Exploit Intelligence Platform
Updated 4h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
77 results
Clear all
CVE-2019-11358
6.1
MEDIUM
EXPLOITED
7 PoCs
Analysis
EPSS 0.02
jQuery <3.4.0 - Info Disclosure
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
CWE-1321
Apr 20, 2019
CVE-2019-5418
7.5
HIGH
KEV
12 PoCs
Analysis
NUCLEI
EPSS 0.94
Ruby On Rails File Content Disclosure (
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
CWE-22
Mar 27, 2019
CVE-2019-5420
9.8
CRITICAL
14 PoCs
Analysis
EPSS 0.94
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
CWE-330
Mar 27, 2019
CVE-2019-8331
6.1
MEDIUM
3 PoCs
Analysis
EPSS 0.02
Bootstrap < 3.4.1 - XSS
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
CWE-79
Feb 20, 2019
CVE-2019-19919
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.18
Handlebars.js < 5.19.0 - Prototype Pollution
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
CWE-1321
Dec 20, 2019
CVE-2019-15224
9.8
CRITICAL
1 PoC
Analysis
EPSS 0.02
Rest-client < 1.6.13 - Code Injection
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.
CWE-94
Aug 19, 2019
CVE-2019-13574
7.8
HIGH
1 PoC
Analysis
EPSS 0.29
MiniMagick <4.9.4 - RCE
In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a '|' character followed by a command.
CWE-78
Jul 12, 2019
CVE-2019-10226
5.4
MEDIUM
1 PoC
Analysis
EPSS 0.02
Fat Free CRM v0.19.0 - HTML Injection
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is a XSS protection mechanism.
CWE-79
Jun 10, 2019
CVE-2018-14040
6.1
MEDIUM
2 PoCs
Analysis
EPSS 0.03
Bootstrap <4.1.2 - XSS
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
CWE-79
Jul 13, 2018
CVE-2018-3760
7.5
HIGH
EXPLOITED
3 PoCs
Analysis
NUCLEI
EPSS 0.94
Redhat Cloudforms < 2.12.4 - Information Disclosure
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.
CWE-22
Jun 26, 2018
CVE-2018-25032
7.5
HIGH
3 PoCs
Analysis
EPSS 0.00
zlib <1.2.12 - Memory Corruption
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
CWE-787
Mar 25, 2022
CVE-2018-14042
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.02
Bootstrap <4.1.2 - XSS
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
CWE-79
Jul 13, 2018
CVE-2018-14041
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.08
Bootstrap <4.1.2 - XSS
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
CWE-79
Jul 13, 2018
CVE-2018-18307
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.00
Alchemy-cms Alchemy Cms - XSS
A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route. Without that session cookie, the request would have been rejected as unauthorized."
CWE-79
Oct 16, 2018
CVE-2017-15412
8.8
HIGH
2 PoCs
Analysis
EPSS 0.02
Redhat Enterprise Linux Desktop < 63.0.3239.84 - Use After Free
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CWE-416
Aug 28, 2018
CVE-2017-0901
7.5
HIGH
1 PoC
Analysis
EPSS 0.19
RubyGems <2.6.12 - Code Injection
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
CWE-22
Aug 31, 2017
CVE-2016-2098
7.3
HIGH
15 PoCs
Analysis
EPSS 0.87
Debian Linux < 3.2.22.1 - Improper Input Validation
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
CWE-20
Apr 07, 2016
CVE-2016-0752
7.5
HIGH
KEV
4 PoCs
Analysis
EPSS 0.91
Ruby on Rails Dynamic Render File Upload Remote Code Execution
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
CWE-22
Feb 16, 2016
CVE-2016-10735
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.07
Bootstrap < 3.4.0 - XSS
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
CWE-79
Jan 09, 2019
CVE-2016-6317
7.5
HIGH
1 PoC
Analysis
EPSS 0.00
Ruby on Rails 4.2.x <4.2.7.1 - Info Disclosure
Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.
CWE-284
Sep 07, 2016