CVE & Exploit Intelligence Database

Updated 42m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
22 results Clear all
CVE-2023-4344 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
CWE-331 Aug 15, 2023
CVE-2023-4343 7.5 HIGH EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable due to exposure of sensitive password information in the URL as a URL search parameter
Aug 15, 2023
CVE-2023-4342 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy
Aug 15, 2023
CVE-2023-4341 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - Privilege Escalation
Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI
Aug 15, 2023
CVE-2023-4340 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - Privilege Escalation
Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
Aug 15, 2023
CVE-2023-4339 7.5 HIGH EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable to exposure of private keys used for CIM stored with insecure file permissions
Aug 15, 2023
CVE-2023-4338 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers
Aug 15, 2023
CVE-2023-4337 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - SSRF
Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation
Aug 15, 2023
CVE-2023-4336 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute
Aug 15, 2023
CVE-2023-4335 7.5 HIGH EPSS 0.00
Broadcom RAID Controller Web - Info Disclosure
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
CWE-306 Aug 15, 2023
CVE-2023-4334 7.5 HIGH EPSS 0.00
Broadcom RAID Controller Web server - Info Disclosure
Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
CWE-306 Aug 15, 2023
CVE-2023-4333 5.5 MEDIUM EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server
CWE-326 Aug 15, 2023
CVE-2023-4332 7.5 HIGH EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
CWE-732 Aug 15, 2023
CVE-2023-4331 7.5 HIGH EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that support obsolete and vulnerable TLS protocols
CWE-327 Aug 15, 2023
CVE-2023-4329 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute
Aug 15, 2023
CVE-2023-4328 5.5 MEDIUM EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows
CWE-522 Aug 15, 2023
CVE-2023-4327 5.5 MEDIUM EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
CWE-522 Aug 15, 2023
CVE-2023-4326 7.5 HIGH EPSS 0.00
Broadcom RAID Controller - SSL/TLS Vulnerability
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration that supports obsolete SHA1-based ciphersuites
CWE-327 Aug 15, 2023
CVE-2023-4325 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - Buffer Overflow
Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
Aug 15, 2023
CVE-2023-4324 9.8 CRITICAL EPSS 0.00
Broadcom RAID Controller - Info Disclosure
Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers
Aug 15, 2023