CVE & Exploit Intelligence Database

Updated 51m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,716 CVEs tracked 53,323 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,939 Nuclei templates 49,017 vendors 42,676 researchers
111,142 results Clear all
CVE-2016-9909 6.1 MEDIUM 1 Writeup EPSS 0.00
Html5lib < 0.99999999 - XSS
The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.
CWE-79 Feb 22, 2017
CVE-2016-9384 6.5 MEDIUM EPSS 0.00
Xen 4.7 - Info Disclosure
Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.
CWE-200 Feb 22, 2017
CVE-2016-9378 5.5 MEDIUM EPSS 0.00
Xen 4.5.x-4.7.x - DoS
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.
CWE-284 Feb 22, 2017
CVE-2016-9377 5.5 MEDIUM EPSS 0.00
Xen 4.5.x-4.7.x - DoS
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
CWE-682 Feb 22, 2017
CVE-2017-3847 5.4 MEDIUM EPSS 0.00
Cisco Firepower Management Center - XSS
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releases: 6.2.1.
CWE-79 Feb 22, 2017
CVE-2017-3845 6.1 MEDIUM EPSS 0.00
Cisco Prime Collaboration Assurance <11.0 - XSS
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc77783. Known Affected Releases: 11.5(0).
CWE-79 Feb 22, 2017
CVE-2017-3844 4.3 MEDIUM EPSS 0.00
Cisco Prime Collaboration Assurance <11.0 - Info Disclosure
A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc86238. Known Affected Releases: 11.5(0).
CWE-20 Feb 22, 2017
CVE-2017-3843 4.3 MEDIUM EPSS 0.00
Cisco Prime Collaboration Assurance - Privilege Escalation
A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0).
CWE-20 Feb 22, 2017
CVE-2017-3842 5.3 MEDIUM EPSS 0.00
Cisco IDM <7.2.1V7 - Info Disclosure
A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, remote attacker to view sensitive information stored in certain HTML comments. More Information: CSCuh91455. Known Affected Releases: 7.2(1)V7.
CWE-200 Feb 22, 2017
CVE-2017-3840 6.1 MEDIUM EPSS 0.00
Cisco ACS <5.8(2.5) - Open Redirect
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect Vulnerability. More Information: CSCvc04849. Known Affected Releases: 5.8(2.5).
CWE-601 Feb 22, 2017
CVE-2017-3839 4.3 MEDIUM EPSS 0.00
Cisco ACS <5.8.2.5 - XSS
An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc04845. Known Affected Releases: 5.8(2.5).
CWE-611 Feb 22, 2017
CVE-2017-3838 6.1 MEDIUM EPSS 0.00
Cisco Secure Access Control System <5.8(2.5) - XSS
A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc04838. Known Affected Releases: 5.8(2.5).
CWE-79 Feb 22, 2017
CVE-2017-3836 4.3 MEDIUM EPSS 0.00
Cisco Unified Communications Manager - Info Disclosure
A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. More Information: CSCvb61689. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.162) 12.0(0.98000.178) 12.0(0.98000.383) 12.0(0.98000.488) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).
CWE-200 Feb 22, 2017
CVE-2017-3833 6.1 MEDIUM EPSS 0.00
Cisco Unified Communications Manager - XSS
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb95951. Known Affected Releases: 12.0(0.99999.2). Known Fixed Releases: 11.0(1.23064.1) 11.5(1.12031.1) 11.5(1.12900.21) 11.5(1.12900.7) 11.5(1.12900.8) 11.6(1.10000.4) 12.0(0.98000.155) 12.0(0.98000.178) 12.0(0.98000.366) 12.0(0.98000.367) 12.0(0.98000.468) 12.0(0.98000.469) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).
CWE-79 Feb 22, 2017
CVE-2017-3829 6.1 MEDIUM EPSS 0.00
Cisco Unified Communications Manager Switches - XSS
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc30999. Known Affected Releases: 12.0(0.98000.280). Known Fixed Releases: 11.0(1.23900.3) 12.0(0.98000.180) 12.0(0.98000.422) 12.0(0.98000.541) 12.0(0.98000.6).
CWE-79 Feb 22, 2017
CVE-2017-3828 6.1 MEDIUM EPSS 0.00
Cisco Unified Communications Manager Switches - XSS
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvb98777. Known Affected Releases: 11.0(1.10000.10) 11.5(1.10000.6). Known Fixed Releases: 11.0(1.23063.1) 11.5(1.12029.1) 11.5(1.12900.11) 11.5(1.12900.21) 11.6(1.10000.4) 12.0(0.98000.156) 12.0(0.98000.178) 12.0(0.98000.369) 12.0(0.98000.470) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).
CWE-79 Feb 22, 2017
CVE-2017-3827 5.8 MEDIUM EPSS 0.00
Cisco AsyncOS < - Auth Bypass
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. More Information: SCvb91473, CSCvc76500. Known Affected Releases: 10.0.0-203 9.9.9-894 WSA10.0.0-233.
CWE-20 Feb 22, 2017
CVE-2017-3821 6.1 MEDIUM EPSS 0.00
Cisco Unified Communications Manager <12.0 - XSS
A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvc49348. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.209) 12.0(0.98000.478) 12.0(0.98000.609).
CWE-79 Feb 22, 2017
CVE-2015-4056 6.7 MEDIUM EPSS 0.00
Dell Vce Vision Intelligent Operations < 2.6.4 - Cryptographic Issue
The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by leveraging administrative access.
CWE-310 Feb 21, 2017
CVE-2017-6078 5.5 MEDIUM 1 Writeup EPSS 0.00
Faststone Maxview - Improper Input Validation
FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section.
CWE-20 Feb 21, 2017