CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,687 CVEs tracked 53,322 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,014 vendors 42,676 researchers
111,134 results Clear all
CVE-2017-5015 6.5 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76-56.0.2924.87 - CSRF
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled Unicode glyphs, which allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Feb 17, 2017
CVE-2017-5014 6.3 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76-56.0.2924.87 - Buffer Overflow
Heap buffer overflow during image processing in Skia in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CWE-119 Feb 17, 2017
CVE-2017-5013 6.5 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76 - XSS
Google Chrome prior to 56.0.2924.76 for Linux incorrectly handled new tab page navigations in non-selected tabs, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Feb 17, 2017
CVE-2017-5011 6.5 MEDIUM EPSS 0.01
Google Chrome <56.0.2924.76 - Info Disclosure
Google Chrome prior to 56.0.2924.76 for Windows insufficiently sanitized DevTools URLs, which allowed a remote attacker who convinced a user to install a malicious extension to read filesystem contents via a crafted HTML page.
CWE-200 Feb 17, 2017
CVE-2017-5010 6.1 MEDIUM EPSS 0.00
Google Chrome <56.0.2924.76-56.0.2924.87 - UXSS
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, resolved promises in an inappropriate context, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CWE-79 Feb 17, 2017
CVE-2017-5008 6.1 MEDIUM EPSS 0.00
Google Chrome <56.0.2924.76-56.0.2924.87 - UXSS
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed attacker controlled JavaScript to be run during the invocation of a private script method, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CWE-79 Feb 17, 2017
CVE-2017-5007 6.1 MEDIUM 1 PoC Analysis EPSS 0.06
Google Chrome <56.0.2924.76-56.0.2924.87 - UXSS
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events when closing a page, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CWE-79 Feb 17, 2017
CVE-2017-5006 6.1 MEDIUM EPSS 0.00
Google Chrome <56.0.2924.76-56.0.2924.87 - UXSS
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled object owner relationships, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CWE-79 Feb 17, 2017
CVE-2016-9955 6.3 MEDIUM EPSS 0.00
Simplesamlphp < 1.14.11 - Improper Input Validation
The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
CWE-20 Feb 17, 2017
CVE-2016-9828 5.5 MEDIUM EPSS 0.00
Libming < 0.4.7 - NULL Pointer Dereference
The dumpBuffer function in read.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SWF file.
CWE-476 Feb 17, 2017
CVE-2016-9827 5.5 MEDIUM EPSS 0.00
Libming < 0.4.7 - Memory Corruption
The _iprintf function in outputtxt.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (buffer over-read) via a crafted SWF file.
CWE-119 Feb 17, 2017
CVE-2016-9773 5.5 MEDIUM EPSS 0.00
Imagemagick - Memory Corruption
Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9556.
CWE-119 Feb 17, 2017
CVE-2016-9139 6.1 MEDIUM EPSS 0.00
OTRS <3.3.16, <4.0.19, <5.0.14 - XSS
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment.
CWE-79 Feb 17, 2017
CVE-2016-8652 5.9 MEDIUM EPSS 0.09
Dovecot <2.2.27 - DoS
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.
CWE-20 Feb 17, 2017
CVE-2016-4327 6.1 MEDIUM EPSS 0.00
WSO2 SOA Enablement Server - XSS
Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CWE-79 Feb 17, 2017
CVE-2016-4316 6.1 MEDIUM 1 PoC Analysis EPSS 0.03
WSO2 Carbon 4.4.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to viewflows/handlers.jsp; or the (7) url parameter to ndatasource/validateconnection-ajaxprocessor.jsp.
CWE-79 Feb 17, 2017
CVE-2016-4315 5.7 MEDIUM 1 PoC Analysis EPSS 0.03
WSO2 Carbon 4.4.5 - CSRF
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.
CWE-352 Feb 17, 2017
CVE-2016-4314 4.9 MEDIUM 1 PoC Analysis EPSS 0.23
WSO2 Carbon 4.4.5 - Path Traversal
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.
CWE-22 Feb 17, 2017
CVE-2016-1249 5.9 MEDIUM EPSS 0.00
DBD::mysql <4.039 - DoS
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
CWE-125 Feb 17, 2017
CVE-2016-6062 6.1 MEDIUM EPSS 0.00
IBM Resilient <26.2 - XSS
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference#: 213457065.
CWE-79 Feb 16, 2017