CVE & Exploit Intelligence Database

Updated 25m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,864 CVEs tracked 53,333 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,042 vendors 42,726 researchers
111,268 results Clear all
CVE-2015-4645 5.5 MEDIUM 1 Writeup EPSS 0.00
Squashfs < 4.3 - Integer Overflow
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.
CWE-190 Mar 17, 2017
CVE-2015-3883 6.1 MEDIUM EPSS 0.00
qdPM 8.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) search[keywords] parameter to index.php/users page; the (2) "Name of application" on index.php/configuration; (3) a new project name on index.php/projects; (4) the task name on index.php/tasks; (5) ticket name on index.php/tickets; (6) discussion name on index.php/discussions; (7) report name on index.php/projectReports; or (8) event name on index.php/scheduler/personal.
CWE-79 Mar 17, 2017
CVE-2015-3882 5.3 MEDIUM EPSS 0.00
qdPM 8.3 - Info Disclosure
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation path in an error message.
CWE-200 Mar 17, 2017
CVE-2014-9853 5.5 MEDIUM EPSS 0.00
ImageMagick - DoS
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
CWE-399 Mar 17, 2017
CVE-2014-8723 5.3 MEDIUM EPSS 0.00
GetSimple CMS 3.3.4 - Info Disclosure
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.
CWE-200 Mar 17, 2017
CVE-2014-8707 5.4 MEDIUM EPSS 0.00
TinyMCE in Pluck CMS 4.7.2 - XSS
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.
CWE-79 Mar 17, 2017
CVE-2014-8706 5.3 MEDIUM EPSS 0.00
Pluck CMS 4.7.2 - Info Disclosure
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the installation path in an error message.
CWE-200 Mar 17, 2017
CVE-2014-8703 6.1 MEDIUM EPSS 0.00
Wonder CMS 2014 - XSS
Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.
CWE-79 Mar 17, 2017
CVE-2014-8702 5.3 MEDIUM EPSS 0.00
Wonder CMS 2014 - Info Disclosure
Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals the installation path in an error message.
CWE-200 Mar 17, 2017
CVE-2017-6966 5.5 MEDIUM EPSS 0.00
GNU Binutils <2.28 - Use After Free
readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.
CWE-416 Mar 17, 2017
CVE-2017-6965 5.5 MEDIUM EPSS 0.00
GNU Binutils <2.28 - Buffer Overflow
readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.
CWE-119 Mar 17, 2017
CVE-2017-6961 5.5 MEDIUM EPSS 0.00
apng2gif 1.7 - Memory Corruption
An issue was discovered in apng2gif 1.7. There is improper sanitization of user input causing huge memory allocations, resulting in a crash. This is related to the read_chunk function using the pChunk->size value (within the PNG file) to determine the amount of memory to allocate.
CWE-20 Mar 17, 2017
CVE-2017-6958 6.1 MEDIUM EPSS 0.00
MantisBT Source Integration Plugin <2.0.2 - XSS
An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by crafting any valid parameter.
CWE-79 Mar 17, 2017
CVE-2017-6955 5.3 MEDIUM EPSS 0.01
WordPress Invite Anyone <1.3.15 - Info Disclosure
An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.
CWE-20 Mar 17, 2017
CVE-2017-6954 4.3 MEDIUM 1 Writeup EPSS 0.00
BuddyPress Docs <1.9.3 - Privilege Escalation
An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.
CWE-269 Mar 17, 2017
CVE-2017-0154 4.4 MEDIUM EPSS 0.01
Microsoft Internet Explorer - Injection
Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."
CWE-74 Mar 17, 2017
CVE-2017-0140 4.2 MEDIUM EPSS 0.13
Microsoft Edge - CSRF
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135.
Mar 17, 2017
CVE-2017-0135 4.2 MEDIUM EPSS 0.22
Microsoft Edge - CSRF
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.
Mar 17, 2017
CVE-2017-0128 4.3 MEDIUM 1 PoC Analysis EPSS 0.10
Microsoft Windows 7 - Information Disclosure
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, and CVE-2017-0127.
CWE-200 Mar 17, 2017
CVE-2017-0127 4.3 MEDIUM 1 PoC Analysis EPSS 0.10
Microsoft Windows 7 - Information Disclosure
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, and CVE-2017-0128.
CWE-200 Mar 17, 2017