CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,831 CVEs tracked 53,332 with exploits 4,739 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,039 vendors 42,720 researchers
111,250 results Clear all
CVE-2017-5505 5.5 MEDIUM EPSS 0.00
Jasper - Memory Corruption
The jas_matrix_asl function in jas_seq.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.
CWE-119 Mar 16, 2017
CVE-2016-10187 5.5 MEDIUM EPSS 0.00
Calibre < 2.74.0 - Access Control
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.
CWE-264 Mar 16, 2017
CVE-2016-0770 6.1 MEDIUM EPSS 0.01
WordPress <8.5.9 - XSS
Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable.
CWE-79 Mar 16, 2017
CVE-2016-10247 5.5 MEDIUM EPSS 0.00
Artifex Mupdf < 1.10 - Out-of-Bounds Write
Buffer overflow in the my_getline function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.
CWE-787 Mar 16, 2017
CVE-2016-10246 5.5 MEDIUM EPSS 0.00
Artifex Mupdf < 1.10 - Out-of-Bounds Write
Buffer overflow in the main function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.
CWE-787 Mar 16, 2017
CVE-2017-6061 4.7 MEDIUM EPSS 0.01
SAP Businessobjects Financial Consolidation - XSS
Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933 allows remote attackers to inject arbitrary web script or HTML via a GET request. /finance/help/en/frameset.htm is the URI for this component. The vendor response is SAP Security Note 2368106.
CWE-79 Mar 16, 2017
CVE-2017-5937 6.5 MEDIUM EPSS 0.00
Virglrenderer < 0.5.0 - NULL Pointer Dereference
The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier allows local guest OS users to cause a denial of service (NULL pointer dereference) via a crafted VIRGL_CCMD_CLEAR command.
CWE-476 Mar 15, 2017
CVE-2017-5898 5.5 MEDIUM EPSS 0.00
Qemu < 2.8.1.1 - Integer Overflow
Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit.
CWE-190 Mar 15, 2017
CVE-2017-5849 5.5 MEDIUM EPSS 0.00
Fedora - Out-of-Bounds Write
tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related to transposing width and height values.
CWE-125 Mar 15, 2017
CVE-2015-8898 5.5 MEDIUM EPSS 0.00
Imagemagick < 6.9.2-3 - NULL Pointer Dereference
The WriteImages function in magick/constitute.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image file.
CWE-476 Mar 15, 2017
CVE-2015-8897 5.5 MEDIUM EPSS 0.00
Imagemagick < 6.9.2-3 - Out-of-Bounds Read
The SpliceImage function in MagickCore/transform.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (application crash) via a crafted png file.
CWE-125 Mar 15, 2017
CVE-2015-8896 6.5 MEDIUM EPSS 0.01
Imagemagick < 6.9.4-0 - Denial of Service
Integer truncation issue in coders/pict.c in ImageMagick before 7.0.5-0 allows remote attackers to cause a denial of service (application crash) via a crafted .pict file.
Mar 15, 2017
CVE-2015-8894 5.5 MEDIUM EPSS 0.00
Imagemagick - Double Free
Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows remote attackers to cause a denial of service (application crash) via a crafted tga file.
CWE-415 Mar 15, 2017
CVE-2017-6918 4.3 MEDIUM EPSS 0.00
BigTree CMS 4.2.16 - CSRF
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
CWE-352 Mar 15, 2017
CVE-2017-6917 4.3 MEDIUM EPSS 0.00
BigTree CMS 4.2.16 - CSRF
CSRF exists in BigTree CMS 4.2.16 with the value parameter to the admin/settings/update/ page. The Colophon can be changed.
CWE-352 Mar 15, 2017
CVE-2017-6916 4.3 MEDIUM EPSS 0.00
BigTree CMS 4.1.18 - CSRF
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
CWE-352 Mar 15, 2017
CVE-2017-6915 4.3 MEDIUM EPSS 0.00
BigTree CMS 4.1.18 - CSRF
CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page. The Colophon can be changed.
CWE-352 Mar 15, 2017
CVE-2016-7103 6.1 MEDIUM EPSS 0.01
Jqueryui Jquery UI < 1.11.4 - XSS
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
CWE-79 Mar 15, 2017
CVE-2017-6443 6.1 MEDIUM 1 PoC Analysis EPSS 0.02
Epson Tmnet Webconfig - XSS
Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1.
CWE-79 Mar 15, 2017
CVE-2017-6430 5.5 MEDIUM 1 Writeup EPSS 0.00
Ettercap < 0.8.2 - Out-of-Bounds Read
The compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted filter.
CWE-125 Mar 15, 2017