CVE & Exploit Intelligence Database

Updated 57m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
14 results Clear all
CVE-2014-8371 EPSS 0.00
Vmware Vcenter Server Appliance - Cryptographic Issue
VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM servers via a crafted certificate.
CWE-310 Dec 08, 2014
CVE-2014-3797 EPSS 0.00
Vmware Vcenter Server Appliance - XSS
Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Dec 08, 2014
CVE-2014-7169 9.8 CRITICAL KEV 19 PoCs Analysis EPSS 0.90
GNU Bash <4.3 - Code Injection
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
CWE-78 Sep 25, 2014
CVE-2014-6271 9.8 CRITICAL KEV 119 PoCs Analysis NUCLEI EPSS 0.94
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
CWE-78 Sep 24, 2014
CVE-2014-4258 EPSS 0.01
Oracle MySQL <5.5.38 & <5.6.18 - Info Disclosure
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.
Jul 17, 2014
CVE-2014-4241 EPSS 0.01
Oracle WebLogic Server <10.3.6.0 - RCE
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.
Jul 17, 2014
CVE-2014-3790 EPSS 0.01
Vmware Vcenter Server Appliance - Access Control
Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.
CWE-264 Jun 01, 2014
CVE-2013-3107 EPSS 0.00
VMware vCenter Server <5.1 - Auth Bypass
VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction with an empty password.
CWE-264 May 01, 2013
CVE-2013-3080 EPSS 0.01
VMware vCenter Server Appliance <5.1 - RCE
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently execute arbitrary code or cause a denial of service, by leveraging Virtual Appliance Management Interface (VAMI) web-interface access.
CWE-264 May 01, 2013
CVE-2013-3079 EPSS 0.00
VMware vCSA <5.1 - Privilege Escalation
VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by leveraging Virtual Appliance Management Interface (VAMI) access.
CWE-94 May 01, 2013
CVE-2013-1659 EPSS 0.01
Vmware Vcenter Server - Denial of Service
VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.
Feb 22, 2013
CVE-2012-6326 EPSS 0.00
Vmware Vcenter Server - Memory Corruption
VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.
CWE-119 Feb 22, 2013
CVE-2012-6325 EPSS 0.00
Vmware Vcenter Server Appliance < 5.0 - Information Disclosure
VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified vectors.
CWE-200 Dec 21, 2012
CVE-2012-6324 EPSS 0.00
Vmware Vcenter Server Appliance - Path Traversal
Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via unspecified vectors.
CWE-22 Dec 21, 2012