Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,234 CVEs tracked 53,343 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,944 Nuclei templates 49,100 vendors 42,782 researchers
111,409 results Clear all
CVE-2017-8349 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadSFWImage function in sfw.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8348 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadMATImage function in mat.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8347 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadEXRImage function in exr.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8346 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadDCMImage function in dcm.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8345 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadMNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8344 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadPCXImage function in pcx.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8343 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
In ImageMagick 7.0.5-5, the ReadAAIImage function in aai.c allows attackers to cause a denial of service (memory leak) via a crafted file.
CWE-772 Apr 30, 2017
CVE-2017-8339 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Watchguard Panda Antivirus - Memory Corruption
PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriver.
CWE-119 Apr 30, 2017
CVE-2017-8327 6.5 MEDIUM 1 Writeup EPSS 0.00
Entropymine Imageworsener < 1.3.0 - Denial of Service
The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted image.
CWE-400 Apr 29, 2017
CVE-2017-7644 6.5 MEDIUM EPSS 0.00
Palo Alto Networks PAN-OS <6.1.17, <7.0.15, <7.1.9 - Info Disclosure
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541.
CWE-200 Apr 29, 2017
CVE-2017-1141 4.3 MEDIUM EPSS 0.00
IBM Insights Foundation for Energy <1.7 - Info Disclosure
IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.
CWE-200 Apr 28, 2017
CVE-2017-2152 6.8 MEDIUM EPSS 0.00
WNC01WH <1.0.0.9 - Command Injection
WNC01WH firmware 1.0.0.9 and earlier allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.
CWE-78 Apr 28, 2017
CVE-2017-2151 6.1 MEDIUM EPSS 0.00
Booking Calendar <7.1 - XSS
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2017
CVE-2017-2150 5.3 MEDIUM EPSS 0.01
Booking Calendar <7.0 - Path Traversal
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.
CWE-22 Apr 28, 2017
CVE-2017-2148 5.4 MEDIUM EPSS 0.00
WN-AC1167GR <1.04 - XSS
Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2017
CVE-2017-2147 6.1 MEDIUM EPSS 0.00
WP Statistics <12.0.4 - XSS
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2017
CVE-2017-2143 5.3 MEDIUM EPSS 0.00
CS-Cart Japanese Edition <4.3.10-jp-1 - Auth Bypass
CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php.
CWE-425 Apr 28, 2017
CVE-2017-2139 5.3 MEDIUM EPSS 0.00
CS-Cart Japanese Edition <4.3.10 - Auth Bypass
CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.
CWE-425 Apr 28, 2017
CVE-2017-2136 6.1 MEDIUM EPSS 0.01
WP Statistics <12.0.4 - XSS
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
CWE-79 Apr 28, 2017
CVE-2017-2135 6.1 MEDIUM EPSS 0.00
WP Statistics <12.0.1 - XSS
Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2017