CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,535 CVEs tracked 53,316 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,936 Nuclei templates 48,971 vendors 42,621 researchers
111,009 results Clear all
CVE-2016-10072 5.3 MEDIUM EPSS 0.00
WampServer 3.0.6 - Privilege Escalation
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an executable file called wampmanager.exe or unins000.exe and replace the original files. The next time one of these programs is launched by a more privileged user, malicious code chosen by the local attacker will run. NOTE: the vendor disputes the relevance of this report, taking the position that a configuration in which "'someone' (an attacker) is able to replace files on a PC" is not "the fault of WampServer.
CWE-94 Dec 27, 2016
CVE-2016-9224 6.5 MEDIUM EPSS 0.00
Cisco Jabber Guest Server - SSRF
A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Releases: 11.0(0).
CWE-20 Dec 26, 2016
CVE-2016-9681 5.4 MEDIUM 1 Writeup EPSS 0.00
S9Y Serendipity < 2.0.4 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name.
CWE-79 Dec 25, 2016
CVE-2016-10006 6.1 MEDIUM 2 PoCs Analysis EPSS 0.01
OWASP AntiSamy <1.5.5 - XSS
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
CWE-79 Dec 24, 2016
CVE-2016-9923 5.5 MEDIUM EPSS 0.00
Qemu < 2.7.1 - Use After Free
Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging the device in the guest. A guest user/process could use this flaw to crash a Qemu process on the host resulting in DoS.
CWE-416 Dec 23, 2016
CVE-2016-9921 6.5 MEDIUM EPSS 0.00
Qemu < 2.7.1 - Divide By Zero
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host, resulting in DoS.
CWE-369 Dec 23, 2016
CVE-2016-9912 6.5 MEDIUM EPSS 0.00
Qemu < 2.8.1.1 - Resource Leak
Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while destroying gpu resource object in 'virtio_gpu_resource_destroy'. A guest user/process could use this flaw to leak host memory bytes, resulting in DoS for a host.
CWE-772 Dec 23, 2016
CVE-2016-9911 6.5 MEDIUM EPSS 0.00
Redhat Openstack < 2.7.1 - Resource Leak
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
CWE-772 Dec 23, 2016
CVE-2016-9907 6.5 MEDIUM EPSS 0.00
Qemu < 2.7.1 - Resource Leak
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
CWE-772 Dec 23, 2016
CVE-2016-7968 6.5 MEDIUM EPSS 0.00
KDE Kmail < 5.3.0 - Code Injection
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.
CWE-94 Dec 23, 2016
CVE-2016-7787 4.9 MEDIUM EPSS 0.01
Kde-cli-tools - Code Injection
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
CWE-94 Dec 23, 2016
CVE-2016-2312 6.8 MEDIUM EPSS 0.00
KDE Kscreenlocker < 5.5.4 - Security Feature Bypass
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
CWE-254 Dec 23, 2016
CVE-2016-6910 5.5 MEDIUM EPSS 0.00
Google Android - Information Disclosure
The non-existent notification listener vulnerability was introduced in the initial Android 5.0.2 builds for the Samsung Galaxy S6 Edge devices, but the vulnerability can persist on the device even after the device has been upgraded to an Android 5.1.1 or 6.0.1 build. The vulnerable system app gives a non-existent app the ability to read the notifications from the device, which a third-party app can utilize if it uses a package name of com.samsung.android.app.portalservicewidget. This vulnerability allows an unprivileged third-party app to obtain the text of the user's notifications, which tend to contain personal data.
CWE-200 Dec 23, 2016
CVE-2016-9889 6.1 MEDIUM EPSS 0.00
Tikiwiki Cms/groupware - XSS
Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don't have the input sanitized, related to tiki-setup.php and article_image.php. The impact is XSS.
CWE-79 Dec 23, 2016
CVE-2016-9561 5.5 MEDIUM EPSS 0.00
Ffmpeg < 3.2 - Resource Management Error
The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.
CWE-399 Dec 23, 2016
CVE-2016-8595 5.5 MEDIUM EPSS 0.00
FFmpeg <3.1.5 - DoS
The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
CWE-20 Dec 23, 2016
CVE-2016-7905 5.5 MEDIUM EPSS 0.01
Ffmpeg < 3.1.3 - NULL Pointer Dereference
The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.
CWE-476 Dec 23, 2016
CVE-2016-7785 5.5 MEDIUM EPSS 0.00
Ffmpeg < 3.1.3 - Improper Input Validation
The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
CWE-20 Dec 23, 2016
CVE-2016-7562 5.5 MEDIUM EPSS 0.01
Ffmpeg < 3.1.3 - Memory Corruption
The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.
CWE-119 Dec 23, 2016
CVE-2016-7555 5.5 MEDIUM EPSS 0.00
Ffmpeg < 3.1.3 - Information Disclosure
The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.
CWE-200 Dec 23, 2016