CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,575 CVEs tracked 53,318 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 48,991 vendors 42,653 researchers
111,032 results Clear all
CVE-2016-9260 5.4 MEDIUM EPSS 0.00
Tenable Nessus <6.9 - XSS
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
CWE-79 Jan 31, 2017
CVE-2016-8697 5.5 MEDIUM EPSS 0.00
potrace <1.13 - DoS
The bm_new function in bitmap.h in potrace before 1.13 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a crafted BMP image.
CWE-369 Jan 31, 2017
CVE-2016-8696 5.5 MEDIUM EPSS 0.00
potrace <1.13 - DoS
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8694 and CVE-2016-8695.
CWE-476 Jan 31, 2017
CVE-2016-8695 5.5 MEDIUM EPSS 0.00
potrace <1.13 - DoS
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8694 and CVE-2016-8696.
CWE-476 Jan 31, 2017
CVE-2016-8694 5.5 MEDIUM EPSS 0.00
potrace <1.13 - DoS
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8695 and CVE-2016-8696.
CWE-476 Jan 31, 2017
CVE-2016-8685 5.5 MEDIUM EPSS 0.00
potrace <1.13 - DoS
The findnext function in decompose.c in potrace 1.13 allows remote attackers to cause a denial of service (invalid memory access and crash) via a crafted BMP image.
CWE-119 Jan 31, 2017
CVE-2016-6329 5.9 MEDIUM EPSS 0.06
OpenVPN - Info Disclosure
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.
CWE-310 Jan 31, 2017
CVE-2016-6285 6.1 MEDIUM EPSS 0.01
Atlassian JIRA <7.2.2 - XSS
Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
CWE-79 Jan 31, 2017
CVE-2015-8976 6.1 MEDIUM EPSS 0.00
Mybb Merge System < 1.6.17 - XSS
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files."
CWE-79 Jan 31, 2017
CVE-2015-8975 6.1 MEDIUM EPSS 0.00
Mybb Merge System < 1.6.17 - XSS
Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 31, 2017
CVE-2016-9039 6.2 MEDIUM EPSS 0.00
Joyent SmartOS 20161110T013148Z - DoS
An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory exhaustion, resulting in a full system denial of service.
CWE-400 Jan 31, 2017
CVE-2016-5117 5.9 MEDIUM EPSS 0.00
Openntpd < 6.0 - Security Feature Bypass
OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp constraint with a valid certificate.
CWE-254 Jan 31, 2017
CVE-2016-3176 5.6 MEDIUM EPSS 0.00
Salt < 2015.5.9 - Authentication Bypass
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.
CWE-287 Jan 31, 2017
CVE-2016-2050 6.5 MEDIUM EPSS 0.01
libdwarf-20151114 - DoS
The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted elf file.
CWE-787 Jan 31, 2017
CVE-2016-9119 6.1 MEDIUM EPSS 0.01
MoinMoin <1.9.8 - XSS
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Jan 30, 2017
CVE-2016-5434 5.5 MEDIUM EPSS 0.00
Pacman - Out-of-Bounds Read
libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted signature file.
CWE-399 Jan 30, 2017
CVE-2016-5026 5.5 MEDIUM EPSS 0.00
Onionshare < 0.9.0 - Improper Access Control
hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.
CWE-284 Jan 30, 2017
CVE-2016-2402 5.9 MEDIUM 2 PoCs Analysis EPSS 0.03
Squareup Okhttp < 2.7.3 - Improper Certificate Validation
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.
CWE-295 Jan 30, 2017
CVE-2016-2217 5.3 MEDIUM EPSS 0.00
Socat <2.0.0-b8 - Info Disclosure
The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret.
CWE-320 Jan 30, 2017
CVE-2015-7331 6.6 MEDIUM EPSS 0.00
Puppetlabs Mcollective-puppet-agent < 1.11.0 - Security Feature Bypass
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --server argument.
CWE-254 Jan 30, 2017