CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,687 CVEs tracked 53,322 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,014 vendors 42,676 researchers
111,134 results Clear all
CVE-2016-5033 6.5 MEDIUM EPSS 0.01
Libdwarf < 2016-09-23 - Out-of-Bounds Read
The print_exprloc_content function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
CWE-125 Feb 17, 2017
CVE-2016-5032 6.5 MEDIUM EPSS 0.01
Libdwarf < 2016-09-23 - Out-of-Bounds Read
The dwarf_get_xu_hash_entry function in libdwarf before 20160923 allows remote attackers to cause a denial of service (crash) via a crafted file.
CWE-125 Feb 17, 2017
CVE-2016-5031 5.5 MEDIUM EPSS 0.00
Libdwarf < 2016-09-23 - Out-of-Bounds Read
The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
CWE-125 Feb 17, 2017
CVE-2016-5030 6.5 MEDIUM EPSS 0.01
Libdwarf < 2016-09-23 - NULL Pointer Dereference
The _dwarf_calculate_info_section_end_ptr function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Feb 17, 2017
CVE-2016-5029 6.5 MEDIUM EPSS 0.01
Libdwarf < 2016-09-23 - NULL Pointer Dereference
The create_fullest_file_path function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted dwarf file.
CWE-476 Feb 17, 2017
CVE-2016-5028 6.5 MEDIUM EPSS 0.01
Libdwarf < 2016-09-23 - NULL Pointer Dereference
The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via an object file with empty bss-like sections.
CWE-476 Feb 17, 2017
CVE-2014-9905 6.1 MEDIUM EPSS 0.01
Alinto Sogo < 2.1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title of an appointment or (2) contact fields.
CWE-79 Feb 17, 2017
CVE-2017-5998 5.4 MEDIUM EPSS 0.00
Intersect Alliance Snare Epilog - XSS
Cross-site scripting (XSS) vulnerability in InterSect Alliance SNARE Epilog for UNIX version 1.5 allows remote authenticated users to inject arbitrary web script or HTML via the str_log_name parameter in a "Web Admin Portal > Log Configuration > Add" action.
CWE-79 Feb 17, 2017
CVE-2017-5027 4.3 MEDIUM EPSS 0.00
Google Chrome <56.0.2924.76-56.0.2924.87 - XSS
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted HTML page.
Feb 17, 2017
CVE-2017-5026 4.3 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76 - XSS
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to prevent alerts from being displayed by swapped out frames, which allowed a remote attacker to show alerts on a page they don't control via a crafted HTML page.
CWE-1021 Feb 17, 2017
CVE-2017-5025 5.5 MEDIUM EPSS 0.00
FFmpeg - Memory Corruption
FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
CWE-119 Feb 17, 2017
CVE-2017-5024 5.5 MEDIUM EPSS 0.00
FFmpeg - Memory Corruption
FFmpeg in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
CWE-119 Feb 17, 2017
CVE-2017-5023 4.3 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76-56.0.2924.87 - Memory Corruption
Type confusion in Histogram in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit a near null dereference via a crafted HTML page.
CWE-476 Feb 17, 2017
CVE-2017-5022 4.3 MEDIUM EPSS 0.00
Google Chrome <56.0.2924.76-56.0.2924.87 - XSS
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted HTML page.
Feb 17, 2017
CVE-2017-5021 4.3 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76-56.0.2924.87 - Use After Free
A use after free in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CWE-416 Feb 17, 2017
CVE-2017-5020 6.1 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76-56.0.2924.87 - RCE
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.
CWE-79 Feb 17, 2017
CVE-2017-5019 6.3 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76-56.0.2924.87 - Use After Free
A use after free in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-416 Feb 17, 2017
CVE-2017-5018 6.1 MEDIUM EPSS 0.00
Google Chrome <56.0.2924.76-56.0.2924.87 - XSS
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on the Chrome app launcher page, which allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.
CWE-79 Feb 17, 2017
CVE-2017-5017 4.3 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76 - Info Disclosure
Interactions with the OS in Google Chrome prior to 56.0.2924.76 for Mac insufficiently cleared video memory, which allowed a remote attacker to possibly extract image fragments on systems with GeForce 8600M graphics chips via a crafted HTML page.
CWE-200 Feb 17, 2017
CVE-2017-5016 6.5 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76-56.0.2924.87 - Info Disclosure
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.
CWE-1021 Feb 17, 2017