CVE & Exploit Intelligence Database

Updated 56m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
8 results Clear all
CVE-2024-54540 4.3 MEDIUM EPSS 0.00
Apple Music < 1.5.0.152 - XSS
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
CWE-79 Jan 15, 2025
CVE-2023-32427 5.9 MEDIUM EPSS 0.00
Apple Music <4.2.0 - Info Disclosure
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 4.2.0 for Android. An attacker in a privileged network position may be able to intercept network traffic.
Jul 28, 2023
CVE-2023-28203 5.5 MEDIUM EPSS 0.00
Apple Music < 4.2.0 - Information Disclosure
The issue was addressed with improved checks. This issue is fixed in Apple Music 4.2.0 for Android. An app may be able to access contacts.
CWE-200 Jul 28, 2023
CVE-2022-32906 5.3 MEDIUM EPSS 0.00
Apple Music < 3.9.10 - Cleartext Transmission
This issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. A user in a privileged network position may intercept SSL/TLS connections.
CWE-319 Feb 27, 2023
CVE-2022-32846 7.5 HIGH EPSS 0.00
Apple Music <3.9.10 - Info Disclosure
A logic issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.
CWE-664 Feb 27, 2023
CVE-2022-32836 7.5 HIGH EPSS 0.00
Apple Music - Information Disclosure
This issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.
CWE-200 Feb 27, 2023
CVE-2021-46841 5.9 MEDIUM EPSS 0.00
Apple Music <3.5.0 - Info Disclosure
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An attacker in a privileged network position can track a user's activity.
CWE-200 Feb 27, 2023
CVE-2020-9982 5.5 MEDIUM EPSS 0.00
Apple Music <3.4.0 - Info Disclosure
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Apple Music 3.4.0 for Android. A malicious application may be able to leak a user's credentials.
Oct 27, 2020