CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,687 CVEs tracked 53,322 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,014 vendors 42,676 researchers
111,134 results Clear all
CVE-2016-7615 5.5 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Denial of Service
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component, which allows local users to cause a denial of service via unspecified vectors.
Feb 20, 2017
CVE-2016-7614 5.5 MEDIUM EPSS 0.00
Apple Icloud < 6.0.1 - Information Disclosure
An issue was discovered in certain Apple products. iCloud before 6.1 is affected. The issue involves the "Windows Security" component. It allows local users to obtain sensitive information from iCloud desktop-client process memory via unspecified vectors.
CWE-200 Feb 20, 2017
CVE-2016-7609 6.2 MEDIUM EPSS 0.00
Apple Mac OS X < 10.12.1 - NULL Pointer Dereference
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "AppleGraphicsPowerManagement" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
CWE-476 Feb 20, 2017
CVE-2016-7608 5.5 MEDIUM 2 PoCs Analysis EPSS 0.01
Apple Mac OS X < 10.12.1 - Information Disclosure
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireFamily" component, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.
CWE-200 Feb 20, 2017
CVE-2016-7607 5.5 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component, which allows attackers to obtain sensitive information from kernel memory via a crafted app.
CWE-200 Feb 20, 2017
CVE-2016-7605 5.5 MEDIUM EPSS 0.00
Apple Mac OS X < 10.12.1 - NULL Pointer Dereference
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
CWE-476 Feb 20, 2017
CVE-2016-7604 5.5 MEDIUM EPSS 0.00
Apple Mac OS X < 10.12.1 - NULL Pointer Dereference
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreCapture" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
CWE-476 Feb 20, 2017
CVE-2016-7603 5.5 MEDIUM EPSS 0.00
Apple Mac OS X < 10.12.1 - NULL Pointer Dereference
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreStorage" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
CWE-476 Feb 20, 2017
CVE-2016-7601 6.8 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Security Feature Bypass
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Local Authentication" component, which does not honor the configured screen-lock time interval if the Touch ID prompt is visible.
CWE-254 Feb 20, 2017
CVE-2016-7600 6.2 MEDIUM EPSS 0.00
Apple Mac OS X < 10.12.1 - Information Disclosure
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "OpenPAM" component, which allows local users to obtain sensitive information by leveraging mishandling of failed PAM authentication by a sandboxed app.
CWE-200 Feb 20, 2017
CVE-2016-7599 6.5 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses HTTP redirects.
CWE-200 Feb 20, 2017
CVE-2016-7598 6.5 MEDIUM EPSS 0.01
Apple Iphone OS < 10.1.1 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2016-7597 4.6 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Security Feature Bypass
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to maintain the unlocked state via vectors related to Handoff with Siri.
CWE-254 Feb 20, 2017
CVE-2016-7592 4.3 MEDIUM EPSS 0.01
Apple Iphone OS < 10.1.1 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.
CWE-200 Feb 20, 2017
CVE-2016-7591 6.5 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Use After Free
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOHIDFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
CWE-416 Feb 20, 2017
CVE-2016-7586 6.5 MEDIUM EPSS 0.01
Apple Iphone OS < 10.1.1 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2016-7581 4.3 MEDIUM EPSS 0.00
Apple Iphone OS < 10.0.3 - Improper Input Validation
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "Safari" component, which allows remote web servers to cause a denial of service via a crafted URL.
CWE-20 Feb 20, 2017
CVE-2016-7580 6.5 MEDIUM EPSS 0.00
Apple Mac OS X < 10.11.6 - Improper Input Validation
An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves the "Mail" component, which allows remote web servers to cause a denial of service via a crafted URL.
CWE-20 Feb 20, 2017
CVE-2016-7579 5.9 MEDIUM EPSS 0.01
Apple Iphone OS < 10.1 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "CFNetwork Proxies" component, which allows man-in-the-middle attackers to spoof a proxy password authentication requirement and obtain sensitive information.
CWE-200 Feb 20, 2017
CVE-2016-4781 6.8 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Security Feature Bypass
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to bypass the passcode attempt counter and unlock a device via unspecified vectors.
CWE-254 Feb 20, 2017