Exploit Intelligence Platform

Updated 5m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
846 results Clear all
CVE-2008-1300 1 PoC Analysis EPSS 0.01
Alkacon OpenCms 7.0.3-7.0.4 - XSS
Cross-site scripting (XSS) vulnerability in the Logfile Viewer Settings function in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the filePath.0 parameter in a save action, a different vector than CVE-2008-1045.
CWE-79 Mar 12, 2008
CVE-2008-1301 1 PoC Analysis EPSS 0.03
Alkacon OpenCms <7.0.4 - Path Traversal
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.
CWE-22 Mar 12, 2008
CVE-2008-1045 1 PoC Analysis EPSS 0.01
Alkacon Opencms < 7.0.4 - XSS
Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_files.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the resource parameter.
CWE-79 Feb 27, 2008
CVE-2007-5333 1 PoC Analysis EPSS 0.82
Apache Tomcat < 4.1.36 - Information Disclosure
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
CWE-200 Feb 12, 2008
CVE-2007-5461 2 PoCs Analysis EPSS 0.06
Apache Tomcat - Path Traversal
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
CWE-22 Oct 15, 2007
CVE-2007-3382 1 PoC Analysis EPSS 0.84
Apache Tomcat - Information Disclosure
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
CWE-200 Aug 14, 2007
CVE-2007-2449 1 PoC Analysis NUCLEI EPSS 0.49
Apache Tomcat <6.0.14 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.
Jun 14, 2007
CVE-2007-1355 1 PoC Analysis EPSS 0.84
Apache Tomcat < 4.1.37 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.
May 21, 2007
CVE-2007-2353 1 PoC Analysis EPSS 0.04
Apache Axis 1.0 - Info Disclosure
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
CWE-200 Apr 30, 2007
CVE-2007-0450 1 PoC Analysis EPSS 0.91
Apache HTTP Server < 5.5.22 - Path Traversal
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
CWE-22 Mar 16, 2007
CVE-2006-2758 1 PoC Analysis EPSS 0.02
Jetty - Path Traversal
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.
CWE-22 Jun 02, 2006
CVE-2006-7196 1 PoC Analysis EPSS 0.80
Apache Tomcat < 4.1.31 - XSS
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
CWE-79 May 10, 2007
CVE-2006-3835 1 PoC Analysis EPSS 0.56
Apache Tomcat <5.5.17 - Path Traversal
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.
Jul 25, 2006
CVE-2006-0254 2 PoCs Analysis EPSS 0.45
Apache Geronimo < 1.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.
Jan 18, 2006
CVE-2005-3747 1 PoC Analysis EPSS 0.19
Mortbay Jetty < 5.1.5 - Information Disclosure
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.
CWE-200 Nov 22, 2005
CVE-2005-3745 1 PoC Analysis EPSS 0.59
Apache Struts - XSS
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
Nov 22, 2005
CVE-2005-4703 1 PoC Analysis EPSS 0.18
Apache Tomcat 4.0.3 - Info Disclosure
Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
Dec 31, 2005
CVE-2003-0866 1 PoC Analysis EPSS 0.20
Tomcat 4.0.x - DoS
The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
Nov 17, 2003
CVE-2003-0042 1 PoC Analysis EPSS 0.56
Jakarta Tomcat <3.3.1a - Info Disclosure
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
Feb 07, 2003
CVE-2002-2272 1 PoC Analysis EPSS 0.31
Apache HTTP Server - Memory Corruption
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
CWE-119 Dec 31, 2002