CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,716 CVEs tracked 53,323 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,939 Nuclei templates 49,017 vendors 42,676 researchers
111,142 results Clear all
CVE-2016-9261 5.4 MEDIUM EPSS 0.00
Tenable LCE <4.8.1 - XSS
Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 28, 2017
CVE-2016-9259 5.4 MEDIUM EPSS 0.00
Tenable Nessus <6.9.1 - XSS
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Feb 28, 2017
CVE-2016-9818 6.5 MEDIUM EPSS 0.00
Xen - Improper Access Control
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at HYP.
CWE-284 Feb 27, 2017
CVE-2016-9817 6.5 MEDIUM EPSS 0.00
Xen - Improper Access Control
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESR_EL2.EA bit set.
CWE-284 Feb 27, 2017
CVE-2016-9816 6.5 MEDIUM EPSS 0.00
Xen - Improper Access Control
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2.
CWE-284 Feb 27, 2017
CVE-2016-9815 6.5 MEDIUM EPSS 0.00
Xen - Improper Access Control
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host panic) by sending an asynchronous abort.
CWE-284 Feb 27, 2017
CVE-2016-5240 5.5 MEDIUM EPSS 0.01
Graphicsmagick < 1.3.23 - Improper Input Validation
The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.
CWE-20 Feb 27, 2017
CVE-2016-10029 5.5 MEDIUM EPSS 0.00
QEMU - DoS
The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a scanout id in a VIRTIO_GPU_CMD_SET_SCANOUT command larger than num_scanouts.
CWE-125 Feb 27, 2017
CVE-2016-10028 5.5 MEDIUM EPSS 0.00
QEMU - DoS
The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a VIRTIO_GPU_CMD_GET_CAPSET command with a maximum capabilities size with a value of 0.
CWE-125 Feb 27, 2017
CVE-2015-8903 6.5 MEDIUM EPSS 0.01
Imagemagick < 6.9.0-5 - Infinite Loop
The ReadVICARImage function in coders/vicar.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted VICAR file.
CWE-835 Feb 27, 2017
CVE-2015-8902 6.5 MEDIUM EPSS 0.00
Imagemagick < 6.9.0-5 - Infinite Loop
The ReadBlobByte function in coders/pdb.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted PDB file.
CWE-835 Feb 27, 2017
CVE-2015-8901 6.5 MEDIUM EPSS 0.00
Imagemagick < 6.9.0-5 - Infinite Loop
ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted MIFF file.
CWE-835 Feb 27, 2017
CVE-2015-8900 5.5 MEDIUM EPSS 0.00
Imagemagick < 6.9.3-10 - Infinite Loop
The ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows remote attackers to cause a denial of service (infinite loop) via a crafted HDR file.
CWE-835 Feb 27, 2017
CVE-2016-8105 6.5 MEDIUM EPSS 0.00
Intel Ethernet Controller <22.0 - DoS
Drivers for the Intel Ethernet Controller X710 and Intel Ethernet Controller XL710 families before version 22.0 are vulnerable to a denial of service in certain layer 2 network configurations.
Feb 27, 2017
CVE-2017-6344 5.9 MEDIUM EPSS 0.00
Grails Pdf Plugin - XXE
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.
CWE-611 Feb 27, 2017
CVE-2017-6341 5.9 MEDIUM EPSS 0.00
Dahuasecurity Camera Firmware - Cleartext Transmission
Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Application, and Desktop Application interfaces, which allows remote attackers to obtain sensitive information by sniffing the network, a different vulnerability than CVE-2013-6117.
CWE-319 Feb 27, 2017
CVE-2017-6297 5.9 MEDIUM EPSS 0.00
Mikrotik Routeros - Missing Encryption
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.
CWE-311 Feb 27, 2017
CVE-2016-5027 5.5 MEDIUM EPSS 0.00
Libdwarf - NULL Pointer Dereference
dwarf_form.c in libdwarf 20160115 allows remote attackers to cause a denial of service (crash) via a crafted elf file.
CWE-476 Feb 24, 2017
CVE-2016-4493 5.5 MEDIUM EPSS 0.00
GNU Libiberty - Out-of-Bounds Read
The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted binary.
CWE-125 Feb 24, 2017
CVE-2016-4492 4.4 MEDIUM EPSS 0.00
GNU Libiberty - Memory Corruption
Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
CWE-119 Feb 24, 2017