Exploit Intelligence Platform

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,361 CVEs tracked 53,621 with exploits 4,857 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,840 researchers
846 results Clear all
CVE-2002-1533 1 PoC Analysis EPSS 0.05
Jetty JSP - XSS
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).
Mar 31, 2003
CVE-2002-1148 1 PoC Analysis EPSS 0.67
Tomcat <4.1.10 - Info Disclosure
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
Oct 11, 2002
CVE-2002-1567 1 PoC Analysis EPSS 0.42
Apache Tomcat 4.1 - XSS
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
Oct 06, 2003
CVE-2002-2006 1 PoC Analysis EPSS 0.32
Apache Tomcat <4.1, <3.3.1 - Info Disclosure
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
Dec 31, 2002
CVE-2001-0590 1 PoC Analysis EPSS 0.48
Apache Tomcat Servlet <3.2.2 - Info Disclosure
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
Aug 02, 2001
CVE-2000-0759 1 PoC Analysis EPSS 0.40
Jakarta Tomcat 3.1 - Info Disclosure
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
Oct 20, 2000