CVE & Exploit Intelligence Database

Updated 45m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,640 CVEs tracked 53,321 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 49,006 vendors 42,664 researchers
111,112 results Clear all
CVE-2017-3814 5.8 MEDIUM EPSS 0.00
Cisco Firepower System Software - Auth Bypass
A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a URL Bypass. More Information: CSCvb93980. Known Affected Releases: 5.3.0 5.4.0 6.0.0 6.0.1 6.1.0.
CWE-20 Feb 03, 2017
CVE-2017-3812 6.8 MEDIUM EPSS 0.01
Cisco Industrial Ethernet - DoS
A vulnerability in the implementation of Common Industrial Protocol (CIP) functionality in Cisco Industrial Ethernet 2000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to a system memory leak. More Information: CSCvc54788. Known Affected Releases: 15.2(5.4.32i)E2. Known Fixed Releases: 15.2(5.4.62i)E2.
CWE-772 Feb 03, 2017
CVE-2017-3810 5.4 MEDIUM EPSS 0.00
Cisco Prime Service Catalog <10.0_R2_tanggula - Open Redirect
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Known Affected Releases: 10.0_R2_tanggula.
CWE-601 Feb 03, 2017
CVE-2017-3809 5.8 MEDIUM EPSS 0.00
Cisco Firepower Management Center - DoS
A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Releases: 6.1.0 6.2.0. Known Fixed Releases: 6.1.0.1 6.2.0.
CWE-20 Feb 03, 2017
CVE-2017-3806 5.3 MEDIUM EPSS 0.00
Cisco Firepower - Command Injection
A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are executed by the device. More Information: CSCvb61343. Known Affected Releases: 2.0(1.68). Known Fixed Releases: 2.0(1.118) 2.1(1.47) 92.1(1.1646) 92.1(1.1763) 92.2(1.101).
CWE-78 Feb 03, 2017
CVE-2016-9873 6.3 MEDIUM EPSS 0.01
EMC Documentum D2 - Command Injection
EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system. An authenticated low-privileged attacker could potentially exploit this vulnerability to access information, modify data or disrupt services by causing execution of arbitrary DQL commands on the application.
CWE-77 Feb 03, 2017
CVE-2016-9872 6.1 MEDIUM EPSS 0.00
EMC Documentum D2 - XSS
EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has Reflected Cross-Site Scripting Vulnerabilities that could potentially be exploited by malicious users to compromise the affected system.
CWE-79 Feb 03, 2017
CVE-2016-8216 6.7 MEDIUM EPSS 0.00
EMC DD OS <5.5.5.0, <5.6.2.0, <5.7.2.10 - Command Injection
EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Data Domain OS (DD OS) 5.6 family all versions prior to 5.6.2.0, EMC Data Domain OS (DD OS) 5.7 family all versions prior to 5.7.2.10 has a command injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.
CWE-264 Feb 03, 2017
CVE-2016-6649 6.7 MEDIUM EPSS 0.00
EMC RecoverPoint <4.4.1.1-5.0 - Command Injection
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root.
CWE-77 Feb 03, 2017
CVE-2016-6648 4.4 MEDIUM EPSS 0.00
EMC RecoverPoint <4.4.1.1 - Info Disclosure
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A malicious administrator with configuration privileges may access this sensitive system file and compromise the affected system.
CWE-275 Feb 03, 2017
CVE-2016-0919 6.1 MEDIUM EPSS 0.00
EMC RSA Web Threat Detection <5.1.2 - XSS
EMC RSA Web Threat Detection version 5.0, RSA Web Threat Detection version 5.1, RSA Web Threat Detection version 5.1.2 has a cross site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.
CWE-79 Feb 03, 2017
CVE-2016-0890 6.4 MEDIUM EPSS 0.00
EMC PowerPath Virtual - Info Disclosure
EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclosure vulnerability that may potentially be exploited by malicious users to compromise the affected system.
CWE-200 Feb 03, 2017
CVE-2016-6116 5.9 MEDIUM EPSS 0.00
IBM Tivoli Key Lifecycle Manager <2.7 - Info Disclosure
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CWE-200 Feb 02, 2017
CVE-2016-6099 5.3 MEDIUM EPSS 0.00
IBM Tivoli Key Lifecycle Manager <2.7 - Info Disclosure
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.
CWE-200 Feb 02, 2017
CVE-2016-5935 5.9 MEDIUM EPSS 0.00
IBM Jazz - Info Disclosure
IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CWE-200 Feb 02, 2017
CVE-2016-6238 5.5 MEDIUM EPSS 0.00
Dropbox lepton 1.0 - DoS
The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds read) via a crafted jpeg file.
CWE-125 Feb 02, 2017
CVE-2016-6237 5.5 MEDIUM EPSS 0.00
Dropbox lepton <1.0 - DoS
The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file.
CWE-787 Feb 02, 2017
CVE-2016-6236 5.5 MEDIUM EPSS 0.00
Dropbox lepton 1.0 - DoS
The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file.
CWE-125 Feb 02, 2017
CVE-2016-6235 5.5 MEDIUM EPSS 0.00
Dropbox lepton 1.0 - DoS
The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file.
CWE-399 Feb 02, 2017
CVE-2016-6234 5.5 MEDIUM EPSS 0.00
Dropbox lepton 1.0 - DoS
The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file.
CWE-20 Feb 02, 2017