Exploit Intelligence Platform
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
846 results
Clear all
CVE-2002-1533
1 PoC
Analysis
EPSS 0.05
Jetty JSP - XSS
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).
Mar 31, 2003
CVE-2002-1148
1 PoC
Analysis
EPSS 0.67
Tomcat <4.1.10 - Info Disclosure
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
Oct 11, 2002
CVE-2002-1567
1 PoC
Analysis
EPSS 0.42
Apache Tomcat 4.1 - XSS
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
Oct 06, 2003
CVE-2002-2006
1 PoC
Analysis
EPSS 0.32
Apache Tomcat <4.1, <3.3.1 - Info Disclosure
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
Dec 31, 2002
CVE-2001-0590
1 PoC
Analysis
EPSS 0.48
Apache Tomcat Servlet <3.2.2 - Info Disclosure
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
Aug 02, 2001
CVE-2000-0759
1 PoC
Analysis
EPSS 0.40
Jakarta Tomcat 3.1 - Info Disclosure
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
Oct 20, 2000