CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,933 CVEs tracked 53,338 with exploits 4,743 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,062 vendors 42,736 researchers
111,303 results Clear all
CVE-2017-7646 6.5 MEDIUM EPSS 0.01
SolarWinds LEM <6.3.1.4 - Info Disclosure
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.
CWE-200 Apr 10, 2017
CVE-2017-7624 5.5 MEDIUM EPSS 0.00
ImageWorsener 1.3.0 - Memory Corruption
The iw_read_bmp_file function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to consume an amount of available memory via a crafted file.
CWE-772 Apr 10, 2017
CVE-2017-7623 5.5 MEDIUM EPSS 0.00
ImageWorsener 1.3.0 - DoS
The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
CWE-125 Apr 10, 2017
CVE-2017-7377 6.0 MEDIUM EPSS 0.00
QEMU - DoS
The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.
CWE-772 Apr 10, 2017
CVE-2017-7345 5.3 MEDIUM EPSS 0.00
NetApp <7.1P1 - Info Disclosure
NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obtain sensitive information via unspecified vectors.
CWE-200 Apr 10, 2017
CVE-2016-10310 4.9 MEDIUM EPSS 0.03
SAP Sql Anywhere < 17.0 - Memory Corruption
Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remote authenticated users to cause a denial of service (resource consumption and process crash) by sending a crafted packet several times, aka SAP Security Note 2308778.
CWE-119 Apr 10, 2017
CVE-2017-7616 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux kernel <4.10.9 - Info Disclosure
Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation.
CWE-388 Apr 10, 2017
CVE-2016-10304 6.5 MEDIUM EPSS 0.01
SAP Netweaver Application Server Java - Insecure Deserialization
The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka SAP Security Note 2315788.
CWE-502 Apr 10, 2017
CVE-2016-5682 6.1 MEDIUM EPSS 0.00
Swagger-UI <2.2.1 - XSS
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
CWE-79 Apr 10, 2017
CVE-2016-5642 5.4 MEDIUM EPSS 0.00
Opmantek NMIS <8.5.12G - XSS
Opmantek NMIS before 8.5.12G has XSS via SNMP.
CWE-79 Apr 10, 2017
CVE-2016-5078 6.1 MEDIUM EPSS 0.00
Paessler Prtg Network Monitor < 16.2.24.3791 - XSS
Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
CWE-79 Apr 10, 2017
CVE-2016-5077 6.1 MEDIUM EPSS 0.00
Netikus Eventsentry - XSS
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
CWE-79 Apr 10, 2017
CVE-2016-5075 6.1 MEDIUM EPSS 0.00
Cloudviewnms Cloudview Nms < 2.09b - XSS
CloudView NMS before 2.10a has XSS via a TELNET login.
CWE-79 Apr 10, 2017
CVE-2016-5073 6.1 MEDIUM EPSS 0.00
Cloudviewnms Cloudview Nms < 2.09b - XSS
CloudView NMS before 2.10a has XSS via SNMP.
CWE-79 Apr 10, 2017
CVE-2016-5059 6.5 MEDIUM EPSS 0.00
Osram Lightify Pro < - - Information Disclosure
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile/Containers/Data/Application.
CWE-200 Apr 10, 2017
CVE-2016-5055 6.1 MEDIUM EPSS 0.00
Osram Lightify Pro < - - XSS
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.
CWE-79 Apr 10, 2017
CVE-2016-4334 6.1 MEDIUM EPSS 0.00
Jive <2016.3.1 - Open Redirect
Jive before 2016.3.1 has an open redirect from the external-link.jspa page.
CWE-601 Apr 10, 2017
CVE-2016-4320 4.3 MEDIUM EPSS 0.01
Atlassian Bitbucket Server <4.7.1 - Path Traversal
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.
CWE-22 Apr 10, 2017
CVE-2016-4318 4.8 MEDIUM EPSS 0.00
Atlassian JIRA Server <7.1.9 - XSS
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
CWE-79 Apr 10, 2017
CVE-2016-4317 5.4 MEDIUM EPSS 0.00
Atlassian Confluence Server <5.9.11 - XSS
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
CWE-79 Apr 10, 2017