Exploit Intelligence Platform
Updated 3h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
846 results
Clear all
CVE-2018-14721
10.0
CRITICAL
2 PoCs
Analysis
EPSS 0.09
FasterXML jackson-databind <2.9.7 - SSRF
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
CWE-918
Jan 02, 2019
CVE-2018-9159
5.3
MEDIUM
4 PoCs
Analysis
EPSS 0.01
Spark < 2.7.2 - Path Traversal
In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.
CWE-22
Mar 31, 2018
CVE-2018-14718
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.15
FasterXML Jackson <2.9.7 - Code Injection
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
CWE-502
Jan 02, 2019
CVE-2018-1274
7.5
HIGH
2 PoCs
Analysis
EPSS 0.01
Pivotal Software Spring Data Commons < 1.13.11 - Resource Allocation Without Limits
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
CWE-770
Apr 18, 2018
CVE-2018-14720
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.03
FasterXML Jackson <2.9.7 - SSRF
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
CWE-502
Jan 02, 2019
CVE-2018-10936
8.1
HIGH
3 PoCs
Analysis
EPSS 0.01
postgresql-jdbc <42.2.5 - SSL Man-In-The-Middle
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.
CWE-297
Aug 30, 2018
CVE-2018-1114
6.5
MEDIUM
2 PoCs
Analysis
EPSS 0.01
Undertow - File Handler Leak
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
CWE-400
Sep 11, 2018
CVE-2018-14719
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.03
FasterXML Jackson <2.9.7 - RCE
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
CWE-502
Jan 02, 2019
CVE-2018-12023
7.5
HIGH
2 PoCs
Analysis
EPSS 0.05
FasterXML jackson-databind <2.7.9.4-2.8.11.2-2.9.6 - Code Injection
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
CWE-502
Mar 21, 2019
CVE-2018-1324
5.5
MEDIUM
3 PoCs
Analysis
EPSS 0.02
Apache Commons Compress < 1.15 - Infinite Loop
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
CWE-835
Mar 16, 2018
CVE-2018-11771
5.5
MEDIUM
2 PoCs
Analysis
EPSS 0.01
Apache Commons Compress < 1.17.0 - Infinite Loop
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service attack against services that use Compress' zip package.
CWE-835
Aug 16, 2018
CVE-2018-20227
7.5
HIGH
2 PoCs
Analysis
EPSS 0.01
RDF4J 2.4.2 - Path Traversal
RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.
CWE-22
Dec 19, 2018
CVE-2018-1002201
5.5
MEDIUM
3 PoCs
Analysis
EPSS 0.01
zt-zip <1.13 - Path Traversal
zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CWE-22
Jul 25, 2018
CVE-2018-1273
9.8
CRITICAL
KEV
RANSOMWARE
10 PoCs
Analysis
NUCLEI
EPSS 0.94
Pivotal Software Spring Data Commons < 1.12.10 - Code Injection
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
CWE-94
Apr 11, 2018
CVE-2018-11307
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.12
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
CWE-502
Jul 09, 2019
CVE-2018-25031
4.3
MEDIUM
16 PoCs
Analysis
NUCLEI
EPSS 0.80
Swagger UI <4.1.2 - CSRF
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.
CWE-918
Mar 11, 2022
CVE-2018-1000129
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.77
Jolokia Agent <1.3.7 - XSS
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.
CWE-79
Mar 14, 2018
CVE-2018-8041
5.3
MEDIUM
1 PoC
Analysis
EPSS 0.02
Apache Camel's Mail <2.22.0 - Path Traversal
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
CWE-22
Sep 17, 2018
CVE-2018-11762
5.9
MEDIUM
2 PoCs
EPSS 0.01
Apache Tika < 1.18 - Path Traversal
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
CWE-22
Sep 19, 2018
CVE-2018-14040
6.1
MEDIUM
2 PoCs
Analysis
EPSS 0.03
Bootstrap <4.1.2 - XSS
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
CWE-79
Jul 13, 2018