - XSS
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120555.
CWE-79 Jul 05, 2017
CVE-2016-9988 5.4 MEDIUM EPSS 0.00
IBM Jazz Reporting Service - XSS
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120554.
CWE-79 Jul 05, 2017
CVE-2016-9987 5.4 MEDIUM EPSS 0.00
IBM Jazz Reporting Service - XSS
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120553.
CWE-79 Jul 05, 2017
CVE-2016-9986 5.4 MEDIUM EPSS 0.00
IBM Jazz Reporting Service - XSS
IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120552.
CWE-79 Jul 05, 2017
CVE-2016-9700 4.3 MEDIUM EPSS 0.00
IBM Rational Collaborative Lifecycle ... - Information Disclosure
IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528.
CWE-200 Jul 05, 2017
CVE-2017-1208 5.4 MEDIUM EPSS 0.00
IBM Maximo Asset Management - XSS
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778.
CWE-79 Jul 05, 2017
CVE-2017-1207 5.5 MEDIUM EPSS 0.00
IBM Websphere Message Broker - Insufficiently Protected Credentials
IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.
CWE-522 Jul 05, 2017
CVE-2017-1113 5.4 MEDIUM EPSS 0.00
IBM Rational Team Concert - XSS
IBM Rational Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121151.
CWE-79 Jul 05, 2017
CVE-2016-9746 5.4 MEDIUM EPSS 0.00
IBM Rational Collaborative Lifecycle Management - XSS
IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119821.
CWE-79 Jul 05, 2017
CVE-2016-9733 5.4 MEDIUM EPSS 0.00
IBM Rational Team Concert - XSS
IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119762.
CWE-79 Jul 05, 2017
CVE-2016-9701 5.4 MEDIUM EPSS 0.00
IBM Rational Team Concert - XSS
IBM Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119529.
CWE-79 Jul 05, 2017
CVE-2017-1258 6.5 MEDIUM EPSS 0.00
IBM Security Guardium - Authentication Bypass
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685
CWE-287 Jul 05, 2017
CVE-2017-1256 6.1 MEDIUM EPSS 0.00
IBM Security Guardium - XSS
IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124678
CWE-79 Jul 05, 2017
CVE-2017-1217 6.1 MEDIUM EPSS 0.00
IBM Websphere Portal - XSS
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857
CWE-79 Jul 05, 2017