Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,281 CVEs tracked 53,347 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,115 vendors 42,789 researchers
111,437 results Clear all
CVE-2017-9210 5.5 MEDIUM EPSS 0.00
QPDF 6.0.0 - DoS
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop3.
CWE-835 May 23, 2017
CVE-2017-9209 5.5 MEDIUM EPSS 0.00
QPDF 6.0.0 - DoS
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2.
CWE-835 May 23, 2017
CVE-2017-9208 5.5 MEDIUM EPSS 0.00
QPDF 6.0.0 - DoS
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infiniteloop1.
CWE-835 May 23, 2017
CVE-2017-9207 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageWorsener 1.3.1 - DoS
The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image, related to imagew-jpeg.c.
CWE-125 May 23, 2017
CVE-2017-9206 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageWorsener 1.3.1 - DoS
The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image, related to imagew-jpeg.c.
CWE-125 May 23, 2017
CVE-2017-9205 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageWorsener 1.3.1 - DoS
The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted image, related to imagew-jpeg.c.
CWE-125 May 23, 2017
CVE-2017-9204 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageWorsener 1.3.1 - DoS
The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted image, related to imagew-jpeg.c.
CWE-125 May 23, 2017
CVE-2017-9203 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageWorsener 1.3.1 - DoS
imagew-main.c:960:12 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (buffer underflow) via a crafted image, related to imagew-bmp.c.
CWE-787 May 23, 2017
CVE-2017-9202 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageWorsener 1.3.1 - DoS
imagew-cmd.c:854:45 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted image, related to imagew-api.c.
CWE-369 May 23, 2017
CVE-2017-9201 6.5 MEDIUM 1 Writeup EPSS 0.00
ImageWorsener 1.3.1 - DoS
imagew-cmd.c:850:46 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted image, related to imagew-api.c.
CWE-369 May 23, 2017
CVE-2017-8379 6.5 MEDIUM EPSS 0.00
Qemu < 2.9.1 - Resource Leak
Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
CWE-772 May 23, 2017
CVE-2017-7288 6.1 MEDIUM EPSS 0.00
Zimbra Collaboration Suite <8.7.1 - XSS
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 May 23, 2017
CVE-2017-5870 5.4 MEDIUM EPSS 0.00
Vimbadmin - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter to domain/add; the (3) name parameter to mailbox/add/did/<domain id>; the (4) goto parameter to alias/add/did/<domain id>; or the (5) captchatext parameter to auth/lost-password.
CWE-79 May 23, 2017
CVE-2016-7977 5.5 MEDIUM EPSS 0.01
Artifex Ghostscript < 9.20 - Information Disclosure
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.
CWE-200 May 23, 2017
CVE-2015-8477 6.1 MEDIUM EPSS 0.00
Redmine <2.6.2 - XSS
Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering.
CWE-79 May 23, 2017
CVE-2015-5382 6.5 MEDIUM 1 Writeup EPSS 0.01
Roundcube Webmail <1.0.6, <1.1.2 - Info Disclosure
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
CWE-200 May 23, 2017
CVE-2015-5381 6.1 MEDIUM 1 Writeup EPSS 0.01
Roundcube Webmail <1.1.2 - XSS
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
CWE-79 May 23, 2017
CVE-2015-4045 6.7 MEDIUM EPSS 0.00
Alienvault Open Source Security Infor... - Access Control
The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script.
CWE-264 May 23, 2017
CVE-2017-9150 5.5 MEDIUM 1 PoC Analysis EPSS 0.01
Linux kernel <4.11.1 - Info Disclosure
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address information via crafted bpf system calls.
CWE-200 May 22, 2017
CVE-2017-1320 5.4 MEDIUM EPSS 0.00
IBM Tivoli Federated Identity Manager 6.2 - XSS
IBM Tivoli Federated Identity Manager 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125732.
CWE-79 May 22, 2017