Exploit Intelligence Platform

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,175 CVEs tracked 53,341 with exploits 4,746 exploited in wild 1,546 CISA KEV 3,943 Nuclei templates 49,090 vendors 42,769 researchers
111,391 results Clear all
CVE-2017-3838 6.1 MEDIUM EPSS 0.00
Cisco Secure Access Control System <5.8(2.5) - XSS
A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc04838. Known Affected Releases: 5.8(2.5).
CWE-79 Feb 22, 2017
CVE-2017-3836 4.3 MEDIUM EPSS 0.00
Cisco Unified Communications Manager - Info Disclosure
A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. More Information: CSCvb61689. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.162) 12.0(0.98000.178) 12.0(0.98000.383) 12.0(0.98000.488) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).
CWE-200 Feb 22, 2017
CVE-2017-3833 6.1 MEDIUM EPSS 0.00
Cisco Unified Communications Manager - XSS
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb95951. Known Affected Releases: 12.0(0.99999.2). Known Fixed Releases: 11.0(1.23064.1) 11.5(1.12031.1) 11.5(1.12900.21) 11.5(1.12900.7) 11.5(1.12900.8) 11.6(1.10000.4) 12.0(0.98000.155) 12.0(0.98000.178) 12.0(0.98000.366) 12.0(0.98000.367) 12.0(0.98000.468) 12.0(0.98000.469) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).
CWE-79 Feb 22, 2017
CVE-2017-3829 6.1 MEDIUM EPSS 0.00
Cisco Unified Communications Manager Switches - XSS
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc30999. Known Affected Releases: 12.0(0.98000.280). Known Fixed Releases: 11.0(1.23900.3) 12.0(0.98000.180) 12.0(0.98000.422) 12.0(0.98000.541) 12.0(0.98000.6).
CWE-79 Feb 22, 2017
CVE-2017-3828 6.1 MEDIUM EPSS 0.00
Cisco Unified Communications Manager Switches - XSS
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvb98777. Known Affected Releases: 11.0(1.10000.10) 11.5(1.10000.6). Known Fixed Releases: 11.0(1.23063.1) 11.5(1.12029.1) 11.5(1.12900.11) 11.5(1.12900.21) 11.6(1.10000.4) 12.0(0.98000.156) 12.0(0.98000.178) 12.0(0.98000.369) 12.0(0.98000.470) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).
CWE-79 Feb 22, 2017
CVE-2017-3827 5.8 MEDIUM EPSS 0.00
Cisco AsyncOS < - Auth Bypass
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. More Information: SCvb91473, CSCvc76500. Known Affected Releases: 10.0.0-203 9.9.9-894 WSA10.0.0-233.
CWE-20 Feb 22, 2017
CVE-2017-3821 6.1 MEDIUM EPSS 0.00
Cisco Unified Communications Manager <12.0 - XSS
A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvc49348. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.209) 12.0(0.98000.478) 12.0(0.98000.609).
CWE-79 Feb 22, 2017
CVE-2015-4056 6.7 MEDIUM EPSS 0.00
Dell Vce Vision Intelligent Operations < 2.6.4 - Cryptographic Issue
The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by leveraging administrative access.
CWE-310 Feb 21, 2017
CVE-2017-6078 5.5 MEDIUM 1 Writeup EPSS 0.00
Faststone Maxview - Improper Input Validation
FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section.
CWE-20 Feb 21, 2017
CVE-2017-6072 5.3 MEDIUM EPSS 0.00
Cmsmadesimple Form Builder < 0.8.1.5 - Information Disclosure
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.
CWE-200 Feb 21, 2017
CVE-2017-6071 5.3 MEDIUM EPSS 0.00
Cmsmadesimple Form Builder < 0.8.1.5 - Information Disclosure
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
CWE-200 Feb 21, 2017
CVE-2016-9316 5.4 MEDIUM 1 PoC Analysis EPSS 0.01
Trend Micro IWSVA <6.5-CP-1737 - XSS
Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users with least privileges to inject arbitrary HTML/JavaScript code into web pages. This was resolved in Version 6.5 CP 1737.
CWE-79 Feb 21, 2017
CVE-2017-0038 5.5 MEDIUM 2 PoCs Analysis EPSS 0.80
Microsoft Windows 10 - Information Disclosure
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220.
CWE-200 Feb 20, 2017
CVE-2016-6249 5.3 MEDIUM EPSS 0.00
F5 BIG-IP <12.0.0, 11.6.1 - Info Disclosure
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files.
CWE-200 Feb 20, 2017
CVE-2017-2371 6.5 MEDIUM 1 PoC Analysis EPSS 0.07
Apple <10.2.1 - XSS
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.
CWE-20 Feb 20, 2017
CVE-2017-2368 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Apple <10.2.1 - DoS
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attackers to cause a denial of service (application crash) via a crafted contact card.
CWE-20 Feb 20, 2017
CVE-2017-2365 6.5 MEDIUM 1 PoC Analysis EPSS 0.18
Apple <10.2.1, <10.0.3, <10.1.1 - SSRF
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2017-2364 6.5 MEDIUM 1 PoC Analysis EPSS 0.18
Apple <10.2.1, <10.0.3 - CSRF
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2017-2363 6.5 MEDIUM 1 PoC Analysis EPSS 0.21
Apple <10.2.1, <10.0.3, <10.1.1, <3.1.3 - CSRF
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2017-2361 6.1 MEDIUM 1 PoC Analysis EPSS 0.06
Apple <10.12.3 - XSS
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.
CWE-79 Feb 20, 2017