Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,234 CVEs tracked 53,343 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,944 Nuclei templates 49,100 vendors 42,782 researchers
111,409 results Clear all
CVE-2017-8795 6.1 MEDIUM EPSS 0.00
Accellion File Transfer Appliance < 9_12_40 - XSS
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.
CWE-79 May 05, 2017
CVE-2017-8792 6.1 MEDIUM EPSS 0.00
Accellion File Transfer Appliance < 9_12_40 - XSS
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.
CWE-79 May 05, 2017
CVE-2017-8791 6.1 MEDIUM EPSS 0.00
Accellion FTA <FTA_9_12_180 - Auth Bypass
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos/courier/login.html auth_params CRLF attack vector.
CWE-93 May 05, 2017
CVE-2017-8788 6.1 MEDIUM EPSS 0.00
Accellion FTA <FTA_9_12_180 - Info Disclosure
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF vulnerability in settings_global_text_edit.php allowing ?display=x%0Dnewline attacks.
CWE-93 May 05, 2017
CVE-2017-8760 6.1 MEDIUM 1 PoC Analysis EPSS 0.01
Accellion File Transfer Appliance < 9_12_40 - XSS
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.
CWE-79 May 05, 2017
CVE-2017-8304 6.1 MEDIUM EPSS 0.00
Accellion File Transfer Appliance < 9_12_40 - XSS
An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.
CWE-79 May 05, 2017
CVE-2017-8060 5.9 MEDIUM EPSS 0.00
Watchguard Panda Mobile Security - Improper Certificate Validation
Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.
CWE-295 May 05, 2017
CVE-2017-8058 5.9 MEDIUM EPSS 0.00
Atlassian Hipchat < 3.16.1 - Improper Certificate Validation
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.
CWE-295 May 05, 2017
CVE-2017-5919 5.9 MEDIUM EPSS 0.00
21st Century Insurance < 10.0.0 - Improper Certificate Validation
The 21st Century Insurance app 10.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5918 5.9 MEDIUM EPSS 0.00
Banco DE Costa Rica Bcr Movil - Improper Certificate Validation
The Banco de Costa Rica BCR Movil app 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5916 5.9 MEDIUM EPSS 0.00
America's First Federal Credit Union ... - Improper Certificate Validation
The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5915 5.9 MEDIUM EPSS 0.00
Emirates Nbd - Improper Certificate Validation
The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5914 5.9 MEDIUM EPSS 0.00
Dotit-corp Banque Zitouna - Improper Certificate Validation
The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5913 5.9 MEDIUM EPSS 0.00
Tradeking Forex - Improper Certificate Validation
The TradeKing Forex for iPhone app 1.2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5912 5.9 MEDIUM EPSS 0.00
Forextrader - Improper Certificate Validation
The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5911 5.9 MEDIUM EPSS 0.00
Banco Santander Mexico SA Supermovil - Improper Certificate Validation
The Banco Santander Mexico SA Supermovil app 3.5 through 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5909 5.9 MEDIUM EPSS 0.00
Electronic Funds Source Efs Mobile Dr... - Improper Certificate Validation
The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5907 5.9 MEDIUM EPSS 0.00
Great Southern Bank Great Southern Mo... - Improper Certificate Validation
The Great Southern Bank Great Southern Mobile Banking app before 4.0.4 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5906 5.9 MEDIUM EPSS 0.00
Everyday Health Diabetes IN Check - Improper Certificate Validation
The Everyday Health Diabetes in Check: Blood Glucose & Carb Tracker app 3.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017
CVE-2017-5905 5.9 MEDIUM EPSS 0.00
Dollar Bank Mobile - Improper Certificate Validation
The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 May 05, 2017