CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,552 CVEs tracked 53,317 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,938 Nuclei templates 48,973 vendors 42,623 researchers
111,010 results Clear all
CVE-2016-5205 6.1 MEDIUM EPSS 0.00
Google Chrome < 54.0.2840.99 - XSS
Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CWE-79 Jan 19, 2017
CVE-2016-5204 6.1 MEDIUM EPSS 0.00
Google Chrome < 54.0.2840.99 - XSS
Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CWE-79 Jan 19, 2017
CVE-2016-5201 6.5 MEDIUM EPSS 0.01
Google Chrome < 54.0.2840.87 - Information Disclosure
A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac allowed a remote attacker to access privileged JavaScript code via a crafted HTML page.
CWE-200 Jan 19, 2017
CVE-2016-9677 5.3 MEDIUM EPSS 0.00
Citrix Provisioning Services - Information Disclosure
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
CWE-200 Jan 18, 2017
CVE-2016-6283 6.1 MEDIUM 1 PoC Analysis EPSS 0.03
Atlassian Confluence <5.10.6 - XSS
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
CWE-79 Jan 18, 2017
CVE-2016-3999 6.1 MEDIUM EPSS 0.00
Zimbra Collaboration <8.7.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703.
CWE-79 Jan 18, 2017
CVE-2016-3414 6.5 MEDIUM EPSS 0.01
Zimbra Collaboration <8.6.0 Patch 7 - DoS
Unspecified vulnerability in Zimbra Collaboration before 8.6.0 Patch 7 allows remote authenticated users to affect availability via unknown vectors, aka bug 102029.
Jan 18, 2017
CVE-2016-3412 6.1 MEDIUM EPSS 0.00
Synacor Zimbra Collaboration Suite < 8.6.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103997, 104413, 104414, 104777, and 104791.
CWE-79 Jan 18, 2017
CVE-2016-3411 6.1 MEDIUM 1 PoC Analysis EPSS 0.10
Synacor Zimbra Collaboration Suite < 8.6.0 - XSS
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 103609.
CWE-79 Jan 18, 2017
CVE-2016-3410 6.1 MEDIUM EPSS 0.00
Synacor Zimbra Collaboration Suite < 8.6.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103956, 103995, 104475, 104838, and 104839.
CWE-79 Jan 18, 2017
CVE-2016-3409 6.1 MEDIUM EPSS 0.00
Synacor Zimbra Collaboration Suite < 8.6.0 - XSS
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 102637.
CWE-79 Jan 18, 2017
CVE-2016-3408 6.1 MEDIUM EPSS 0.00
Synacor Zimbra Collaboration Suite < 8.6.0 - XSS
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 101813.
CWE-79 Jan 18, 2017
CVE-2016-3407 6.1 MEDIUM EPSS 0.00
Synacor Zimbra Collaboration Suite < 8.6.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104222, 104910, 105071, and 105175.
CWE-79 Jan 18, 2017
CVE-2016-3401 6.5 MEDIUM EPSS 0.00
Zimbra Collaboration <8.7.0 - Info Disclosure
Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote authenticated users to affect integrity via unknown vectors, aka bug 99810.
Jan 18, 2017
CVE-2016-6897 6.5 MEDIUM 1 PoC Analysis EPSS 0.30
Wordpress < 4.5.5 - CSRF
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.
CWE-352 Jan 18, 2017
CVE-2016-10148 4.3 MEDIUM EPSS 0.00
WordPress <4.6 - Auth Bypass
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.
CWE-284 Jan 18, 2017
CVE-2016-10147 5.5 MEDIUM EPSS 0.00
Linux kernel <4.8.15 - DoS
crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an AF_ALG socket with an incompatible algorithm, as demonstrated by mcryptd(md5).
CWE-476 Jan 18, 2017
CVE-2016-9844 4.0 MEDIUM EPSS 0.10
Unzip - Memory Corruption
Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.
CWE-119 Jan 18, 2017
CVE-2016-9278 5.5 MEDIUM EPSS 0.00
Samsung Exynos fimg2d - DoS
The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736.
CWE-20 Jan 18, 2017
CVE-2016-9273 5.5 MEDIUM EPSS 0.00
libtiff 4.0.6 - DoS
tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.
CWE-125 Jan 18, 2017