Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,380 CVEs tracked 53,349 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,139 vendors 42,810 researchers
111,437 results Clear all
CVE-2017-9420 6.1 MEDIUM EPSS 0.00
Spiffy Calendar <3.3.0 - XSS
Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.
CWE-79 Jun 05, 2017
CVE-2017-9440 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.5-5 - DoS
In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPSDChannel in coders/psd.c, which allows attackers to cause a denial of service via a crafted file.
CWE-772 Jun 05, 2017
CVE-2017-9439 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.5-5 - Memory Corruption
In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to cause a denial of service via a crafted file.
CWE-772 Jun 05, 2017
CVE-2017-9434 5.3 MEDIUM 1 Writeup EPSS 0.00
Crypto++ <5.6.5 - Info Disclosure
Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.
CWE-125 Jun 05, 2017
CVE-2017-8840 5.3 MEDIUM 1 PoC Analysis EPSS 0.04
Peplink B305hw2 Firmware - Information Disclosure
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted syncid.
CWE-200 Jun 05, 2017
CVE-2017-8839 6.1 MEDIUM 1 PoC Analysis EPSS 0.02
Peplink B305hw2 Firmware - XSS
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/preview.cgi.
CWE-79 Jun 05, 2017
CVE-2017-8838 6.1 MEDIUM 1 PoC Analysis EPSS 0.02
Peplink B305hw2 Firmware - XSS
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/HASync/hasync.cgi.
CWE-79 Jun 05, 2017
CVE-2017-8441 4.3 MEDIUM EPSS 0.00
Elastic X-pack < 5.3.3 - Information Disclosure
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.
CWE-200 Jun 05, 2017
CVE-2017-8440 6.1 MEDIUM EPSS 0.00
Elastic Kibana - XSS
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CWE-79 Jun 05, 2017
CVE-2017-8439 6.1 MEDIUM EPSS 0.00
Elastic Kibana - XSS
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.
CWE-79 Jun 05, 2017
CVE-2017-1000367 6.4 MEDIUM EXPLOITED 6 PoCs Analysis EPSS 0.19
Todd Miller's sudo <1.8.20 - Info Disclosure & Command Execution
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
CWE-362 Jun 05, 2017
CVE-2014-9983 5.5 MEDIUM EPSS 0.00
Rar - Path Traversal
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.
CWE-22 Jun 04, 2017
CVE-2012-6705 6.1 MEDIUM EPSS 0.00
Jamroom < 4.2.6 - XSS
Cross Site Scripting (XSS) exists in Jamroom before 4.2.7 via the Status Update field.
CWE-79 Jun 04, 2017
CVE-2017-9416 6.5 MEDIUM NUCLEI EPSS 0.50
Odoo <10.0 - Path Traversal
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.
CWE-22 Jun 04, 2017
CVE-2017-3740 5.5 MEDIUM EPSS 0.00
Lenovo Active Protection System <1.82.0.14 - Privilege Escalation
In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.
Jun 04, 2017
CVE-2017-9409 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.5-5 - DoS
In ImageMagick 7.0.5-5, the ReadMPCImage function in mpc.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Jun 02, 2017
CVE-2017-9408 6.5 MEDIUM EPSS 0.01
Poppler 0.54.0 - DoS
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.
CWE-772 Jun 02, 2017
CVE-2017-9407 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.5-5 - DoS
In ImageMagick 7.0.5-5, the ReadPALMImage function in palm.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Jun 02, 2017
CVE-2017-9406 6.5 MEDIUM EPSS 0.01
Poppler 0.54.0 - Memory Corruption
In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.
CWE-772 Jun 02, 2017
CVE-2017-9405 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.5-5 - DoS
In ImageMagick 7.0.5-5, the ReadICONImage function in icon.c:452 allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Jun 02, 2017