Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,497 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,202 vendors 42,818 researchers
111,546 results Clear all
CVE-2017-8554 4.7 MEDIUM EPSS 0.01
Microsoft Windows 10 - Information Disclosure
The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an authenticated attacker to obtain memory contents via a specially crafted application.
CWE-200 Jun 29, 2017
CVE-2017-1310 6.5 MEDIUM EPSS 0.01
IBM Informix Dynamic Server 12.1 - Buffer Overflow
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
CWE-119 Jun 29, 2017
CVE-2017-10673 6.1 MEDIUM EPSS 0.00
Get-simple Getsimple Cms - XSS
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
CWE-79 Jun 29, 2017
CVE-2017-10667 6.1 MEDIUM EPSS 0.00
Zen-cart Zen Cart - XSS
In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS.
CWE-79 Jun 29, 2017
CVE-2017-1106 5.4 MEDIUM EPSS 0.00
IBM Curam Social Program Management <7.0 - XSS
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120744.
CWE-79 Jun 28, 2017
CVE-2017-5241 5.4 MEDIUM EPSS 0.00
Biscom Secure File Transfer <5.1.1024 - XSS
Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in the "Name" and "Description" fields of a Workspace, as well as the "Description" field of a File Details pane of a file stored in a Workspace. This issue has been resolved in version 5.1.1025.
CWE-79 Jun 28, 2017
CVE-2017-9998 6.5 MEDIUM EPSS 0.01
Libdwarf < 2017-06-28 - Memory Corruption
The _dwarf_decode_s_leb128_chk function in dwarf_leb.c in libdwarf through 2017-06-28 allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
CWE-119 Jun 28, 2017
CVE-2017-9989 6.5 MEDIUM EPSS 0.01
Libming - NULL Pointer Dereference
util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack.
CWE-476 Jun 28, 2017
CVE-2017-9988 6.5 MEDIUM EPSS 0.01
Libming - NULL Pointer Dereference
The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.
CWE-476 Jun 28, 2017
CVE-2015-8697 5.5 MEDIUM EPSS 0.00
Stalin - Improper Access Control
stalin 0.11-5 allows local users to write to arbitrary files.
CWE-284 Jun 27, 2017
CVE-2015-7898 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Samsung Galaxy S6 - DoS
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CWE-284 Jun 27, 2017
CVE-2015-7895 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Samsung Gallery <Galaxy S6 - DoS
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CWE-284 Jun 27, 2017
CVE-2015-7780 6.5 MEDIUM NUCLEI EPSS 0.36
ManageEngine Firewall Analyzer <8.0 - Path Traversal
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
CWE-22 Jun 27, 2017
CVE-2015-3840 5.5 MEDIUM EPSS 0.00
Android <5.1.1 - Info Disclosure
The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.
CWE-284 Jun 27, 2017
CVE-2017-1328 5.3 MEDIUM EPSS 0.00
IBM API Connect 5.0.0.0-5.0.6.0 - Auth Bypass
IBM API Connect 5.0.0.0 - 5.0.6.0 could allow a remote attacker to bypass security restrictions of the api, caused by improper handling of security policy. By crafting a suitable request, an attacker could exploit this vulnerability to bypass security and use the vulnerable API. IBM X-Force ID: 126230.
Jun 27, 2017
CVE-2017-1234 5.4 MEDIUM EPSS 0.00
IBM Qradar Security Information And Event Manager - XSS
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123913.
CWE-79 Jun 27, 2017
CVE-2016-9972 5.9 MEDIUM EPSS 0.00
IBM Qradar Security Information And Event Manager - Access Control
IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 120208.
CWE-264 Jun 27, 2017
CVE-2016-6083 5.3 MEDIUM EPSS 0.00
IBM Tivoli Monitoring V6 - Info Disclosure
IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696.
CWE-200 Jun 27, 2017
CVE-2017-7522 6.5 MEDIUM EPSS 0.01
OpenVPN <2.4.3, <2.3.17 - DoS
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.
CWE-476 Jun 27, 2017
CVE-2017-7521 5.9 MEDIUM EPSS 0.00
OpenVPN <2.4.3, <2.3.17 - DoS
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().
CWE-772 Jun 27, 2017