CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,864 CVEs tracked 53,333 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,042 vendors 42,726 researchers
111,268 results Clear all
CVE-2016-10130 5.9 MEDIUM EPSS 0.01
libgit2 <0.24.6, <0.25.1 - Info Disclosure
The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.
CWE-284 Mar 24, 2017
CVE-2017-5644 5.5 MEDIUM EPSS 0.01
Apache Poi < 3.14 - XML Entity Expansion
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
CWE-776 Mar 24, 2017
CVE-2015-8678 5.5 MEDIUM EPSS 0.00
Huawei Mate S Firmware < crr-cl00c92b153 - Improper Input Validation
The ION driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows remote attackers to cause a denial of service (crash) via a crafted application.
CWE-20 Mar 24, 2017
CVE-2017-6507 5.9 MEDIUM EPSS 0.00
Apparmor < 2.11 - Improper Privilege Management
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic.
CWE-269 Mar 24, 2017
CVE-2017-7251 6.1 MEDIUM EPSS 0.00
pi-engine/pi 2.5.0 - XSS
A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the "pi-develop/www/script/editor/markitup/preview/markdown.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Mar 23, 2017
CVE-2017-7250 6.1 MEDIUM 1 Writeup EPSS 0.00
Gazelle <2017-03-19 - XSS
A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (action) passed to the 'Gazelle-master/sections/tools/finances/bitcoin_balance.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Mar 23, 2017
CVE-2017-7249 6.1 MEDIUM 1 Writeup EPSS 0.00
Gazelle <2017-03-19 - XSS
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (action, userid) passed to the 'Gazelle-master/sections/tools/data/ocelot_info.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Mar 23, 2017
CVE-2017-7248 6.1 MEDIUM 1 Writeup EPSS 0.00
Gazelle <2017-03-19 - XSS
A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (type) passed to the 'Gazelle-master/sections/better/transcode.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Mar 23, 2017
CVE-2017-7247 6.1 MEDIUM 1 Writeup EPSS 0.00
Gazelle <2017-03-19 - XSS
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (torrents, size) passed to the 'Gazelle-master/sections/tools/managers/multiple_freeleech.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Mar 23, 2017
CVE-2017-7244 5.5 MEDIUM EPSS 0.01
PCRE 8.40 - DoS
The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.
CWE-125 Mar 23, 2017
CVE-2017-6911 6.6 MEDIUM EPSS 0.00
USB Pratirodh - Info Disclosure
USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in further attack.
CWE-922 Mar 23, 2017
CVE-2015-8687 5.4 MEDIUM EPSS 0.00
Alcatel-lucent Motive Home Device Manager < 4.1.10.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceTypeID parameter to DeviceType/getDeviceType.do; the (2) policyActionClass or (3) policyActionName parameter to PolicyAction/findPolicyActions.do; the deviceID parameter to (4) SingleDeviceMgmt/getDevice.do or (5) device/editDevice.do; the operation parameter to (6) ajax.do or (7) xmlHttp.do; or the (8) policyAction, (9) policyClass, or (10) policyName parameter to policy/findPolicies.do.
CWE-79 Mar 23, 2017
CVE-2015-8628 5.3 MEDIUM EPSS 0.00
Mediawiki < 1.23.11 - Information Disclosure
The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 allow remote attackers to obtain sensitive user login information via crafted links combined with page view statistics.
CWE-200 Mar 23, 2017
CVE-2015-8627 5.3 MEDIUM EPSS 0.00
Mediawiki < 1.23.11 - Improper Access Control
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize IP addresses containing zero-padded octets, which might allow remote attackers to bypass intended access restrictions by using an IP address that was not supposed to have been allowed.
CWE-284 Mar 23, 2017
CVE-2015-8622 6.1 MEDIUM EPSS 0.00
MediaWiki <1.23.12, 1.24.x <1.24.5, 1.25.x <1.25.4, 1.26.x <1.26.1 ...
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1, when is configured with a relative URL, allows remote authenticated users to inject arbitrary web script or HTML via wikitext, as demonstrated by a wikilink to a page named "javascript:alert('XSS!')."
CWE-79 Mar 23, 2017
CVE-2014-0229 6.5 MEDIUM EPSS 0.00
Apache Hadoop <0.23.11 & 2.<2.4.1 - DoS
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
CWE-264 Mar 23, 2017
CVE-2017-7242 6.1 MEDIUM EPSS 0.00
SLiMS 7 Cendana - XSS
Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkout_item.php, bibliography/dl_print.php, bibliography/item.php, bibliography/item_barcode_generator.php, bibliography/printed_card.php, circulation/loan_rules.php, master_file/author.php, master_file/coll_type.php, and master_file/doc_language.php and the quickReturnID field to circulation/ajax_action.php.
CWE-79 Mar 23, 2017
CVE-2016-9557 5.5 MEDIUM 1 Writeup EPSS 0.00
Jasper < 1.900.24 - Integer Overflow
Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file.
CWE-190 Mar 23, 2017
CVE-2016-9556 5.5 MEDIUM 1 Writeup EPSS 0.00
Imagemagick - Memory Corruption
The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
CWE-119 Mar 23, 2017
CVE-2016-9395 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer <1.900.25 - DoS
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
CWE-20 Mar 23, 2017