Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,497 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,202 vendors 42,818 researchers
111,546 results Clear all
CVE-2017-10923 6.5 MEDIUM EPSS 0.01
Xen - Improper Input Validation
Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
CWE-20 Jul 05, 2017
CVE-2017-10919 6.5 MEDIUM EPSS 0.01
Xen < 4.8.1 - Denial of Service
Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.
Jul 05, 2017
CVE-2017-10911 6.5 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.11.7 - Information Disclosure
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
CWE-200 Jul 05, 2017
CVE-2017-7276 6.1 MEDIUM EPSS 0.00
TOPdesk <5.7.6, 6.x, 7.x <7.03.019 - XSS
There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.
CWE-79 Jul 04, 2017
CVE-2017-10803 6.5 MEDIUM 1 PoC Analysis EPSS 0.02
Odoo - Insecure Deserialization
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.
CWE-502 Jul 04, 2017
CVE-2017-9313 6.1 MEDIUM 1 Writeup EPSS 0.01
Webmin <1.850 - XSS
Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these issues were not fixed in 1.840.
CWE-79 Jul 04, 2017
CVE-2017-7316 6.1 MEDIUM EPSS 0.00
Humax Digital HG100R <2.0.6 - XSS
An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page.
CWE-79 Jul 04, 2017
CVE-2017-6725 6.1 MEDIUM EPSS 0.00
Cisco Prime Infrastructure - XSS
A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCuw65833 CSCuw65837. Known Affected Releases: 2.2(2).
CWE-79 Jul 04, 2017
CVE-2017-6724 6.1 MEDIUM EPSS 0.00
Cisco Prime Infrastructure <3.1 - XSS
A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCuw65843. Known Affected Releases: 3.1(0.0).
CWE-79 Jul 04, 2017
CVE-2017-6722 6.1 MEDIUM EPSS 0.00
Cisco UCCx <11.5.1.10000.61 - Auth Bypass
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases: 10.6(1). Known Fixed Releases: 11.5(1.10000.61).
CWE-287 Jul 04, 2017
CVE-2017-6721 5.3 MEDIUM EPSS 0.01
Cisco WAAS <6.3(1) - DoS
A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to restart unexpectedly, causing a denial of service (DoS) condition. More Information: CSCvc57428. Known Affected Releases: 6.3(1). Known Fixed Releases: 6.3(0.143) 6.2(3c)6 6.2(3.22).
CWE-20 Jul 04, 2017
CVE-2017-6719 6.7 MEDIUM EPSS 0.00
Cisco IOS XR Software - Command Injection
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.1.28i.BASE 6.2.1.22i.BASE 6.1.32.8i.BASE 6.1.31.3i.BASE 6.1.3.10i.BASE.
CWE-20 Jul 04, 2017
CVE-2017-6718 6.7 MEDIUM EPSS 0.00
Cisco IOS XR Software - Privilege Escalation
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.11.3i.ROUT 6.2.1.29i.ROUT 6.2.1.26i.ROUT.
CWE-20 Jul 04, 2017
CVE-2017-6717 5.4 MEDIUM EPSS 0.00
Cisco Firepower Management Center - XSS
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc38801. Known Affected Releases: 6.0.1.3 6.2.1. Known Fixed Releases: 6.2.1.
CWE-79 Jul 04, 2017
CVE-2017-6716 5.4 MEDIUM EPSS 0.00
Cisco Firepower <6.0.0 - XSS
A vulnerability in the web framework code of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. Affected Products: Cisco Firepower Management Center Software Releases prior to 6.0.0.0. More Information: CSCuy88785. Known Affected Releases: 5.4.1.6.
CWE-79 Jul 04, 2017
CVE-2017-6715 5.4 MEDIUM EPSS 0.00
Cisco Firepower Mgmt Ctr <5.4.1.x - XSS
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. Affected Products: Cisco Firepower Management Center Releases 5.4.1.x and prior. More Information: CSCuy88951. Known Affected Releases: 5.4.1.6.
CWE-79 Jul 04, 2017
CVE-2017-6706 5.1 MEDIUM EPSS 0.00
Cisco Prime Collaboration Provisioning - Information Disclosure
A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information. More Information: CSCvd07260. Known Affected Releases: 12.1.
CWE-200 Jul 04, 2017
CVE-2017-6705 5.5 MEDIUM EPSS 0.00
Cisco Prime Collaboration Provisioning - Information Disclosure
A vulnerability in the filesystem of the Cisco Prime Collaboration Provisioning tool could allow an authenticated, local attacker to acquire sensitive information. More Information: CSCvc82973. Known Affected Releases: 12.1.
CWE-200 Jul 04, 2017
CVE-2017-6704 6.5 MEDIUM EPSS 0.01
Cisco Prime Collaboration Provisioning - Path Traversal
A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an authenticated, remote attacker to perform arbitrary file downloads that could allow the attacker to read files from the underlying filesystem. More Information: CSCvc90335. Known Affected Releases: 12.1.
CWE-22 Jul 04, 2017
CVE-2017-6703 5.9 MEDIUM EPSS 0.01
Cisco Prime Collaboration Provisioning - Authentication Bypass
A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack another user's session. More Information: CSCvc90346. Known Affected Releases: 12.1.
CWE-287 Jul 04, 2017