CVE & Exploit Intelligence Database

Updated 6h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,552 CVEs tracked 53,317 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 48,973 vendors 42,623 researchers
111,032 results Clear all
CVE-2016-9401 5.5 MEDIUM EPSS 0.00
bash <popd - Use After Free
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
CWE-416 Jan 23, 2017
CVE-2016-9385 6.0 MEDIUM EPSS 0.00
Xen 4.4.x-4.7.x - DoS
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
CWE-20 Jan 23, 2017
CVE-2016-7410 5.5 MEDIUM EPSS 0.00
Libdwarf - Out-of-Bounds Read
The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.
CWE-125 Jan 23, 2017
CVE-2016-6484 6.1 MEDIUM EPSS 0.00
Infoblox Network Automation <7.1.1 - CRLF Injection
CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.tdf.
CWE-93 Jan 23, 2017
CVE-2016-5876 5.9 MEDIUM EPSS 0.00
ownCloud <8.2.6 & <9.0.3 - Info Disclosure
ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download arbitrary images via a direct request.
CWE-264 Jan 23, 2017
CVE-2016-5237 4.8 MEDIUM 1 PoC Analysis EPSS 0.00
Valvesoftware Steamos < 3.42.16.13 - Access Control
Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files and possibly gain privileges as demonstrated by a Trojan horse Steam.exe file.
CWE-264 Jan 23, 2017
CVE-2016-4484 6.8 MEDIUM EPSS 0.00
Cryptsetup < 2.1.7.3-2 - Authentication Bypass
The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.
CWE-287 Jan 23, 2017
CVE-2016-4056 6.1 MEDIUM EPSS 0.00
TYPO3 6.2.x <6.2.19 - XSS
Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.
CWE-79 Jan 23, 2017
CVE-2016-4055 6.5 MEDIUM EPSS 0.04
moment <2.11.2 - DoS
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
CWE-400 Jan 23, 2017
CVE-2016-0765 6.1 MEDIUM EPSS 0.00
WordPress eShop plugin 6.3.14 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.
CWE-79 Jan 23, 2017
CVE-2015-8862 6.1 MEDIUM EPSS 0.00
Mustache.js < 2.2.0 - XSS
mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
CWE-79 Jan 23, 2017
CVE-2015-8861 6.1 MEDIUM EPSS 0.01
Handlebars.js < 4.0.0 - XSS
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
CWE-79 Jan 23, 2017
CVE-2015-8859 5.3 MEDIUM EPSS 0.01
Node.js Send <0.11.1 - Info Disclosure
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
Jan 23, 2017
CVE-2015-8856 6.1 MEDIUM EPSS 0.00
Openjsf Serve-index < 1.6.3 - XSS
Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web script or HTML via a crafted file or directory name.
CWE-79 Jan 23, 2017
CVE-2015-7743 6.5 MEDIUM EPSS 0.00
PRTG Network Monitor <16.2.23.3077-3078 - Info Disclosure
XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file.
CWE-611 Jan 23, 2017
CVE-2014-9772 6.1 MEDIUM EPSS 0.00
Validator <2.0.0 - XSS
The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters.
CWE-79 Jan 23, 2017
CVE-2013-7454 6.1 MEDIUM EPSS 0.00
Node.js <1.1.0 - XSS
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.
CWE-79 Jan 23, 2017
CVE-2013-7453 6.1 MEDIUM EPSS 0.00
Validator <1.1.0 - XSS
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing.
CWE-79 Jan 23, 2017
CVE-2013-7452 6.1 MEDIUM EPSS 0.01
Validator <1.1.0 - XSS
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI.
CWE-79 Jan 23, 2017
CVE-2013-7451 6.1 MEDIUM EPSS 0.01
Validator <1.1.0 - XSS
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.
CWE-79 Jan 23, 2017