Exploit Intelligence Platform

Updated 5m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,363 CVEs tracked 53,626 with exploits 4,858 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,288 vendors 43,844 researchers
366 results Clear all
CVE-2018-3729 7.5 HIGH 1 PoC Analysis EPSS 0.00
Localhost-now < 1.0.2 - Path Traversal
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CWE-22 Jun 07, 2018
CVE-2018-3727 7.5 HIGH 1 PoC Analysis EPSS 0.00
626 - Path Traversal
626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CWE-22 Jun 07, 2018
CVE-2018-3726 6.1 MEDIUM 1 PoC 1 Writeup Analysis EPSS 0.00
Crud-file-server < 0.8.0 - XSS
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
CWE-79 Jun 07, 2018
CVE-2018-3725 7.5 HIGH 1 PoC Analysis EPSS 0.00
Hekto < 0.2.3 - Path Traversal
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CWE-22 Jun 07, 2018
CVE-2018-3724 7.5 HIGH 1 PoC Analysis EPSS 0.01
General-file-server - Path Traversal
general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which allows a malicious user to read content of any file with known path.
CWE-22 Jun 07, 2018
CVE-2018-3717 5.4 MEDIUM 1 PoC 1 Writeup Analysis EPSS 0.00
Sencha Connect < 2.14.0 - XSS
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
CWE-79 Jun 07, 2018
CVE-2018-3716 5.4 MEDIUM 1 PoC Analysis EPSS 0.00
Simplehttpserver < 0.1.0 - XSS
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
CWE-79 Jun 07, 2018
CVE-2018-3715 6.5 MEDIUM 1 PoC 1 Writeup Analysis EPSS 0.00
Glance < 3.0.4 - Path Traversal
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
CWE-22 Jun 07, 2018
CVE-2018-3714 6.5 MEDIUM 1 PoC Analysis NUCLEI EPSS 0.73
Node-srv < 2.1.1 - Path Traversal
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
CWE-22 Jun 07, 2018
CVE-2018-3713 6.5 MEDIUM 1 PoC Analysis EPSS 0.00
Angular-http-server < 1.6.0 - Path Traversal
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.
CWE-22 Jun 07, 2018
CVE-2018-3712 6.5 MEDIUM 1 PoC Analysis EPSS 0.01
Zeit Serve < 6.4.9 - Path Traversal
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of any directory with known path.
CWE-22 Jun 07, 2018
CVE-2018-3755 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Sexstatic - XSS
XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with <iframe> element used in directory name.
CWE-79 Jun 01, 2018
CVE-2018-3744 9.8 CRITICAL 1 PoC Analysis EPSS 0.00
Html-pages - Path Traversal
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
CWE-22 May 29, 2018
CVE-2018-3734 7.5 HIGH 1 PoC Analysis EPSS 0.00
Stattic < 0.3.0 - Path Traversal
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path.
CWE-22 May 29, 2018
CVE-2018-3733 7.5 HIGH 1 PoC 1 Writeup Analysis EPSS 0.00
Crud-file-server < 0.9.0 - Path Traversal
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.
CWE-22 May 29, 2018
CVE-2018-9207 9.8 CRITICAL 1 PoC Analysis EPSS 0.29
Hayageek Jquery Upload File < 4.0.2 - Unrestricted File Upload
Arbitrary file upload in jQuery Upload File <= 4.0.2
CWE-434 Nov 19, 2018
CVE-2018-13797 9.8 CRITICAL 1 PoC Analysis EPSS 0.11
Node-macaddress < 0.2.9 - OS Command Injection
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
CWE-78 Jul 10, 2018
CVE-2018-16492 9.8 CRITICAL 1 PoC Analysis EPSS 0.03
Extend < 2.0.2 - Denial of Service
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
CWE-74 Feb 01, 2019
CVE-2018-3786 9.8 CRITICAL 1 PoC Analysis EPSS 0.10
Eggjs Egg-scripts < 2.8.1 - Command Injection
A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument.
CWE-78 Aug 24, 2018
CVE-2017-16086 7.5 HIGH 1 PoC Analysis EPSS 0.58
Ua-parser - Denial of Service
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
CWE-400 Jun 07, 2018