CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,098 CVEs tracked 53,218 with exploits 4,684 exploited in wild 1,536 CISA KEV 3,912 Nuclei templates 37,750 vendors 42,417 researchers
14 results Clear all
CVE-2010-0887 EPSS 0.10
Oracle Java SE/JDK/JRE <6.19 - Info Disclosure
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Apr 20, 2010
CVE-2009-1107 EPSS 0.03
Java Plug-in <6.12 & <5.0.17 - XSS
The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.
Mar 25, 2009
CVE-2009-1105 EPSS 0.08
Java Plug-in <6-11-10 - RCE
The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490.
Mar 25, 2009
CVE-2009-1104 EPSS 0.02
SUN Java - XSS
The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331. NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors.
CWE-16 Mar 25, 2009
CVE-2009-1103 EPSS 0.05
Java Plug-in <6 - Code Injection
Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "deserializing applets," aka CR 6646860.
Mar 25, 2009
CVE-2009-1102 EPSS 0.06
SUN Java - Code Injection
Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "code generation."
CWE-94 Mar 25, 2009
CVE-2008-3440 EPSS 0.01
Sun Java <1.6.0_03 - Code Injection
Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
CWE-94 Aug 01, 2008
CVE-2005-2529 EPSS 0.01
Java <1.4.2 - Privilege Escalation
Unspecified vulnerability in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to gain privileges via unspecified attack vectors relating to "the utility used to update Java shared archives."
Dec 31, 2005
CVE-2005-2738 EPSS 0.01
Java <1.4.2 - Info Disclosure
Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X does not prevent multiple programs from opening the same port as a Java ServerSocket, which allows local users to operate a Java program that intercepts network data intended for the ServerSocket of a different Java program.
Dec 31, 2005
CVE-2005-2527 EPSS 0.00
SUN Java < 1.4.2_release1 - Symlink Following
Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack vectors related to a temporary directory, possibly due to a symlink attack.
CWE-59 Dec 31, 2005
CVE-2005-2530 EPSS 0.01
Java <1.3.1_16 - Privilege Escalation
Unspecified vulnerability in Java 1.3.1 before 1.3.1_16 on Apple Mac OS X allows an untrusted applet to gain privileges, related to "Mac OS X specific extensions."
Dec 31, 2005
CVE-2003-1134 1 PoC Analysis EPSS 0.00
SUN Java - Denial of Service
Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.
Dec 31, 2003
CVE-1999-0440 EPSS 0.02
Java JVM - RCE
The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.
Mar 01, 1999
CVE-1999-0142 EPSS 0.00
Netscape Navigator 2.0 - SSRF
The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.
Mar 01, 1996