Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,490 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,201 vendors 42,812 researchers
111,546 results Clear all
CVE-2017-9778 5.5 MEDIUM EPSS 0.00
GDB <8.0 - Memory Corruption
GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file can cause GDB to repeatedly allocate memory until a process limit is reached. This can, for example, impede efforts to analyze malware with GDB.
CWE-770 Jun 21, 2017
CVE-2017-9130 5.5 MEDIUM 1 PoC Analysis EPSS 0.01
Freeware Advanced Audio Coder (FAAC) 1.28 - DoS
The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.
CWE-125 Jun 21, 2017
CVE-2017-9129 5.5 MEDIUM 1 PoC Analysis EPSS 0.01
Freeware Advanced Audio Coder (FAAC) 1.28 - DoS
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.
CWE-400 Jun 21, 2017
CVE-2017-3744 6.5 MEDIUM EPSS 0.00
Lenovo System x - Info Disclosure
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.
CWE-532 Jun 20, 2017
CVE-2017-3215 5.3 MEDIUM EPSS 0.00
Milwaukee One-key - Insufficient Session Expiration
The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.
CWE-613 Jun 20, 2017
CVE-2017-9762 5.5 MEDIUM EPSS 0.00
radare2 <1.5.0 - DoS
The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file.
CWE-416 Jun 19, 2017
CVE-2017-9761 5.5 MEDIUM 1 Writeup EPSS 0.00
radare2 <1.5.0 - DoS
The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
CWE-119 Jun 19, 2017
CVE-2017-1000377 5.9 MEDIUM EPSS 0.00
PAX Linux <June 19, 2017 - Memory Corruption
An issue was discovered in the size of the default stack guard page on PAX Linux (originally from GRSecurity but shipped by other Linux vendors), specifically the default stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects PAX Linux Kernel versions as of June 19, 2017 (specific version information is not available at this time).
CWE-119 Jun 19, 2017
CVE-2017-1000373 6.5 MEDIUM 1 PoC Analysis EPSS 0.19
OpenBSD <6.1 - RCE
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.
CWE-400 Jun 19, 2017
CVE-2017-1000369 4.0 MEDIUM 1 Writeup EPSS 0.00
Exim <4.89 - RCE
Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note that at this time upstream has released a patch (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21), but it is not known if a new point release is available that addresses this issue at this time.
CWE-404 Jun 19, 2017
CVE-2017-9668 6.1 MEDIUM EPSS 0.00
CMS Made Simple 2.1.6 - XSS
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.
CWE-79 Jun 18, 2017
CVE-2017-1000380 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux kernel <4.11.5 - Info Disclosure
sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.
CWE-200 Jun 17, 2017
CVE-2017-9503 5.5 MEDIUM EPSS 0.00
QEMU - DoS
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing.
CWE-476 Jun 16, 2017
CVE-2017-9375 5.5 MEDIUM EPSS 0.00
QEMU - DoS
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing.
CWE-835 Jun 16, 2017
CVE-2017-9374 5.5 MEDIUM EPSS 0.00
QEMU - DoS
Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the device.
CWE-401 Jun 16, 2017
CVE-2017-9373 5.5 MEDIUM EPSS 0.00
QEMU - DoS
Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the AHCI device.
CWE-401 Jun 16, 2017
CVE-2015-3254 6.5 MEDIUM EPSS 0.02
Apache Thrift <0.9.3 - DoS
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
CWE-20 Jun 16, 2017
CVE-2017-8451 6.1 MEDIUM EPSS 0.00
Elastic Kibana < 5.3.0 - Open Redirect
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
CWE-601 Jun 16, 2017
CVE-2017-8449 5.9 MEDIUM EPSS 0.00
Elastic X-pack < 5.2.2 - Information Disclosure
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.
CWE-200 Jun 16, 2017
CVE-2016-10366 6.1 MEDIUM EPSS 0.00
Elastic Kibana - XSS
Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.
CWE-79 Jun 16, 2017