Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,380 CVEs tracked 53,349 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,139 vendors 42,810 researchers
111,437 results Clear all
CVE-2017-1305 5.4 MEDIUM EPSS 0.00
IBM DOORS Next Generation (DNG/RRC) <6.0.3 - XSS
IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125459.
CWE-79 Jun 07, 2017
CVE-2017-1178 6.1 MEDIUM EPSS 0.00
IBM Endpoint Manager for Security and Compliance <1.9.70 - XSS
IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123430.
CWE-79 Jun 07, 2017
CVE-2016-9710 5.3 MEDIUM EPSS 0.00
IBM Cognos Business Intelligence Server - Information Disclosure
IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow the attacker to obtain sensitive information. IBM X-Force ID: 119618.
CWE-200 Jun 07, 2017
CVE-2016-8939 5.5 MEDIUM EPSS 0.00
IBM Tivoli Storage Manager - Info Disclosure
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.
CWE-200 Jun 07, 2017
CVE-2016-6089 5.5 MEDIUM EPSS 0.00
IBM WebSphere MQ <9.0.2 - Privilege Escalation
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.
CWE-284 Jun 07, 2017
CVE-2016-5960 5.5 MEDIUM EPSS 0.00
IBM Security Privileged Identity Manager <2.1.0 - Info Disclosure
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.
CWE-200 Jun 07, 2017
CVE-2016-5959 5.3 MEDIUM EPSS 0.00
IBM Security Privileged Identity Manager <2.1.0 - Info Disclosure
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136.
CWE-200 Jun 07, 2017
CVE-2016-3051 4.3 MEDIUM EPSS 0.00
IBM Security Access Manager 9.0 Firmware - Access Control
IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.
CWE-264 Jun 07, 2017
CVE-2016-3019 6.5 MEDIUM EPSS 0.00
IBM Security Access Manager 9.0 Firmware - Weak Encryption
IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.
CWE-326 Jun 07, 2017
CVE-2016-0254 6.5 MEDIUM EPSS 0.00
IBM Cognos Business Intelligence <10.2 - DoS
IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vulnerability to consume all available CPU resources and cause a denial of service. IBM X-Force ID: 110563.
CWE-611 Jun 07, 2017
CVE-2017-9501 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageMagick <7.0.5-7 - DoS
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function LockSemaphoreInfo, which allows attackers to cause a denial of service via a crafted file.
CWE-617 Jun 07, 2017
CVE-2017-9500 6.5 MEDIUM EPSS 0.00
ImageMagick <7.0.5-8 - DoS
In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.
CWE-617 Jun 07, 2017
CVE-2017-9499 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageMagick <7.0.5-7 - DoS
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.
CWE-617 Jun 07, 2017
CVE-2015-8326 5.5 MEDIUM EPSS 0.00
IPTables-Parse <1.6 - Local File Write
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
CWE-59 Jun 07, 2017
CVE-2015-7514 6.5 MEDIUM EPSS 0.00
OpenStack Ironic <4.2.1 - Info Disclosure
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
CWE-200 Jun 07, 2017
CVE-2016-9834 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Sophos Cyberoam Firmware < 10.6.4 - XSS
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a request to the "LiveConnectionDetail.jsp" application. GET parameters "applicationname" and "username" are improperly sanitized allowing an attacker to inject arbitrary JavaScript into the page. This can be abused by an attacker to perform a cross-site scripting attack on the user. A vulnerable URI is /corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.
CWE-79 Jun 07, 2017
CVE-2017-9474 5.5 MEDIUM EPSS 0.00
ytnef 1.9.2 - DoS
In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CWE-125 Jun 07, 2017
CVE-2017-9473 5.5 MEDIUM EPSS 0.00
ytnef 1.9.2 - DoS
In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
Jun 07, 2017
CVE-2017-9472 5.5 MEDIUM EPSS 0.00
ytnef 1.9.2 - DoS
In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CWE-125 Jun 07, 2017
CVE-2017-9471 5.5 MEDIUM EPSS 0.00
ytnef 1.9.2 - DoS
In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CWE-125 Jun 07, 2017