Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,234 CVEs tracked 53,343 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,944 Nuclei templates 49,100 vendors 42,782 researchers
111,409 results Clear all
CVE-2017-8879 6.8 MEDIUM EPSS 0.00
Dolibarr ERP/CRM <4.0.4 - Info Disclosure
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.
CWE-287 May 10, 2017
CVE-2017-7887 6.1 MEDIUM EPSS 0.00
Dolibarr Erp/crm - XSS
Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.
CWE-79 May 10, 2017
CVE-2016-6037 4.8 MEDIUM EPSS 0.00
IBM Rational Team Concert - XSS
IBM Rational Team Concert (RTC) is vulnerable to HTML injection. A remote attacker with project administrator privileges could send a project that contains malicious HTML code, which when the project is viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 116918.
CWE-79 May 10, 2017
CVE-2016-6035 5.4 MEDIUM EPSS 0.00
IBM Rational Quality Manager - XSS
IBM Rational Quality Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116896.
CWE-79 May 10, 2017
CVE-2016-5888 5.4 MEDIUM EPSS 0.00
IBM Interact <10.0 - XSS
IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 115084.
CWE-79 May 10, 2017
CVE-2016-3032 5.4 MEDIUM EPSS 0.00
IBM Cognos Analytics - XSS
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114516.
CWE-79 May 10, 2017
CVE-2017-8878 6.5 MEDIUM EPSS 0.00
ASUS RT-AC*-RT-N* <3.0.0.4.380.7378 - Info Disclosure
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.
CWE-200 May 10, 2017
CVE-2017-8877 6.5 MEDIUM EXPLOITED EPSS 0.00
ASUS RT-AC*-RT-N* <3.0.0.4.380.7378 - Info Disclosure
ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.
CWE-200 May 10, 2017
CVE-2017-8876 6.1 MEDIUM 1 Writeup EPSS 0.00
Symphony 2 <2.6.11 - XSS
Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.
CWE-79 May 10, 2017
CVE-2017-8875 6.5 MEDIUM EPSS 0.00
Codection Clean Login - CSRF
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
CWE-352 May 10, 2017
CVE-2016-10371 5.5 MEDIUM EPSS 0.00
Libtiff - Improper Input Validation
The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file.
CWE-20 May 10, 2017
CVE-2017-0355 5.5 MEDIUM EPSS 0.00
Nvidia Gpu Driver - Improper Input Validation
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where it may access paged memory while holding a spinlock, leading to a denial of service.
CWE-20 May 09, 2017
CVE-2017-0354 4.7 MEDIUM EPSS 0.00
Nvidia Gpu Driver - Improper Input Validation
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where a call to certain function requiring lower IRQL can be made under raised IRQL which may lead to a denial of service.
CWE-20 May 09, 2017
CVE-2017-0353 5.5 MEDIUM EPSS 0.00
Nvidia Gpu Driver - Improper Input Validation
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking on certain conditions may lead to a denial of service
CWE-20 May 09, 2017
CVE-2017-5527 4.3 MEDIUM EPSS 0.00
Tibco Spotfire Analytics Platform For Aws < 7.8.0 - SQL Injection
TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerabilities which may allow authorized users to perform SQL injection attacks.
CWE-89 May 09, 2017
CVE-2017-7967 5.5 MEDIUM EPSS 0.00
Schneider-electric Vampset < 2.2.185 - Memory Corruption
All versions of VAMPSET software produced by Schneider Electric, prior to V2.2.189, are susceptible to a memory corruption vulnerability when a corrupted vf2 file is used. This vulnerability causes the software to halt or not start when trying to open the corrupted file. This vulnerability occurs when fill settings are intentionally malformed and is opened in a standalone state, without connection to a protection relay. This attack is not considered to be remotely exploitable. This vulnerability has no effect on the operation of the protection relay to which VAMPSET is connected. As Windows operating system remains operational and VAMPSET responds, it is able to be shut down through its normal closing protocol.
CWE-119 May 09, 2017
CVE-2017-6137 5.9 MEDIUM EPSS 0.01
F5 BIG-IP - DoS
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, and WebSafe 11.6.1 HF1, 12.0.0 HF3, 12.0.0 HF4, and 12.1.0 through 12.1.2, undisclosed traffic patterns received while software SYN cookie protection is engaged may cause a disruption of service to the Traffic Management Microkernel (TMM) on specific platforms and configurations.
May 09, 2017
CVE-2017-0302 5.3 MEDIUM EPSS 0.00
F5 BIG-IP APM <13.1.2 - DoS
In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if the length of the requested URL is less than 16 characters.
CWE-118 May 09, 2017
CVE-2016-9257 6.1 MEDIUM EPSS 0.00
F5 BIG-IP APM <12.1.2 - XSS
In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when the Administrative user is viewing the Access System Logs, allowing the non-authenticated user to carry out a Cross Site Scripting (XSS) attack against the Administrative user.
CWE-79 May 09, 2017
CVE-2017-0894 4.3 MEDIUM EPSS 0.01
Nextcloud Server <11.0.3 - Info Disclosure
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
CWE-285 May 08, 2017