Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,380 CVEs tracked 53,349 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,139 vendors 42,810 researchers
111,437 results Clear all
CVE-2017-9470 5.5 MEDIUM EPSS 0.00
ytnef 1.9.2 - DoS
In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
CWE-476 Jun 07, 2017
CVE-2017-9461 6.5 MEDIUM EPSS 0.03
Samba <4.4.10, <4.5.6 - DoS
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
CWE-835 Jun 06, 2017
CVE-2016-9960 5.5 MEDIUM EPSS 0.00
Game-music-emu < 0.6.0 - Divide By Zero
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
CWE-369 Jun 06, 2017
CVE-2016-5004 6.5 MEDIUM 1 Writeup EPSS 0.01
Apache Ws-xmlrpc - Denial of Service
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.
CWE-400 Jun 06, 2017
CVE-2016-3077 6.5 MEDIUM EPSS 0.00
Redhat Ovirt-engine - Memory Corruption
The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.
CWE-119 Jun 06, 2017
CVE-2016-3066 6.5 MEDIUM EPSS 0.00
Spice-gtk - Information Disclosure
The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.
CWE-200 Jun 06, 2017
CVE-2016-2192 6.5 MEDIUM EPSS 0.00
Pl/java < 1.4.3 - Improper Privilege Management
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.
CWE-269 Jun 06, 2017
CVE-2016-0767 6.5 MEDIUM EPSS 0.00
PostgreSQL PL/Java <1.5.0 - Privilege Escalation
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath.
CWE-269 Jun 06, 2017
CVE-2015-3830 6.5 MEDIUM EPSS 0.00
Android - SSRF
The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names.
CWE-20 Jun 06, 2017
CVE-2015-1207 6.5 MEDIUM EPSS 0.00
FFMPEG - Memory Corruption
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
CWE-415 Jun 06, 2017
CVE-2014-8180 5.5 MEDIUM EPSS 0.00
Mongodb - Authentication Bypass
MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.
CWE-287 Jun 06, 2017
CVE-2017-9452 4.8 MEDIUM EPSS 0.00
Piwigo <2.9.0 - XSS
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CWE-79 Jun 06, 2017
CVE-2017-9451 6.1 MEDIUM 1 Writeup EPSS 0.00
flatCore 1.4.6 - XSS
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.
CWE-79 Jun 06, 2017
CVE-2017-8920 6.1 MEDIUM 1 Writeup EPSS 0.00
CGI:IRC <0.5.12 - XSS
irc.cgi in CGI:IRC before 0.5.12 reflects user-supplied input from the R parameter without proper output encoding, aka XSS.
CWE-79 Jun 06, 2017
CVE-2017-9448 5.4 MEDIUM EPSS 0.00
BigTree CMS <4.2.18 - XSS
Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in core\admin\ajax\pages\save-revision.php and core\admin\modules\pages\revisions.php. Low-privileged (administrator) users can attack high-privileged (Developer) users.
CWE-79 Jun 06, 2017
CVE-2017-9332 6.1 MEDIUM EPSS 0.00
PivotX 2.3.11 - XSS
The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag.
CWE-79 Jun 06, 2017
CVE-2017-8083 6.7 MEDIUM EPSS 0.00
Compulab Intense PC Firmware < cr_2.2.0.400.2 - Missing Authorization
CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by leveraging administrative privileges.
CWE-862 Jun 06, 2017
CVE-2017-7515 5.5 MEDIUM EPSS 0.00
poppler <0.55.0 - DoS
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
CWE-674 Jun 06, 2017
CVE-2014-9951 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist.
CWE-200 Jun 06, 2017
CVE-2014-9947 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.
CWE-200 Jun 06, 2017