CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,896 CVEs tracked 53,334 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,053 vendors 42,729 researchers
111,280 results Clear all
CVE-2016-7585 6.8 MEDIUM EPSS 0.00
Apple Mac OS X < 10.12.3 - Cryptographic Issue
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.
CWE-310 Apr 02, 2017
CVE-2017-7395 6.5 MEDIUM EPSS 0.00
TigerVNC 1.7.1 - Memory Corruption
In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.
CWE-190 Apr 01, 2017
CVE-2017-7391 6.1 MEDIUM EXPLOITED NUCLEI EPSS 0.09
Magmi 0.7.22 - XSS
A Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The vulnerability exists due to insufficient filtration of user-supplied data (prefix) passed to the 'magmi-git-master/magmi/web/ajax_gettime.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Apr 01, 2017
CVE-2017-7390 6.1 MEDIUM EPSS 0.00
SocialNetwork v1.2.1 - XSS
A Cross-Site Scripting (XSS) was discovered in 'SocialNetwork v1.2.1'. The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the 'SocialNetwork-andrea/app/template/pw_forgot.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Apr 01, 2017
CVE-2017-7389 6.1 MEDIUM EPSS 0.00
openeclass Release_3.5.4 - XSS
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Apr 01, 2017
CVE-2017-7388 6.1 MEDIUM EPSS 0.00
Wallacepos v1.4.1 - XSS
A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtration of user-supplied data (token) passed to the 'wallacepos-master/myaccount/resetpassword.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Apr 01, 2017
CVE-2017-7387 6.1 MEDIUM EPSS 0.00
TheFirstQuestion/HelpMeWatchWho <2017-03-28 - XSS
TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID parameter).
CWE-79 Apr 01, 2017
CVE-2017-7386 6.1 MEDIUM EPSS 0.00
citymont/symetrie <0.9.6 - XSS
citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in symetrie-master/app/commands/page.php (model parameter).
CWE-79 Apr 01, 2017
CVE-2017-1171 4.3 MEDIUM EPSS 0.00
IBM TRIRIGA App Plat <3.3-3.5 - Privilege Escalation
The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to. IBM Reference #: 2001083.
Mar 31, 2017
CVE-2017-1154 6.5 MEDIUM EPSS 0.00
IBM Algorithmics One-Algo Risk App <5.1.0 - Info Disclosure
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892.
CWE-200 Mar 31, 2017
CVE-2016-9990 6.1 MEDIUM EPSS 0.00
IBM Inotes - XSS
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998824.
CWE-79 Mar 31, 2017
CVE-2016-8935 5.4 MEDIUM EPSS 0.00
IBM Kenexa LMS on Cloud <14.0.0 - XSS
IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999483.
CWE-79 Mar 31, 2017
CVE-2016-6036 5.4 MEDIUM EPSS 0.00
IBM Rational Quality Manager <6.0 - XSS
IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.
CWE-79 Mar 31, 2017
CVE-2016-6031 5.4 MEDIUM EPSS 0.00
IBM Rational Quality Manager <6.0 - XSS
IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.
CWE-79 Mar 31, 2017
CVE-2016-6022 5.4 MEDIUM EPSS 0.00
IBM Quality Manager <6.0 - XSS
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.
CWE-79 Mar 31, 2017
CVE-2016-6209 6.1 MEDIUM EPSS 0.01
Nagios - XSS
Cross-site scripting (XSS) vulnerability in Nagios.
CWE-79 Mar 31, 2017
CVE-2017-7363 6.1 MEDIUM EPSS 0.00
Pixie 1.0.4 - XSS
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.
CWE-79 Mar 31, 2017
CVE-2017-7362 6.1 MEDIUM EPSS 0.00
Pixie 1.0.4 - XSS
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
CWE-79 Mar 31, 2017
CVE-2017-7361 6.1 MEDIUM EPSS 0.00
Pixie 1.0.4 - XSS
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
CWE-79 Mar 31, 2017
CVE-2017-7360 6.1 MEDIUM EPSS 0.00
Pixie 1.0.4 - XSS
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
CWE-79 Mar 31, 2017