Exploit Intelligence Platform

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,076 CVEs tracked 53,339 with exploits 4,745 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,076 vendors 42,752 researchers
111,366 results Clear all
CVE-2017-6617 5.4 MEDIUM EPSS 0.00
Cisco Integrated Management Controlle... - Authentication Bypass
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not assign a new session identifier to a user session when a user authenticates to the web-based GUI. An attacker could exploit this vulnerability by using a hijacked session identifier to connect to the software through the web-based GUI. A successful exploit could allow the attacker to hijack an authenticated user's browser session on the affected system. Cisco Bug IDs: CSCvd14583.
CWE-287 Apr 20, 2017
CVE-2017-6615 6.3 MEDIUM EPSS 0.00
Cisco Ios XE - Race Condition
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that could occur when the affected software processes an SNMP read request that contains certain criteria for a specific object ID (OID) and an active crypto session is disconnected on an affected device. An attacker who can authenticate to an affected device could trigger this vulnerability by issuing an SNMP request for a specific OID on the device. A successful exploit will cause the device to restart due to an attempt to access an invalid memory region. The attacker does not control how or when crypto sessions are disconnected on the device. Cisco Bug IDs: CSCvb94392.
CWE-399 Apr 20, 2017
CVE-2017-6614 6.5 MEDIUM EPSS 0.00
Cisco Findit Network Probe - Information Disclosure
A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authenticated, remote attacker to download and view any system file by using the affected software. The vulnerability is due to the absence of role-based access control (RBAC) for file-download requests that are sent to the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to download and view any system file by using the affected software. Cisco Bug IDs: CSCvd11628.
CWE-200 Apr 20, 2017
CVE-2017-6613 5.8 MEDIUM EPSS 0.00
Cisco Prime Network Registrar - Improper Input Validation
A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS process to momentarily restart, which could lead to a partial denial of service (DoS) condition on the affected system. The vulnerability is due to incomplete DNS packet header validation when the packet is received by the application. An attacker could exploit this vulnerability by sending a malformed DNS packet to the application. An exploit could allow the attacker to cause the DNS process to restart, which could lead to a DoS condition. This vulnerability affects Cisco Prime Network Registrar on all software versions prior to 8.3.5. Cisco Bug IDs: CSCvb55412.
CWE-399 Apr 20, 2017
CVE-2017-6611 6.1 MEDIUM EPSS 0.00
Cisco Prime Infrastructure - XSS
A vulnerability in the web framework code of Cisco Prime Infrastructure 2.2(2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting the malicious code. An exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCuw65830.
CWE-79 Apr 20, 2017
CVE-2017-4969 6.5 MEDIUM EPSS 0.00
Cloud Foundry cf-release <v255 - Privilege Escalation
The Cloud Controller in Cloud Foundry cf-release versions prior to v255 allows authenticated developer users to exceed memory and disk quotas for tasks.
Apr 20, 2017
CVE-2017-3793 4.0 MEDIUM EPSS 0.00
Cisco ASA/Firepower <9.6 - DoS
A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 through 8.7 and 9.0 through 9.6) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause Cisco ASA and FTD to drop any further incoming traffic on all interfaces, resulting in a denial of service (DoS) condition. The vulnerability is due to improper limitation of the global out-of-order TCP queue for specific block sizes. An attacker could exploit this vulnerability by sending a large number of unique permitted TCP connections with out-of-order segments. An exploit could allow the attacker to exhaust available blocks in the global out-of-order TCP queue, causing the dropping of any further incoming traffic on all interfaces and resulting in a DoS condition. Cisco Bug IDs: CSCvb46321.
CWE-399 Apr 20, 2017
CVE-2016-9980 5.4 MEDIUM EPSS 0.00
IBM Curam Social Program Management - XSS
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120256.
CWE-79 Apr 20, 2017
CVE-2016-9979 5.4 MEDIUM EPSS 0.00
IBM Curam Social Program Management - XSS
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120255.
CWE-79 Apr 20, 2017
CVE-2016-9978 4.3 MEDIUM EPSS 0.00
IBM Curam Social Program Management - Information Disclosure
IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.
CWE-200 Apr 20, 2017
CVE-2016-8923 4.3 MEDIUM EPSS 0.00
IBM Curam Social Program Management <7.0 - Info Disclosure
IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.
CWE-200 Apr 20, 2017
CVE-2016-3733 4.3 MEDIUM EPSS 0.00
Moodle <3.0.3-<2.8.11 - Privilege Escalation
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
CWE-284 Apr 20, 2017
CVE-2016-3732 4.3 MEDIUM EPSS 0.00
Moodle <3.0.3, <2.9.5, <2.8.11, <2.7.13 - Info Disclosure
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.
CWE-200 Apr 20, 2017
CVE-2016-3731 5.3 MEDIUM EPSS 0.00
Moodle <3.0.3, <2.9.5, <2.8.11 - Info Disclosure
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.
CWE-200 Apr 20, 2017
CVE-2016-3729 6.5 MEDIUM EPSS 0.00
Moodle <3.0.3, <2.9.5, <2.8.11, <2.7.13 - Privilege Escalation
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.
CWE-284 Apr 20, 2017
CVE-2017-5160 5.3 MEDIUM EPSS 0.00
Aveva Wonderware Intouch Access Anywhere < 11.5.2 - Weak Encryption
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.
CWE-326 Apr 20, 2017
CVE-2017-5183 6.1 MEDIUM EPSS 0.00
NetIQ Access Manager <4.3.1+ - XSS
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
CWE-79 Apr 20, 2017
CVE-2017-2806 4.3 MEDIUM EPSS 0.00
Lexmark Perceptive Document Filters - Out-of-Bounds Read
An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 11.3.0.2228 and 11.3.0.2400
CWE-125 Apr 20, 2017
CVE-2016-7540 6.5 MEDIUM 1 Writeup EPSS 0.01
Imagemagick < 6.9.4-9 - Denial of Service
coders/rgf.c in ImageMagick before 6.9.4-10 allows remote attackers to cause a denial of service (assertion failure) by converting an image to rgf format.
CWE-19 Apr 20, 2017
CVE-2016-7538 6.5 MEDIUM 1 Writeup EPSS 0.01
Imagemagick - Out-of-Bounds Write
coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.
CWE-787 Apr 20, 2017