Exploit Intelligence Platform
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
366 results
Clear all
CVE-2018-3729
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Localhost-now < 1.0.2 - Path Traversal
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CWE-22
Jun 07, 2018
CVE-2018-3727
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
626 - Path Traversal
626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CWE-22
Jun 07, 2018
CVE-2018-3726
6.1
MEDIUM
1 PoC
1 Writeup
Analysis
EPSS 0.00
Crud-file-server < 0.8.0 - XSS
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
CWE-79
Jun 07, 2018
CVE-2018-3725
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Hekto < 0.2.3 - Path Traversal
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CWE-22
Jun 07, 2018
CVE-2018-3724
7.5
HIGH
1 PoC
Analysis
EPSS 0.01
General-file-server - Path Traversal
general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which allows a malicious user to read content of any file with known path.
CWE-22
Jun 07, 2018
CVE-2018-3717
5.4
MEDIUM
1 PoC
1 Writeup
Analysis
EPSS 0.00
Sencha Connect < 2.14.0 - XSS
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
CWE-79
Jun 07, 2018
CVE-2018-3716
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.00
Simplehttpserver < 0.1.0 - XSS
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
CWE-79
Jun 07, 2018
CVE-2018-3715
6.5
MEDIUM
1 PoC
1 Writeup
Analysis
EPSS 0.00
Glance < 3.0.4 - Path Traversal
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
CWE-22
Jun 07, 2018
CVE-2018-3714
6.5
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.73
Node-srv < 2.1.1 - Path Traversal
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
CWE-22
Jun 07, 2018
CVE-2018-3713
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.00
Angular-http-server < 1.6.0 - Path Traversal
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.
CWE-22
Jun 07, 2018
CVE-2018-3712
6.5
MEDIUM
1 PoC
Analysis
EPSS 0.01
Zeit Serve < 6.4.9 - Path Traversal
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of any directory with known path.
CWE-22
Jun 07, 2018
CVE-2018-3755
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.00
Sexstatic - XSS
XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with <iframe> element used in directory name.
CWE-79
Jun 01, 2018
CVE-2018-3744
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.00
Html-pages - Path Traversal
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
CWE-22
May 29, 2018
CVE-2018-3734
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Stattic < 0.3.0 - Path Traversal
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path.
CWE-22
May 29, 2018
CVE-2018-3733
7.5
HIGH
1 PoC
1 Writeup
Analysis
EPSS 0.00
Crud-file-server < 0.9.0 - Path Traversal
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.
CWE-22
May 29, 2018
CVE-2018-9207
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.29
Hayageek Jquery Upload File < 4.0.2 - Unrestricted File Upload
Arbitrary file upload in jQuery Upload File <= 4.0.2
CWE-434
Nov 19, 2018
CVE-2018-13797
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.11
Node-macaddress < 0.2.9 - OS Command Injection
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
CWE-78
Jul 10, 2018
CVE-2018-16492
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.03
Extend < 2.0.2 - Denial of Service
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
CWE-74
Feb 01, 2019
CVE-2018-3786
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.10
Eggjs Egg-scripts < 2.8.1 - Command Injection
A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument.
CWE-78
Aug 24, 2018
CVE-2017-16086
7.5
HIGH
1 PoC
Analysis
EPSS 0.58
Ua-parser - Denial of Service
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
CWE-400
Jun 07, 2018