CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,716 CVEs tracked 53,323 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,939 Nuclei templates 49,017 vendors 42,676 researchers
111,206 results Clear all
CVE-2016-7139 6.1 MEDIUM EPSS 0.00
Plone < 5.0.6 - XSS
Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CWE-79 Mar 07, 2017
CVE-2016-7138 6.1 MEDIUM EPSS 0.00
Plone - XSS
Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CWE-79 Mar 07, 2017
CVE-2016-7137 6.1 MEDIUM EPSS 0.00
Plone - Open Redirect
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.
CWE-601 Mar 07, 2017
CVE-2016-7136 6.1 MEDIUM EPSS 0.00
Plone - XSS
z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request.
CWE-79 Mar 07, 2017
CVE-2016-7135 4.9 MEDIUM EPSS 0.01
Plone < 5.0.7 - Path Traversal
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.
CWE-22 Mar 07, 2017
CVE-2016-6522 5.5 MEDIUM EPSS 0.00
OpenBSD 5.9 - DoS
Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping.
CWE-190 Mar 07, 2017
CVE-2016-6350 5.5 MEDIUM EPSS 0.00
OpenBSD <5.10 - DoS
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9.
CWE-476 Mar 07, 2017
CVE-2016-6247 5.5 MEDIUM EPSS 0.00
OpenBSD <5.10 - DoS
OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist.
CWE-20 Mar 07, 2017
CVE-2016-6246 4.4 MEDIUM EPSS 0.00
OpenBSD 5.8-5.9 - DoS
OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to cause a denial of service (kernel panic) by mounting a tmpfs with a VNOVAL in the (1) username, (2) groupname, or (3) device name of the root node.
CWE-20 Mar 07, 2017
CVE-2016-6245 5.5 MEDIUM EPSS 0.00
OpenBSD <5.10 - DoS
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a large size in a getdents system call.
Mar 07, 2017
CVE-2016-6243 5.5 MEDIUM EPSS 0.00
OpenBSD <5.10 - DoS
thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call.
CWE-20 Mar 07, 2017
CVE-2016-6242 5.5 MEDIUM EPSS 0.00
OpenBSD <5.10 - DoS
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ident value in a kevent system call.
CWE-189 Mar 07, 2017
CVE-2016-6239 5.5 MEDIUM EPSS 0.00
OpenBSD <5.10 - DoS
The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.
CWE-20 Mar 07, 2017
CVE-2016-4948 6.1 MEDIUM EPSS 0.00
Cloudera Manager < 5.5.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Template Name field when renaming a template; (2) KDC Server host, (3) Kerberos Security Realm, (4) Kerberos Encryption Types, (5) Advanced Configuration Snippet (Safety Valve) for [libdefaults] section of krb5.conf, (6) Advanced Configuration Snippet (Safety Valve) for the Default Realm in krb5.conf, (7) Advanced Configuration Snippet (Safety Valve) for remaining krb5.conf, or (8) Active Directory Account Prefix fields in the Kerberos wizard; or (9) classicWizard parameter to cmf/cloudera-director/redirect.
CWE-79 Mar 07, 2017
CVE-2016-4947 5.3 MEDIUM EPSS 0.00
Cloudera Hue < 3.9.0 - Information Disclosure
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.
CWE-200 Mar 07, 2017
CVE-2016-4946 6.1 MEDIUM EPSS 0.00
Cloudera Hue < 3.9.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE 3.9.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name or (2) Last name field in the HUE Users page.
CWE-79 Mar 07, 2017
CVE-2016-9148 6.1 MEDIUM EPSS 0.00
CA Service Desk Manager <14.1 - XSS
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the QBE.EQ.REF_NUM parameter.
CWE-79 Mar 07, 2017
CVE-2016-5315 5.5 MEDIUM EPSS 0.00
Libtiff < 4.0.6 - Out-of-Bounds Read
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
CWE-125 Mar 07, 2017
CVE-2016-10040 5.5 MEDIUM EPSS 0.01
Qt 4.8.5 - Buffer Overflow
Stack-based buffer overflow in QXmlSimpleReader in Qt 4.8.5 allows remote attackers to cause a denial of service (application crash) via a xml file with multiple nested open tags.
CWE-119 Mar 07, 2017
CVE-2013-5653 5.5 MEDIUM EPSS 0.00
Artifex Afpl Ghostscript - Information Disclosure
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.
CWE-200 Mar 07, 2017