Exploit Intelligence Platform
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
846 results
Clear all
CVE-2016-5394
6.1
MEDIUM
2 PoCs
Analysis
EPSS 0.01
Apache Sling < 1.0.12 - XSS
In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for some input patterns allows script tags to pass through unencoded, leading to potential XSS vulnerabilities.
CWE-79
Jul 19, 2017
CVE-2016-10726
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Duraspace Dspace < 3.6 - Path Traversal
The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.
CWE-22
Jul 10, 2018
CVE-2016-4977
8.8
HIGH
EXPLOITED
2 PoCs
Analysis
NUCLEI
EPSS 0.94
Pivotal Spring Security Oauth < 2.0.10 - Remote Code Execution
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.
CWE-19
May 25, 2017
CVE-2016-8735
9.8
CRITICAL
KEV
1 PoC
NUCLEI
EPSS 0.94
Apache Tomcat , 7.x , 8.x , 8.5.x , 9.x <6.0.48 <7.0.73 <8.0.39 <8.5.7 - Remote Code Execution
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Apr 06, 2017
CVE-2016-6798
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.01
Apache Sling < 1.0.10 - XXE
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.
CWE-611
Jul 19, 2017
CVE-2016-4438
9.8
CRITICAL
2 PoCs
Analysis
EPSS 0.62
Apache Struts 2 <2.3.28.1 - RCE
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
CWE-20
Jul 04, 2016
CVE-2016-0793
7.5
HIGH
2 PoCs
Analysis
EPSS 0.35
WildFly <10.0.0.Final - Info Disclosure
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless" characters.
CWE-200
Apr 01, 2016
CVE-2016-6816
7.1
HIGH
1 PoC
Analysis
EPSS 0.03
Apache Tomcat < 9.0.0.M12 - Improper Input Validation
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.
CWE-20
Mar 20, 2017
CVE-2016-2173
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.21
Fedora < 1.5.5 - Improper Input Validation
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
CWE-20
Apr 21, 2017
CVE-2016-5725
5.9
MEDIUM
1 PoC
Analysis
EPSS 0.30
JCraft JSch <0.1.54 - Path Traversal
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
CWE-22
Jan 19, 2017
CVE-2016-4316
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.03
WSO2 Carbon 4.4.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to viewflows/handlers.jsp; or the (7) url parameter to ndatasource/validateconnection-ajaxprocessor.jsp.
CWE-79
Feb 17, 2017
CVE-2016-4314
4.9
MEDIUM
1 PoC
Analysis
EPSS 0.23
WSO2 Carbon 4.4.5 - Path Traversal
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.
CWE-22
Feb 17, 2017
CVE-2016-3670
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.09
Liferay <7.0.0 - XSS
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to inject arbitrary web script or HTML via the FirstName field.
CWE-79
Jun 13, 2016
CVE-2016-2402
5.9
MEDIUM
2 PoCs
Analysis
EPSS 0.03
Squareup Okhttp < 2.7.3 - Improper Certificate Validation
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
CWE-295
Jan 30, 2017
CVE-2016-0784
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.06
Apache OpenMeetings <3.1.1 - Path Traversal
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.
CWE-22
Apr 11, 2016
CVE-2016-0709
7.2
HIGH
1 PoC
Analysis
EPSS 0.71
Apache Jetspeed <2.3.1 - Path Traversal
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by "../../webapps/x.jsp."
CWE-22
Apr 11, 2016
CVE-2016-0956
7.5
HIGH
1 PoC
Analysis
EPSS 0.13
Apache Sling 2.3.6 - Info Disclosure
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
CWE-200
Feb 10, 2016
CVE-2015-5254
9.8
CRITICAL
4 PoCs
Analysis
EPSS 0.80
Apache ActiveMQ <5.13.0 - RCE
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
CWE-20
Jan 08, 2016
CVE-2015-5531
EXPLOITED
5 PoCs
Analysis
NUCLEI
EPSS 0.92
Elasticsearch <1.6.1 - Path Traversal
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.
CWE-22
Aug 17, 2015
CVE-2015-9251
6.1
MEDIUM
EXPLOITED
5 PoCs
Analysis
EPSS 0.27
Jquery < 3.0.0 - XSS
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
CWE-79
Jan 18, 2018