CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,535 CVEs tracked 53,316 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,936 Nuclei templates 48,971 vendors 42,621 researchers
111,009 results Clear all
CVE-2016-6771 5.3 MEDIUM EPSS 0.00
Google Android - Improper Access Control
An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android. Versions: 6.0, 6.0.1, 7.0. Android ID: A-31566390.
CWE-284 Jan 12, 2017
CVE-2016-6769 4.6 MEDIUM EPSS 0.00
Google Android - Improper Access Control
An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart Lock settings without a PIN. This issue is rated as Moderate because it first requires physical access to an unlocked device where Smart Lock was the last settings pane accessed by the user. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1. Android ID: A-29055171.
CWE-284 Jan 12, 2017
CVE-2016-6767 5.5 MEDIUM EPSS 0.00
Google Android - Resource Management Error
A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4. Android ID: A-31833604.
CWE-399 Jan 12, 2017
CVE-2016-6766 5.5 MEDIUM EPSS 0.00
Google Android - Denial of Service
A denial of service vulnerability in libmedia and libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31318219.
CWE-19 Jan 12, 2017
CVE-2016-6765 5.5 MEDIUM EPSS 0.00
Google Android - Denial of Service
A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 7.0. Android ID: A-31449945.
CWE-19 Jan 12, 2017
CVE-2016-6764 5.5 MEDIUM EPSS 0.00
Google Android - Resource Management Error
A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31681434.
CWE-399 Jan 12, 2017
CVE-2016-6763 5.5 MEDIUM EPSS 0.00
Google Android - Improper Access Control
A denial of service vulnerability in Telephony could enable a local malicious application to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of local permanent denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31530456.
CWE-284 Jan 12, 2017
CVE-2016-6757 4.7 MEDIUM EPSS 0.00
Linux Kernel - Information Disclosure
An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-30148242. References: QC-CR#1052821.
CWE-200 Jan 12, 2017
CVE-2016-6756 4.7 MEDIUM EPSS 0.00
Linux Kernel - Information Disclosure
An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-29464815. References: QC-CR#1042068.
CWE-200 Jan 12, 2017
CVE-2016-4807 4.8 MEDIUM 1 PoC Analysis EPSS 0.00
Web2py < 2.14.5 - XSS
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).
CWE-79 Jan 11, 2017
CVE-2017-2947 5.5 MEDIUM EPSS 0.02
Adobe Acrobat < 11.0.18 - Improper Input Validation
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security bypass vulnerability when manipulating Form Data Format (FDF).
CWE-20 Jan 11, 2017
CVE-2017-2938 6.5 MEDIUM EPSS 0.02
Adobe Flash Player <24.0.0.186 - Auth Bypass
Adobe Flash Player versions 24.0.0.186 and earlier have a security bypass vulnerability related to handling TCP connections.
Jan 11, 2017
CVE-2016-9247 5.9 MEDIUM EPSS 0.01
BIG-IP - DoS
Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets may cause the Traffic Management Microkernel (TMM) to restart.
CWE-20 Jan 10, 2017
CVE-2016-6837 6.1 MEDIUM EPSS 0.01
Mantisbt < 1.2.18 - XSS
Cross-site scripting (XSS) vulnerability in MantisBT Filter API in MantisBT versions before 1.2.19, and versions 2.0.0-beta1, 1.3.0-beta1 allows remote attackers to inject arbitrary web script or HTML via the 'view_type' parameter.
CWE-79 Jan 10, 2017
CVE-2015-4591 6.1 MEDIUM 1 PoC Analysis EPSS 0.02
Eclinicalworks Population Health - XSS
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter.
CWE-79 Jan 10, 2017
CVE-2016-8106 5.9 MEDIUM EPSS 0.03
Intel Ethernet Controller <5.05 - DoS
A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions.
CWE-20 Jan 09, 2017
CVE-2017-5217 5.5 MEDIUM EPSS 0.00
Samsung Android KK-LM - DoS
Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission app will create an active install session for a separate app that it has embedded within it. The active install session of the embedded app is performed using the android.content.pm.PackageInstaller class and its nested classes in the Android API. The active install session will write the embedded APK file to the /data/app directory, but the app will not be installed since third-party applications cannot programmatically install apps. Samsung has modified AOSP in order to accelerate the parsing of APKs by introducing the com.android.server.pm.PackagePrefetcher class and its nested classes. These classes will parse the APKs present in the /data/app directory and other directories, even if the app is not actually installed. The embedded APK that was written to the /data/app directory via the active install session has a very large but valid AndroidManifest.xml file. Specifically, the AndroidManifest.xml file contains a very large string value for the name of a permission-tree that it declares. When system_server tries to parse the APK file of the embedded app from the active install session, it will crash due to an uncaught error (i.e., java.lang.OutOfMemoryError) or an uncaught exception (i.e., std::bad_alloc) because of memory constraints. The Samsung Android device will encounter a soft reboot due to a system_server crash, and this action will keep repeating since parsing the APKs in the /data/app directory as performed by the system_server process is part of the normal boot process. The Samsung ID is SVE-2016-6917.
CWE-119 Jan 09, 2017
CVE-2017-5216 5.5 MEDIUM EPSS 0.00
Netop Remote Control <12.21 - Buffer Overflow
Stack-based buffer overflow vulnerability in Netop Remote Control versions 11.53, 12.21 and prior. The affected module in the Guest client is the "Import to Phonebook" option. When a specially designed malicious file containing special characters is loaded, the overflow occurs. 12.51 is the fixed version. The Support case ref is 00109744.
CWE-119 Jan 09, 2017
CVE-2016-9869 5.5 MEDIUM EPSS 0.00
EMC ScaleIO <2.0.1.1 - Privilege Escalation
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. Incorrect permissions on the SCINI driver may allow a low-privileged local attacker to modify the configuration and render the ScaleIO Data Client (SDC) server unavailable.
CWE-275 Jan 06, 2017
CVE-2016-9868 5.5 MEDIUM EPSS 0.00
EMC Scaleio < 2.0.1.0 - Security Feature Bypass
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may cause a denial-of-service by generating a kernel panic in the SCINI driver using IOCTL calls which may render the ScaleIO Data Client (SDC) server unavailable until the next reboot.
CWE-254 Jan 06, 2017