CVE & Exploit Intelligence Database

Updated 51m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,716 CVEs tracked 53,323 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,939 Nuclei templates 49,017 vendors 42,676 researchers
111,142 results Clear all
CVE-2017-6072 5.3 MEDIUM EPSS 0.00
Cmsmadesimple Form Builder < 0.8.1.5 - Information Disclosure
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.
CWE-200 Feb 21, 2017
CVE-2017-6071 5.3 MEDIUM EPSS 0.00
Cmsmadesimple Form Builder < 0.8.1.5 - Information Disclosure
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
CWE-200 Feb 21, 2017
CVE-2016-9316 5.4 MEDIUM 1 PoC Analysis EPSS 0.01
Trend Micro IWSVA <6.5-CP-1737 - XSS
Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users with least privileges to inject arbitrary HTML/JavaScript code into web pages. This was resolved in Version 6.5 CP 1737.
CWE-79 Feb 21, 2017
CVE-2017-0038 5.5 MEDIUM 2 PoCs Analysis EPSS 0.80
Microsoft Windows 10 - Information Disclosure
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220.
CWE-200 Feb 20, 2017
CVE-2016-6249 5.3 MEDIUM EPSS 0.00
F5 BIG-IP <12.0.0, 11.6.1 - Info Disclosure
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files.
CWE-200 Feb 20, 2017
CVE-2017-2371 6.5 MEDIUM 1 PoC Analysis EPSS 0.07
Apple <10.2.1 - XSS
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.
CWE-20 Feb 20, 2017
CVE-2017-2368 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Apple <10.2.1 - DoS
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attackers to cause a denial of service (application crash) via a crafted contact card.
CWE-20 Feb 20, 2017
CVE-2017-2365 6.5 MEDIUM 1 PoC Analysis EPSS 0.18
Apple <10.2.1, <10.0.3, <10.1.1 - SSRF
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2017-2364 6.5 MEDIUM 1 PoC Analysis EPSS 0.18
Apple <10.2.1, <10.0.3 - CSRF
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2017-2363 6.5 MEDIUM 1 PoC Analysis EPSS 0.21
Apple <10.2.1, <10.0.3, <10.1.1, <3.1.3 - CSRF
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2017-2361 6.1 MEDIUM 1 PoC Analysis EPSS 0.06
Apple <10.12.3 - XSS
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.
CWE-79 Feb 20, 2017
CVE-2017-2359 6.5 MEDIUM EPSS 0.00
Apple <10.0.3 - XSS
An issue was discovered in certain Apple products. Safari before 10.0.3 is affected. The issue involves the "Safari" component, which allows remote attackers to spoof the address bar via a crafted web site.
Feb 20, 2017
CVE-2017-2352 4.6 MEDIUM EPSS 0.00
Apple <10.2.1 - Auth Bypass
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Unlock with iPhone" component, which allows attackers to bypass the wrist-presence protection mechanism and unlock a Watch device via unspecified vectors.
Feb 20, 2017
CVE-2017-2350 6.5 MEDIUM EPSS 0.01
Apple <10.2.1, <10.0.3, <10.1.1 - SSRF
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2016-7762 6.1 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - XSS
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "WebKit" component, which allows XSS attacks against Safari.
CWE-79 Feb 20, 2017
CVE-2016-7761 5.5 MEDIUM EPSS 0.00
Apple Mac OS X < 10.12.1 - Information Disclosure
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "WiFi" component, which allows local users to obtain sensitive network-configuration information by leveraging global storage.
CWE-200 Feb 20, 2017
CVE-2016-7759 4.3 MEDIUM EPSS 0.00
Apple Iphone OS < 9.3.5 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10 is affected. The issue involves the "Springboard" component, which allows physically proximate attackers to obtain sensitive information by viewing application snapshots in the Task Switcher.
CWE-200 Feb 20, 2017
CVE-2016-7666 5.5 MEDIUM EPSS 0.00
Apple Transporter < 1.9.1 - Information Disclosure
An issue was discovered in certain Apple products. Transporter before 1.9.2 is affected. The issue involves the "iTMSTransporter" component, which allows attackers to obtain sensitive information via a crafted EPUB.
CWE-200 Feb 20, 2017
CVE-2016-7665 5.5 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Improper Input Validation
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Graphics Driver" component, which allows remote attackers to cause a denial of service via a crafted video.
CWE-20 Feb 20, 2017
CVE-2016-7651 5.3 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Improper Authorization
An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" component, which allows local users to bypass intended authorization restrictions by leveraging the mishandling of an app uninstall.
CWE-285 Feb 20, 2017