Exploit Intelligence Platform

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,234 CVEs tracked 53,343 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,944 Nuclei templates 49,100 vendors 42,782 researchers
111,409 results Clear all
CVE-2017-8458 6.5 MEDIUM EPSS 0.00
Brave - Injection
Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://[email protected]/ is displayed without a clear UI indication that it is not a resource on the safe.example.com web site.
CWE-74 May 03, 2017
CVE-2016-10368 6.1 MEDIUM NUCLEI EPSS 0.01
Opsview - Open Redirect
Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the /login URI.
CWE-601 May 03, 2017
CVE-2015-9058 6.1 MEDIUM EPSS 0.00
Proxmox Mail Gateway < 4.0-4\/b38fc5d9 - Open Redirect
Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.
CWE-601 May 03, 2017
CVE-2015-9057 6.1 MEDIUM EPSS 0.00
Proxmox Mail Gateway < 4.0-4\/b38fc5d9 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multiple parameters, related to /users/index.htm, /quarantine/spam/manage.htm, /quarantine/spam/whitelist.htm, /queues/mail/index/, /system/ssh.htm, /queues/mail/?domain=, and /quarantine/virus/manage.htm.
CWE-79 May 03, 2017
CVE-2017-7430 6.1 MEDIUM EPSS 0.01
Novell iManager <2.7 SP7 Patch 10 HF1 & NetIQ iManager <3.0.3.1 - XSS
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
CWE-79 May 03, 2017
CVE-2017-7428 5.3 MEDIUM EPSS 0.00
NetIQ iManager <3.0.3.1 - Info Disclosure
NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.
CWE-20 May 03, 2017
CVE-2017-8421 5.5 MEDIUM EPSS 0.00
GNU Binutils - Resource Leak
The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in dump_relocs_in_section in objdump.c can resolve this.
CWE-772 May 02, 2017
CVE-2017-7216 6.5 MEDIUM EPSS 0.00
Palo Alto Networks PAN-OS <7.1.9 - Info Disclosure
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters.
CWE-200 May 02, 2017
CVE-2017-8112 6.5 MEDIUM EPSS 0.00
Qemu < 2.9.1 - Infinite Loop
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
CWE-835 May 02, 2017
CVE-2017-8086 6.5 MEDIUM EPSS 0.00
Qemu < 2.8.1 - Resource Leak
Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable.
CWE-772 May 02, 2017
CVE-2017-7440 6.5 MEDIUM EPSS 0.00
Kerio Connect <9.2.2 - CSRF
Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.
CWE-1021 May 02, 2017
CVE-2016-5810 4.9 MEDIUM EPSS 0.25
Advantech WebAccess <8.1_20160519 - Info Disclosure
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.
CWE-200 May 02, 2017
CVE-2016-5063 5.3 MEDIUM 2 PoCs Analysis EPSS 0.17
BMC Server Automation < 8.6 - Improper Authorization
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vectors.
CWE-285 May 02, 2017
CVE-2016-4467 5.9 MEDIUM EPSS 0.00
Apache Qpid Proton - Improper Certificate Validation
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when using the SChannel-based security layer, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
CWE-295 May 02, 2017
CVE-2016-4442 5.3 MEDIUM EPSS 0.00
Rack-Mini-Profiler <0.10.1 - Info Disclosure
The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.
CWE-200 May 02, 2017
CVE-2017-8401 6.5 MEDIUM EPSS 0.00
Swftools < 0.9.2 - Out-of-Bounds Read
In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in the function png_load() in lib/png.c:724. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS.
CWE-125 May 01, 2017
CVE-2017-6564 6.5 MEDIUM EPSS 0.00
Franklinfueling Ts-550 Evo Firmware - Missing Authorization
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.
CWE-862 May 01, 2017
CVE-2017-8388 5.3 MEDIUM EPSS 0.00
GeniXCMS 1.0.2 - Auth Bypass
GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.
May 01, 2017
CVE-2017-8376 5.4 MEDIUM EPSS 0.00
Genixcms < 1.1.0 - XSS
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.
CWE-79 May 01, 2017
CVE-2017-5631 6.1 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.25
KMC Information Systems Caseaware - XSS
An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.
CWE-79 May 01, 2017