CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,687 CVEs tracked 53,322 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,014 vendors 42,676 researchers
111,134 results Clear all
CVE-2016-4721 5.9 MEDIUM EPSS 0.00
Apple Iphone OS < 10.0.3 - Security Feature Bypass
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "IDS - Connectivity" component, which allows man-in-the-middle attackers to spoof calls via a "switch caller" notification.
CWE-254 Feb 20, 2017
CVE-2016-4690 6.8 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1.1 - Improper Input Validation
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Image Capture" component, which allows attackers to execute arbitrary code via a crafted USB HID device.
CWE-20 Feb 20, 2017
CVE-2016-4686 4.4 MEDIUM EPSS 0.00
Apple Iphone OS < 10.0.3 - Access Control
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "Contacts" component, which does not prevent an app's Address Book access after access revocation.
CWE-264 Feb 20, 2017
CVE-2016-4685 5.9 MEDIUM EPSS 0.00
Apple Iphone OS < 10.0.3 - Weak Encryption
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "iTunes Backup" component, which improperly hashes passwords, making it easier to decrypt files.
CWE-326 Feb 20, 2017
CVE-2016-4680 5.5 MEDIUM EPSS 0.00
Apple Iphone OS < 10.1 - Information Disclosure
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.
CWE-200 Feb 20, 2017
CVE-2016-4679 5.5 MEDIUM EPSS 0.01
Apple Iphone OS < 10.1 - Symlink Following
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libarchive" component, which allows remote attackers to write to arbitrary files via a crafted archive containing a symlink.
CWE-59 Feb 20, 2017
CVE-2016-4663 5.5 MEDIUM EPSS 0.00
Apple Mac OS X < 10.12.0 - Memory Corruption
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to cause a denial of service (memory corruption) via a crafted app.
CWE-119 Feb 20, 2017
CVE-2016-4661 5.5 MEDIUM EPSS 0.00
Apple Mac OS X < 10.12.0 - Improper Input Validation
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ntfs" component, which misparses disk images and allows attackers to cause a denial of service via a crafted app.
CWE-20 Feb 20, 2017
CVE-2016-4613 6.5 MEDIUM EPSS 0.01
Apple Safari < 10.0.0 - Information Disclosure
An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site.
CWE-200 Feb 20, 2017
CVE-2017-5986 5.5 MEDIUM 1 Writeup EPSS 0.01
Linux Kernel < 4.9.11 - Race Condition
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.
CWE-362 Feb 18, 2017
CVE-2016-7511 5.5 MEDIUM EPSS 0.00
Libdwarf - Integer Overflow
Integer overflow in the dwarf_die_deliv.c in libdwarf 20160613 allows remote attackers to cause a denial of service (crash) via a crafted file.
CWE-190 Feb 17, 2017
CVE-2016-7510 6.5 MEDIUM EPSS 0.01
Libdwarf < 2016-09-23 - Out-of-Bounds Read
The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.
CWE-125 Feb 17, 2017
CVE-2016-7111 4.7 MEDIUM EPSS 0.00
Mantisbt < 1.3.0 - XSS
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
CWE-79 Feb 17, 2017
CVE-2016-6191 6.1 MEDIUM EPSS 0.00
SOGo <3.1.3 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Description, (2) Location, (3) URL, or (4) Title field.
CWE-79 Feb 17, 2017
CVE-2016-6190 4.3 MEDIUM EPSS 0.00
SOGo <2.3.12-3.1.1 - Info Disclosure
SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.
CWE-200 Feb 17, 2017
CVE-2016-6189 4.3 MEDIUM EPSS 0.00
SOGo <3.1.1 - Info Disclosure
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.
CWE-184 Feb 17, 2017
CVE-2016-5364 6.1 MEDIUM EPSS 0.00
Mantisbt < 1.2.19 - XSS
Cross-site scripting (XSS) vulnerability in manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier allows remote attackers to inject arbitrary web script or HTML via the return parameter.
CWE-79 Feb 17, 2017
CVE-2016-5037 6.5 MEDIUM EPSS 0.01
Libdwarf < 2016-09-23 - NULL Pointer Dereference
The _dwarf_load_section function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Feb 17, 2017
CVE-2016-5035 6.5 MEDIUM EPSS 0.01
Libdwarf < 2016-09-23 - Out-of-Bounds Read
The _dwarf_read_line_table_header function in dwarf_line_table_reader.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
CWE-125 Feb 17, 2017
CVE-2016-5034 6.5 MEDIUM EPSS 0.01
Libdwarf < 2016-09-23 - Out-of-Bounds Write
dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file, related to relocation records.
CWE-787 Feb 17, 2017