Exploit Intelligence Platform
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
846 results
Clear all
CVE-2018-12036
7.8
HIGH
1 PoC
Analysis
EPSS 0.00
OWASP Dependency-Check <3.2.0 - Path Traversal
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.
CWE-22
Jun 07, 2018
CVE-2018-1000850
7.5
HIGH
1 PoC
Analysis
EPSS 0.03
Square Retrofit <2.5.0 - Path Traversal
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.
CWE-22
Dec 20, 2018
CVE-2018-17297
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Hutool <4.1.12 - Path Traversal
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
CWE-22
Sep 21, 2018
CVE-2018-1002202
6.5
MEDIUM
2 PoCs
Analysis
EPSS 0.04
zip4j <1.3.3 - Path Traversal
zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CWE-22
Jul 25, 2018
CVE-2018-1260
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.50
Pivotal Software Spring Security Oauth < 2.0.14 - Code Injection
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.
CWE-94
May 11, 2018
CVE-2018-1047
5.5
MEDIUM
1 PoC
Analysis
EPSS 0.00
Redhat Jboss Wildfly Application Server < 12.0.0 - Path Traversal
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
CWE-22
Jan 24, 2018
CVE-2018-11784
4.3
MEDIUM
3 PoCs
Analysis
NUCLEI
EPSS 0.83
Apache Tomcat < 7.0.90 - Open Redirect
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
CWE-601
Oct 04, 2018
CVE-2018-1297
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.18
Apache Jmeter < 4.0 - Cleartext Transmission
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
CWE-319
Feb 13, 2018
CVE-2018-1000861
9.8
CRITICAL
KEV
RANSOMWARE
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Jenkins <2.153 - RCE
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
CWE-502
Dec 10, 2018
CVE-2018-18893
5.3
MEDIUM
1 PoC
Analysis
EPSS 0.00
Jinjava <2.4.6 - Info Disclosure
Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.
Jan 03, 2019
CVE-2018-8032
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.02
Apache Axis <1.4 - XSS
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
CWE-79
Aug 02, 2018
CVE-2018-14042
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.02
Bootstrap <4.1.2 - XSS
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
CWE-79
Jul 13, 2018
CVE-2018-14041
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.08
Bootstrap <4.1.2 - XSS
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
CWE-79
Jul 13, 2018
CVE-2018-1263
4.7
MEDIUM
1 PoC
Analysis
EPSS 0.01
Vmware Spring Integration Zip < 1.0.2 - Path Traversal
Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
CWE-22
May 15, 2018
CVE-2018-20433
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Mchange C3p0 < 0.9.5.3 - XXE
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
CWE-611
Dec 24, 2018
CVE-2018-19859
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.11
OpenRefine <3.2 - Path Traversal
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.
CWE-22
Dec 05, 2018
CVE-2018-1288
5.4
MEDIUM
1 PoC
EPSS 0.01
Apache Kafka <1.0.0 - Privilege Escalation
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
Jul 26, 2018
CVE-2018-14667
9.8
CRITICAL
KEV
6 PoCs
Analysis
EPSS 0.89
RichFaces Framework 3.X-3.3.4 - Code Injection
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
CWE-94
Nov 06, 2018
CVE-2018-8718
8.0
HIGH
2 PoCs
Analysis
EPSS 0.01
Mailer Plugin 1.20 for Jenkins 2.111 - CSRF
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.
CWE-352
Mar 27, 2018
CVE-2018-11761
7.5
HIGH
1 PoC
Analysis
EPSS 0.11
Apache Tika < 1.18 - XXE
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
CWE-611
Sep 19, 2018