Exploit Intelligence Platform
Updated 6h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
846 results
Clear all
CVE-2019-16943
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.02
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.
CWE-502
Oct 01, 2019
CVE-2019-12384
5.9
MEDIUM
4 PoCs
Analysis
EPSS 0.52
FasterXML jackson-databind <2.9.9.1 - Deserialization
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
CWE-502
Jun 24, 2019
CVE-2019-14439
7.5
HIGH
3 PoCs
Analysis
EPSS 0.10
FasterXML jackson-databind <2.9.9.2 - Info Disclosure
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
CWE-502
Jul 30, 2019
CVE-2019-16942
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.00
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
CWE-502
Oct 01, 2019
CVE-2019-14379
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.01
FasterXML Jackson <2.9.9.2 - RCE
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
CWE-1321
Jul 29, 2019
CVE-2019-12814
5.9
MEDIUM
3 PoCs
Analysis
EPSS 0.18
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.
CWE-502
Jun 19, 2019
CVE-2019-10078
6.1
MEDIUM
2 PoCs
Analysis
EPSS 0.03
Apache JSPWiki <2.11.0.M3 - XSS
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.
CWE-79
May 20, 2019
CVE-2019-0207
7.5
HIGH
2 PoCs
Analysis
EPSS 0.01
Apache Tapestry < 5.4.4 - Path Traversal
Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.
CWE-22
Sep 16, 2019
CVE-2019-10076
6.1
MEDIUM
2 PoCs
Analysis
EPSS 0.03
Apache JSPWiki <2.11.0.M3 - XSS
A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
CWE-79
May 20, 2019
CVE-2019-17640
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.02
Eclipse Vert.x < 3.9.4 - Path Traversal
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back slashes on Windows Operating systems, allowing, escape the webroot folder to the current working directory.
CWE-22
Oct 15, 2020
CVE-2019-10089
6.1
MEDIUM
2 PoCs
Analysis
EPSS 0.04
Apache JSPWiki <2.11.0.M4 - XSS
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
CWE-79
Sep 23, 2019
CVE-2019-10077
6.1
MEDIUM
2 PoCs
Analysis
EPSS 0.03
Apache JSPWiki <2.11.0.M3 - XSS
A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
CWE-79
May 20, 2019
CVE-2019-8331
6.1
MEDIUM
3 PoCs
Analysis
EPSS 0.02
Bootstrap < 3.4.1 - XSS
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
CWE-79
Feb 20, 2019
CVE-2019-0222
7.5
HIGH
1 PoC
Analysis
EPSS 0.10
Apache ActiveMQ <5.15.8 - Info Disclosure
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
Mar 28, 2019
CVE-2019-17573
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.16
Apache Cxf < 3.2.12 - XSS
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.
CWE-79
Jan 16, 2020
CVE-2019-0194
7.5
HIGH
1 PoC
EPSS 0.02
Apache Camel < 2.19.0 - Path Traversal
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
CWE-22
Apr 30, 2019
CVE-2019-0225
7.5
HIGH
1 PoC
Analysis
EPSS 0.03
Apache Jspwiki < 2.11.0 - Path Traversal
A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.
CWE-22
Mar 28, 2019
CVE-2019-17572
5.3
MEDIUM
1 PoC
Analysis
EPSS 0.02
Apache Rocketmq < 4.6.0 - Path Traversal
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.
CWE-22
May 14, 2020
CVE-2019-10392
8.8
HIGH
3 PoCs
Analysis
EPSS 0.81
Jenkins Git Client < 2.8.4 - OS Command Injection
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
CWE-78
Sep 12, 2019
CVE-2019-16891
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.80
Liferay Portal CE 6.2.5 - Code Injection
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
CWE-502
Oct 04, 2019