Exploit Intelligence Platform

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,175 CVEs tracked 53,341 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,943 Nuclei templates 49,090 vendors 42,769 researchers
111,409 results Clear all
CVE-2017-2134 6.1 MEDIUM EPSS 0.00
ASSETBASE <8.0 - XSS
Cross-site scripting vulnerability in ASSETBASE 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2017
CVE-2017-2127 5.4 MEDIUM EPSS 0.00
YOP Poll <5.8.1 - XSS
Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2017
CVE-2017-2124 6.1 MEDIUM EPSS 0.00
OneThird CMS <1.73 - XSS
Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via contact.php.
CWE-79 Apr 28, 2017
CVE-2017-2123 6.1 MEDIUM EPSS 0.00
OneThird CMS <1.73 - XSS
Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via language.php.
CWE-79 Apr 28, 2017
CVE-2017-2118 6.1 MEDIUM EPSS 0.00
WBCE CMS <1.1.10 - XSS
Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2017
CVE-2017-2117 4.9 MEDIUM EPSS 0.02
CubeCart <6.1.5 - Path Traversal
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.
CWE-22 Apr 28, 2017
CVE-2017-2116 4.3 MEDIUM EPSS 0.00
Cybozu Office 10.0.0-10.5.0 - Auth Bypass
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.
Apr 28, 2017
CVE-2017-2115 4.3 MEDIUM EPSS 0.00
Cybozu Office 10.0.0-10.5.0 - Auth Bypass
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.
CWE-732 Apr 28, 2017
CVE-2017-2114 5.4 MEDIUM EPSS 0.00
Cybozu Office 10.0.0-10.5.0 - XSS
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2017
CVE-2017-2111 6.1 MEDIUM EPSS 0.00
TS-* - Info Disclosure
HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier may allow a remote attackers to display false information.
CWE-93 Apr 28, 2017
CVE-2017-2110 5.9 MEDIUM EPSS 0.00
Access CX App <2.0.0.1-2.0.2 - Info Disclosure
The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-295 Apr 28, 2017
CVE-2017-2106 6.1 MEDIUM EPSS 0.00
Webmin <1.830 - XSS
Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Apr 28, 2017
CVE-2017-2105 5.9 MEDIUM EPSS 0.00
TVer App <3.2.7 - Info Disclosure
The TVer App for Android 3.2.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-200 Apr 28, 2017
CVE-2017-2104 5.9 MEDIUM EPSS 0.00
Business LaLa Call App <1.4.7 - Info Disclosure
The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-200 Apr 28, 2017
CVE-2017-2103 5.9 MEDIUM EPSS 0.00
LaLa Call App <2.4.7 - Info Disclosure
The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-200 Apr 28, 2017
CVE-2017-2100 6.3 MEDIUM EPSS 0.00
AppGoat <V3.0.1 - SSRF
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.1 and earlier allows remote attackers to conduct DNS rebinding attacks via unspecified vectors.
CWE-20 Apr 28, 2017
CVE-2017-2099 6.3 MEDIUM EPSS 0.00
AppGoat <V3.0.0 - RCE
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote code execution via unspecified vectors.
Apr 28, 2017
CVE-2017-2098 6.5 MEDIUM EPSS 0.02
CubeCart <6.1.4 - Path Traversal
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
CWE-22 Apr 28, 2017
CVE-2017-2095 4.3 MEDIUM EPSS 0.00
Cybozu Garoon <4.2.3 - Auth Bypass
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in the mail function leading to an alteration of the order of mail folders via unspecified vectors.
Apr 28, 2017
CVE-2017-2094 4.3 MEDIUM EPSS 0.00
Cybozu Garoon <4.2.3 - Auth Bypass
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.
CWE-269 Apr 28, 2017