CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,933 CVEs tracked 53,338 with exploits 4,743 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,062 vendors 42,736 researchers
111,303 results Clear all
CVE-2016-1517 5.5 MEDIUM EPSS 0.00
OpenCV 3.0.0 - DoS
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
CWE-20 Apr 10, 2017
CVE-2015-8276 5.5 MEDIUM EPSS 0.00
LVRTC eParakstitajs <3.0 - Info Disclosure
LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to read arbitrary files via crafted EDOC files.
CWE-200 Apr 10, 2017
CVE-2015-8275 5.5 MEDIUM EPSS 0.00
LVRTC eParakstitajs <3.0 - Code Injection
LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC files.
CWE-284 Apr 10, 2017
CVE-2015-7275 6.1 MEDIUM EPSS 0.00
Dell Integrated Remote Access Controller Firmware < 2.21.21.21 - XSS
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
CWE-79 Apr 10, 2017
CVE-2015-6035 6.1 MEDIUM EPSS 0.00
Opsview <2015-11-06 - XSS
Opsview before 2015-11-06 has XSS via SNMP.
CWE-79 Apr 10, 2017
CVE-2015-6027 6.1 MEDIUM EPSS 0.00
Castle Rock Computing SNMPc <2015-12-17 - XSS
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.
CWE-79 Apr 10, 2017
CVE-2015-6021 6.1 MEDIUM EPSS 0.00
Spiceworks Desktop <2015-12-01 - XSS
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
CWE-79 Apr 10, 2017
CVE-2015-2883 5.4 MEDIUM EPSS 0.00
Philips In.Sight B120/37 - XSS
Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to deviceSettings.php or shareDevice.php.
CWE-79 Apr 10, 2017
CVE-2017-7613 5.5 MEDIUM EPSS 0.01
elfutils <0.168 - DoS
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
CWE-20 Apr 09, 2017
CVE-2017-7612 5.5 MEDIUM EPSS 0.01
elfutils <0.168 - DoS
The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CWE-125 Apr 09, 2017
CVE-2017-7611 5.5 MEDIUM EPSS 0.01
elfutils <0.168 - DoS
The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CWE-125 Apr 09, 2017
CVE-2017-7610 5.5 MEDIUM EPSS 0.01
elfutils <0.168 - DoS
The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CWE-125 Apr 09, 2017
CVE-2017-7609 5.5 MEDIUM EPSS 0.00
elfutils <0.168 - DoS
elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
CWE-20 Apr 09, 2017
CVE-2017-7608 5.5 MEDIUM EPSS 0.00
elfutils <0.168 - DoS
The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CWE-125 Apr 09, 2017
CVE-2017-7607 5.5 MEDIUM EPSS 0.01
Elfutils <0.168 - DoS
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CWE-125 Apr 09, 2017
CVE-2017-7606 6.5 MEDIUM EPSS 0.00
ImageMagick 7.0.5-4 - DoS
coders/rle.c in ImageMagick 7.0.5-4 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
CWE-20 Apr 09, 2017
CVE-2017-7595 5.5 MEDIUM EPSS 0.00
LibTIFF 4.0.7 - DoS
The JPEGSetupEncode function in tiff_jpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.
CWE-369 Apr 09, 2017
CVE-2017-7594 5.5 MEDIUM EPSS 0.00
LibTIFF 4.0.7 - DoS
The OJPEGReadHeaderInfoSecTablesDcTable function in tif_ojpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (memory leak) via a crafted image.
CWE-772 Apr 09, 2017
CVE-2017-7593 5.5 MEDIUM EPSS 0.00
LibTIFF 4.0.7 - Info Disclosure
tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.
CWE-119 Apr 09, 2017
CVE-2017-7591 6.1 MEDIUM EPSS 0.00
OpenIDM <4.0.0-4.5.0 - XSS
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.
CWE-79 Apr 09, 2017