CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,896 CVEs tracked 53,334 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,053 vendors 42,729 researchers
111,280 results Clear all
CVE-2017-7359 6.1 MEDIUM EPSS 0.00
Pixie 1.0.4 - XSS
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
CWE-79 Mar 31, 2017
CVE-2017-7309 4.8 MEDIUM EPSS 0.02
MantisBT - XSS
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter. This is fixed in 1.3.9, 2.1.3, and 2.2.3.
CWE-79 Mar 31, 2017
CVE-2017-7241 4.8 MEDIUM EPSS 0.01
MantisBT - XSS
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this vulnerability is not exploitable if the admin tools directory is removed, as recommended in the "Post-installation and upgrade tasks" of the MantisBT Admin Guide. A reminder to do so is also displayed on the login page.
CWE-79 Mar 31, 2017
CVE-2017-6973 4.8 MEDIUM EPSS 0.01
MantisBT - XSS
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.
CWE-79 Mar 31, 2017
CVE-2016-9319 5.9 MEDIUM EPSS 0.00
Trend Micro Enterprise Mobile Security <9.7.1193 - Info Disclosure
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
CWE-295 Mar 31, 2017
CVE-2017-7346 5.5 MEDIUM EPSS 0.00
Linux kernel <4.10.7 - DoS
The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call for a /dev/dri/renderD* device.
CWE-20 Mar 30, 2017
CVE-2017-6184 4.7 MEDIUM EPSS 0.01
Sophos Web Appliance < 4.3.1.1 - Command Injection
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.
CWE-77 Mar 30, 2017
CVE-2017-5184 5.3 MEDIUM EPSS 0.00
NetIQ Sentinel Server <8.0.1 - Info Disclosure
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).
CWE-200 Mar 30, 2017
CVE-2014-9818 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a malformed sun file.
CWE-125 Mar 30, 2017
CVE-2014-9816 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted viff file.
CWE-125 Mar 30, 2017
CVE-2014-9815 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted wpg file.
CWE-20 Mar 30, 2017
CVE-2014-9814 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted wpg file.
CWE-476 Mar 30, 2017
CVE-2014-9813 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted viff file.
CWE-20 Mar 30, 2017
CVE-2014-9812 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted ps file.
CWE-476 Mar 30, 2017
CVE-2014-9811 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
The xwd file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed xwd file.
CWE-20 Mar 30, 2017
CVE-2014-9810 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file.
CWE-20 Mar 30, 2017
CVE-2014-9809 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted xwd image.
CWE-20 Mar 30, 2017
CVE-2014-9808 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted dpc image.
CWE-20 Mar 30, 2017
CVE-2014-9807 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
The pdb coder in ImageMagick allows remote attackers to cause a denial of service (double free) via unspecified vectors.
CWE-415 Mar 30, 2017
CVE-2014-9806 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (file descriptor consumption) via a crafted file.
CWE-20 Mar 30, 2017