CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,896 CVEs tracked 53,334 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,053 vendors 42,729 researchers
111,280 results Clear all
CVE-2017-2475 6.1 MEDIUM EPSS 0.01
Apple Safari < 10.1 - XSS
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted use of frames on a web site.
CWE-79 Apr 02, 2017
CVE-2017-2453 6.5 MEDIUM EPSS 0.00
Apple Safari < 10.0.3 - Improper Input Validation
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof FaceTime prompts in the user interface via a crafted web site.
CWE-20 Apr 02, 2017
CVE-2017-2452 4.6 MEDIUM EPSS 0.00
Apple Iphone OS < 10.2.1 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to read text messages on the lock screen via unspecified vectors.
CWE-200 Apr 02, 2017
CVE-2017-2448 5.9 MEDIUM EPSS 0.01
Apple Iphone OS < 10.2.1 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. The issue involves the "Keychain" component. It allows man-in-the-middle attackers to bypass an iCloud Keychain secret protection mechanism by leveraging lack of authentication for OTR packets.
CWE-200 Apr 02, 2017
CVE-2017-2445 6.1 MEDIUM 1 PoC Analysis EPSS 0.01
Apple Safari < 10.0.3 - XSS
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted frame objects.
CWE-79 Apr 02, 2017
CVE-2017-2442 6.5 MEDIUM 1 PoC Analysis EPSS 0.12
Apple Safari < 10.0.3 - Improper Input Validation
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScript Bindings" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
CWE-20 Apr 02, 2017
CVE-2017-2424 6.5 MEDIUM EPSS 0.00
Apple <10.3 - Info Disclosure
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves mishandling of OpenGL shaders in the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory via a crafted web site.
CWE-200 Apr 02, 2017
CVE-2017-2418 6.5 MEDIUM EPSS 0.00
Apple <10.12.4 - Info Disclosure
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Hypervisor" component. It allows guest OS users to obtain sensitive information from the CR8 control register via unspecified vectors.
CWE-200 Apr 02, 2017
CVE-2017-2417 5.5 MEDIUM EPSS 0.01
Apple <10.3, <10.12.4, <10.2, <3.2 - DoS
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to cause a denial of service (infinite recursion) via a crafted image.
CWE-835 Apr 02, 2017
CVE-2017-2414 5.3 MEDIUM EPSS 0.00
Apple <10.3 - Info Disclosure
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "DataAccess" component. It allows remote attackers to access Exchange traffic in opportunistic circumstances by leveraging a mistake in typing an e-mail address.
CWE-20 Apr 02, 2017
CVE-2017-2412 5.9 MEDIUM EPSS 0.00
Apple <10.3 - Info Disclosure
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the-middle attackers to modify the client-server data stream to iTunes sandbox web services by leveraging use of cleartext HTTP.
CWE-319 Apr 02, 2017
CVE-2017-2400 5.3 MEDIUM EPSS 0.00
Apple <10.3 - Info Disclosure
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "SafariViewController" component. It allows attackers to obtain sensitive information by leveraging the SafariViewController's incorrect synchronization of Safari cache clearing.
CWE-200 Apr 02, 2017
CVE-2017-2399 4.6 MEDIUM EPSS 0.00
Apple iOS <10.3 - Info Disclosure
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Pasteboard" component. It allows physically proximate attackers to read the pasteboard by leveraging the use of an encryption key derived only from the hardware UID (rather than that UID in addition to the user passcode).
CWE-326 Apr 02, 2017
CVE-2017-2393 6.1 MEDIUM EPSS 0.00
Apple <10.3 - XSS
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Safari Reader" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site.
CWE-79 Apr 02, 2017
CVE-2017-2391 5.3 MEDIUM EPSS 0.00
Apple Products - Info Disclosure
An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" component. It allows users to bypass iWork PDF password protection by leveraging use of 40-bit RC4.
CWE-326 Apr 02, 2017
CVE-2017-2390 5.5 MEDIUM EPSS 0.00
Apple <10.3 - Local Privilege Escalation
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves symlink mishandling in the "libarchive" component. It allows local users to change arbitrary directory permissions via unspecified vectors.
CWE-59 Apr 02, 2017
CVE-2017-2388 5.5 MEDIUM 2 PoCs Analysis EPSS 0.04
Apple <10.12.4 - DoS
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
CWE-476 Apr 02, 2017
CVE-2017-2386 6.5 MEDIUM EPSS 0.00
Apple <10.3 - SSRF
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Apr 02, 2017
CVE-2017-2385 5.5 MEDIUM EPSS 0.00
Apple <10.1 - Info Disclosure
An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows local users to obtain access to locked keychain items via unspecified vectors.
CWE-200 Apr 02, 2017
CVE-2017-2367 6.5 MEDIUM 1 PoC Analysis EPSS 0.12
Apple <10.3 - SSRF
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Apr 02, 2017