Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,281 CVEs tracked 53,347 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,945 Nuclei templates 49,115 vendors 42,789 researchers
111,422 results Clear all
CVE-2017-9038 5.5 MEDIUM EPSS 0.00
GNU Binutils 2.28 - DoS
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in elfcomm.c, the get_unwind_section_word function in readelf.c, and ARM unwind information that contains invalid word offsets.
CWE-125 May 18, 2017
CVE-2017-4017 5.3 MEDIUM EPSS 0.00
McAfee NDLP <9.3 - Info Disclosure
User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via the appliance web interface.
CWE-200 May 17, 2017
CVE-2017-4016 5.3 MEDIUM EPSS 0.00
McAfee NDLP <9.3.x - Info Disclosure
Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to exploit and find another hole via HTTP response header.
CWE-200 May 17, 2017
CVE-2017-4015 4.5 MEDIUM EPSS 0.00
McAfee NDLP <9.3.x - XSS
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
CWE-1021 May 17, 2017
CVE-2017-4013 5.3 MEDIUM EPSS 0.00
McAfee NDLP <9.3.x - Info Disclosure
Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP response header.
CWE-200 May 17, 2017
CVE-2017-4012 6.5 MEDIUM EPSS 0.00
McAfee NDLP <9.3.x - Privilege Escalation
Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via modification of the HTTP request.
May 17, 2017
CVE-2017-4011 6.1 MEDIUM NUCLEI EPSS 0.11
McAfee NDLP <9.3.x - XSS
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.
CWE-79 May 17, 2017
CVE-2016-10374 5.5 MEDIUM EPSS 0.00
Perltidy < 2016-03-02 - Symlink Following
perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users to overwrite arbitrary files by creating a symlink, as demonstrated by creating a perltidy.ERR symlink that the victim cannot delete.
CWE-59 May 17, 2017
CVE-2015-4070 6.1 MEDIUM EPSS 0.00
WOW NEW Media Wow Moodboard Lite - Open Redirect
Open redirect vulnerability in the proxyimages function in wowproxy.php in the Wow Moodboard Lite plugin 1.1.1.1 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
CWE-601 May 17, 2017
CVE-2015-3998 6.1 MEDIUM EPSS 0.00
Clickfraud-monitoring Adsense-click-fraud-monitoring - XSS
Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary web script or HTML via the query parameter to whois.php.
CWE-79 May 17, 2017
CVE-2017-9025 6.5 MEDIUM EPSS 0.04
HooToo Trip Mate 6 <2.000.030 - Buffer Overflow
Heap buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unauthenticated attackers to control the program counter via a specially crafted HTTP Cookie header.
CWE-119 May 17, 2017
CVE-2017-7488 4.3 MEDIUM EPSS 0.00
Authconfig <6.2.8 - Info Disclosure
Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.
CWE-200 May 16, 2017
CVE-2015-9001 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
In TrustZone an information exposure vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.
CWE-200 May 16, 2017
CVE-2017-8382 4.5 MEDIUM 2 PoCs Analysis EPSS 0.01
Admidio < 4.1-Beta.1 - CSRF
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.
CWE-352 May 16, 2017
CVE-2017-7953 5.4 MEDIUM 1 PoC Analysis EPSS 0.00
Infor Enterprise Asset Management - XSS
INFOR EAM V11.0 Build 201410 has XSS via comment fields.
CWE-79 May 16, 2017
CVE-2016-9750 6.5 MEDIUM EPSS 0.00
IBM Qradar Security Information And E... - Credentials Management
IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.
CWE-255 May 15, 2017
CVE-2016-9735 4.3 MEDIUM EPSS 0.00
IBM Rational Collaborative Lifecycle ... - Information Disclosure
IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781,
CWE-200 May 15, 2017
CVE-2017-8943 5.9 MEDIUM EPSS 0.00
PUMA PUMATRAC <3.0.2 - SSL Man-in-the-Middle
The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 15, 2017
CVE-2017-8942 5.9 MEDIUM EPSS 0.00
Yottamark. Shopwell - Healthy Diet & Grocery Food Scanner - Improper Certificate Validation
The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 15, 2017
CVE-2017-8941 5.9 MEDIUM EPSS 0.00
Interval International <3.5.1 - Info Disclosure
The Interval International app 3.3 through 3.5.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 15, 2017