CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,896 CVEs tracked 53,334 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,053 vendors 42,729 researchers
111,280 results Clear all
CVE-2014-9805 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted pnm file.
CWE-20 Mar 30, 2017
CVE-2016-7542 4.9 MEDIUM EPSS 0.00
Fortinet Fortios - Information Disclosure
A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.
CWE-200 Mar 30, 2017
CVE-2016-7541 5.9 MEDIUM EPSS 0.00
Fortinet Fortios - Security Feature Bypass
Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.
CWE-254 Mar 30, 2017
CVE-2017-7320 6.1 MEDIUM EPSS 0.00
MODX Revolution <2.5.4-pl - RCE
setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value.
CWE-79 Mar 30, 2017
CVE-2016-4976 5.5 MEDIUM EPSS 0.00
Apache Ambari < 2.4.0 - Information Disclosure
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
CWE-200 Mar 29, 2017
CVE-2017-7299 5.5 MEDIUM EPSS 0.00
GNU Binutils 2.28 - Memory Corruption
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before trying to read the ELF reloc section header. The vulnerability leads to a GNU linker (ld) program crash.
CWE-125 Mar 29, 2017
CVE-2017-5900 5.4 MEDIUM EPSS 0.00
Netcomm Nb16wv-02 Firmware - XSS
Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web script or HTML via the S801F0334 parameter to hdd.htm.
CWE-79 Mar 29, 2017
CVE-2016-6846 6.1 MEDIUM EPSS 0.00
Open-xchange Documentconverter-api - XSS
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before 7.8.2-rev5; and Documentconverter-API before 7.8.2-rev5 allows remote attackers to inject arbitrary web script or HTML.
CWE-79 Mar 29, 2017
CVE-2015-8234 5.5 MEDIUM EPSS 0.00
OpenStack Glance 11.0.0 - Auth Bypass
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
CWE-310 Mar 29, 2017
CVE-2017-7298 5.4 MEDIUM EPSS 0.00
Moodle <3.2.2 - XSS
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.
CWE-79 Mar 29, 2017
CVE-2017-6864 5.4 MEDIUM EPSS 0.00
Siemens RUGGEDCOM ROX I - XSS
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an authenticated user to perform stored Cross-Site Scripting attacks.
CWE-79 Mar 29, 2017
CVE-2017-2687 6.1 MEDIUM EPSS 0.00
Siemens Ruggedcom Rox I < 2.9.0 - XSS
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induced to click on a malicious link.
CWE-79 Mar 29, 2017
CVE-2017-2686 6.5 MEDIUM EPSS 0.00
Siemens Ruggedcom Rox I < 2.9.0 - Information Disclosure
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive information.
CWE-285 Mar 29, 2017
CVE-2016-8884 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer 1.900.5 - DoS
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8690.
CWE-476 Mar 28, 2017
CVE-2017-0882 6.3 MEDIUM EPSS 0.00
GitLab <8.15.8-8.17.4 - Info Disclosure
Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.
CWE-639 Mar 28, 2017
CVE-2017-0881 4.3 MEDIUM 1 Writeup EPSS 0.00
Zulip <1.4.3 - Privilege Escalation
An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join. The issue affects all previously released versions of the Zulip server.
CWE-200 Mar 28, 2017
CVE-2016-9473 4.7 MEDIUM EPSS 0.01
Brave Browser < 1.2.18 - XSS
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.
CWE-451 Mar 28, 2017
CVE-2016-9472 5.4 MEDIUM 1 Writeup EPSS 0.00
Revive-adserver Revive Adserver < 3.2.4 - XSS
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other parameters. It has to be noted that the window for such attack vectors to be possible is extremely narrow and it is very unlikely that such an attack could be actually effective.
CWE-79 Mar 28, 2017
CVE-2016-9468 5.3 MEDIUM 2 Writeups EPSS 0.00
Nextcloud Server < 9.0.54 - Improper Access Control
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential misrepresentation of information.
CWE-284 Mar 28, 2017
CVE-2016-9467 5.3 MEDIUM 2 Writeups EPSS 0.01
Nextcloud Server < 9.0.54 - Improper Access Control
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user.
CWE-284 Mar 28, 2017