CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,933 CVEs tracked 53,338 with exploits 4,743 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,062 vendors 42,736 researchers
111,303 results Clear all
CVE-2017-7590 6.1 MEDIUM EPSS 0.00
OpenIDM <4.5.0 - XSS
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name.
CWE-79 Apr 09, 2017
CVE-2017-7589 6.5 MEDIUM EPSS 0.00
OpenIDM <4.5.0 - Info Disclosure
In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the "anonymous" user, as demonstrated by responses with a 200 HTTP status code and a JSON object containing IP address strings. This is related to a missing access-control check in bin/defaults/script/info/login.js.
CWE-200 Apr 09, 2017
CVE-2017-0586 4.7 MEDIUM EPSS 0.00
Linux Kernel - Information Disclosure
An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33649808. References: QC-CR#1097569.
CWE-200 Apr 07, 2017
CVE-2017-0585 4.7 MEDIUM EPSS 0.00
Linux Kernel - Information Disclosure
An information disclosure vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32475556. References: B-RB#112953.
CWE-200 Apr 07, 2017
CVE-2017-0584 4.7 MEDIUM EPSS 0.00
Linux Kernel - Information Disclosure
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32074353. References: QC-CR#1104731.
CWE-200 Apr 07, 2017
CVE-2017-0560 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access data from the previous owner. This issue is rated as Moderate due to the possibility of bypassing device protection. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-30681079.
CWE-200 Apr 07, 2017
CVE-2017-0559 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
An information disclosure vulnerability in libskia could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33897722.
CWE-200 Apr 07, 2017
CVE-2017-0558 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34056274.
CWE-200 Apr 07, 2017
CVE-2017-0557 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34093073.
CWE-200 Apr 07, 2017
CVE-2017-0556 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34093952.
CWE-200 Apr 07, 2017
CVE-2017-0555 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33551775.
CWE-200 Apr 07, 2017
CVE-2017-0552 5.5 MEDIUM EPSS 0.00
Google Android - Denial of Service
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097915.
Apr 07, 2017
CVE-2017-0551 5.5 MEDIUM EPSS 0.00
Google Android - Denial of Service
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097231.
Apr 07, 2017
CVE-2017-0550 5.5 MEDIUM EPSS 0.00
Google Android - Denial of Service
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33933140.
Apr 07, 2017
CVE-2017-0549 5.5 MEDIUM EPSS 0.00
Google Android - Denial of Service
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33818508.
Apr 07, 2017
CVE-2017-0548 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Google Android - Memory Corruption
A remote denial of service vulnerability in libskia could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33251605.
CWE-119 Apr 07, 2017
CVE-2017-0547 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33861560.
CWE-200 Apr 07, 2017
CVE-2017-7586 5.5 MEDIUM 1 Writeup EPSS 0.00
Libsndfile <1.0.28 - Buffer Overflow
In libsndfile before 1.0.28, an error in the "header_read()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.
CWE-119 Apr 07, 2017
CVE-2017-7585 5.5 MEDIUM 1 Writeup EPSS 0.00
libsndfile <1.0.28 - Buffer Overflow
In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.
CWE-119 Apr 07, 2017
CVE-2017-7583 6.1 MEDIUM 1 Writeup EPSS 0.01
ILIAS <5.2.3 - XSS
ILIAS before 5.2.3 has XSS via SVG documents.
CWE-79 Apr 07, 2017