Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,234 CVEs tracked 53,343 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,944 Nuclei templates 49,100 vendors 42,782 researchers
111,409 results Clear all
CVE-2017-8385 5.3 MEDIUM EPSS 0.00
Craftcms Craft Cms < 2.6.2974 - Password Reset Weakness
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
CWE-640 May 01, 2017
CVE-2017-8384 6.1 MEDIUM EPSS 0.00
Craftcms Craft Cms < 2.6.2974 - XSS
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
CWE-79 May 01, 2017
CVE-2017-8383 5.3 MEDIUM EPSS 0.00
Craft CMS <2.6.2976 - Info Disclosure
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
May 01, 2017
CVE-2017-8374 5.5 MEDIUM EPSS 0.00
Underbit Mad Libmad - Out-of-Bounds Read
The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
CWE-125 May 01, 2017
CVE-2017-8372 4.7 MEDIUM EPSS 0.00
Underbit Mad Libmad - Reachable Assertion
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b, if NDEBUG is omitted, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted audio file.
CWE-617 May 01, 2017
CVE-2016-10351 5.5 MEDIUM EPSS 0.00
Telegram Desktop - Information Disclosure
Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.
CWE-200 May 01, 2017
CVE-2016-10350 5.5 MEDIUM EPSS 0.02
Libarchive - Memory Corruption
The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CWE-119 May 01, 2017
CVE-2016-10349 5.5 MEDIUM EPSS 0.02
Libarchive - Memory Corruption
The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CWE-119 May 01, 2017
CVE-2017-8371 6.8 MEDIUM EPSS 0.00
Schneider-electric Struxureware Data ... - Insufficiently Protected Credentials
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors.
CWE-522 Apr 30, 2017
CVE-2017-8365 6.5 MEDIUM EPSS 0.01
Libsndfile - Out-of-Bounds Read
The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.
CWE-125 Apr 30, 2017
CVE-2017-8363 6.5 MEDIUM EPSS 0.01
Libsndfile - Out-of-Bounds Read
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
CWE-125 Apr 30, 2017
CVE-2017-8362 6.5 MEDIUM EPSS 0.01
Libsndfile - Out-of-Bounds Read
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.
CWE-125 Apr 30, 2017
CVE-2017-8357 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadEPTImage function in ept.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8356 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadSUNImage function in sun.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8355 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadMTVImage function in mtv.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8354 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadBMPImage function in bmp.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8353 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadPICTImage function in pict.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8352 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadXWDImage function in xwd.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8351 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadPCDImage function in pcd.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8350 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadJNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017