CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,933 CVEs tracked 53,338 with exploits 4,743 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,062 vendors 42,736 researchers
111,303 results Clear all
CVE-2017-0164 4.4 MEDIUM EPSS 0.05
Microsoft Windows 10 - Improper Input Validation
A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability."
CWE-20 Apr 12, 2017
CVE-2017-0058 4.7 MEDIUM 1 PoC Analysis EPSS 0.16
Microsoft Windows 10 - Information Disclosure
A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability."
CWE-200 Apr 12, 2017
CVE-2017-7697 5.5 MEDIUM EPSS 0.00
Libsamplerate <0.1.9 - Buffer Overflow
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
CWE-125 Apr 11, 2017
CVE-2015-8613 6.5 MEDIUM EPSS 0.00
QEMU - Buffer Overflow
Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO command.
CWE-787 Apr 11, 2017
CVE-2015-8568 6.5 MEDIUM EPSS 0.00
QEMU - DoS
Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.
CWE-772 Apr 11, 2017
CVE-2015-8504 6.5 MEDIUM EPSS 0.03
Qemu - DoS
Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.
CWE-369 Apr 11, 2017
CVE-2014-9837 6.5 MEDIUM EPSS 0.00
ImageMagick <6.9.0-1 - DoS
coders/pnm.c in ImageMagick 6.9.0-1 Beta and earlier allows remote attackers to cause a denial of service (crash) via a crafted png file.
CWE-125 Apr 11, 2017
CVE-2014-8716 6.2 MEDIUM EPSS 0.00
ImageMagick <6.8.9-9 - DoS
The JPEG decoder in ImageMagick before 6.8.9-9 allows local users to cause a denial of service (out-of-bounds memory access and crash).
CWE-125 Apr 11, 2017
CVE-2014-8562 5.5 MEDIUM EPSS 0.00
Imagemagick < 6.8.9-8 - Out-of-Bounds Read
DCM decode in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
CWE-125 Apr 11, 2017
CVE-2014-8355 5.5 MEDIUM EPSS 0.00
Imagemagick < 6.8.9-8 - Out-of-Bounds Read
PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
CWE-125 Apr 11, 2017
CVE-2014-8354 6.5 MEDIUM EPSS 0.01
Imagemagick < 6.8.9-8 - Out-of-Bounds Read
The HorizontalFilter function in resize.c in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
CWE-125 Apr 11, 2017
CVE-2016-5322 5.5 MEDIUM EPSS 0.00
Libtiff < 4.0.6 - Out-of-Bounds Read
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
CWE-125 Apr 11, 2017
CVE-2017-5969 4.7 MEDIUM EPSS 0.03
Xmlsoft Libxml2 - NULL Pointer Dereference
libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.
CWE-476 Apr 11, 2017
CVE-2017-7461 4.9 MEDIUM 1 PoC Analysis EPSS 0.08
Intellinet NFC-30ir IP Camera <LM.1.6.16.05 - Path Traversal
Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI script that is used to read HTML text file, but that does not do any URI/path sanitization.
CWE-22 Apr 11, 2017
CVE-2017-5873 6.7 MEDIUM EPSS 0.00
Unisys s-Par <4.4.20 - Privilege Escalation
Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.
CWE-428 Apr 11, 2017
CVE-2017-5672 6.5 MEDIUM EPSS 0.00
Kony Enterprise Mobile Management < 4.2.0 - Information Disclosure
Kony Enterprise Mobile Management (EMM) before 4.2.5.2 has the vulnerability of disclosing the private key in clear-text when changing the parameters of the request.
CWE-200 Apr 11, 2017
CVE-2016-5011 4.6 MEDIUM EPSS 0.00
Kernel Util-linux < 2.28 - Denial of Service
The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.
Apr 11, 2017
CVE-2016-7467 5.3 MEDIUM EPSS 0.02
F5 Big-ip Access Policy Manager - Improper Input Validation
The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML Identity Provider with a Service Provider (SP) connector, might allow traffic to be disrupted or failover initiated when a malformed, signed SAML authentication request from an authenticated user is sent via the SP connector.
CWE-20 Apr 11, 2017
CVE-2016-10259 5.9 MEDIUM EPSS 0.00
Bluecoat SSL Visibility Appliance Sv1... - Resource Management Error
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections. A malicious SSL client can, under certain circumstances, temporarily exhaust the TCP connection pool of an SSL server.
CWE-399 Apr 11, 2017
CVE-2017-7621 6.1 MEDIUM EPSS 0.00
AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 - XSS
Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different end user via the page parameter to code/student_portal/home.php. The affected versions are eMLi School Management 1.0, eMLi College Campus Management 1.0, and eMLi University Management 1.0.
CWE-79 Apr 11, 2017