CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,535 CVEs tracked 53,316 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,936 Nuclei templates 48,971 vendors 42,621 researchers
111,009 results Clear all
CVE-2016-7122 5.5 MEDIUM EPSS 0.00
Ffmpeg < 3.1.3 - Resource Management Error
The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure.
CWE-399 Dec 23, 2016
CVE-2016-6881 5.5 MEDIUM EPSS 0.00
Ffmpeg < 3.1.2 - Resource Management Error
The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file.
CWE-399 Dec 23, 2016
CVE-2016-7091 4.4 MEDIUM EPSS 0.00
Redhat Enterprise Linux - Information Disclosure
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.
CWE-200 Dec 22, 2016
CVE-2016-9757 5.4 MEDIUM EPSS 0.00
Rapid7 Nexpose - XSS
In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags can inject cross-site scripting (XSS) elements in the tag name field. Once this tag is viewed in the Tag Detail page of the Rapid7 Nexpose 6.4.12 UI by another authenticated user, the script is run in that user's browser context.
CWE-79 Dec 20, 2016
CVE-2016-5303 6.1 MEDIUM EPSS 0.00
Horde Groupware - XSS
Cross-site scripting (XSS) vulnerability in the Horde Text Filter API in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows remote attackers to inject arbitrary web script or HTML via crafted data:text/html content in a form (1) action or (2) xlink attribute.
CWE-79 Dec 20, 2016
CVE-2016-4552 6.1 MEDIUM EPSS 0.00
Roundcube Webmail - XSS
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.
CWE-79 Dec 20, 2016
CVE-2016-7295 5.5 MEDIUM EPSS 0.01
Microsoft Windows 10 - Information Disclosure
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information from process memory via a crafted application, aka "Windows Common Log File System Driver Information Disclosure Vulnerability."
CWE-200 Dec 20, 2016
CVE-2016-7284 4.3 MEDIUM EPSS 0.24
Microsoft Internet Explorer - Information Disclosure
Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
CWE-200 Dec 20, 2016
CVE-2016-7282 6.1 MEDIUM EPSS 0.05
Microsoft Edge - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
CWE-79 Dec 20, 2016
CVE-2016-7281 5.3 MEDIUM EPSS 0.22
Microsoft Edge - Security Feature Bypass
The Web Workers implementation in Microsoft Internet Explorer 10 and 11 and Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Browser Security Feature Bypass Vulnerability."
CWE-254 Dec 20, 2016
CVE-2016-7280 6.1 MEDIUM EPSS 0.08
Microsoft Edge - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7206.
CWE-79 Dec 20, 2016
CVE-2016-7278 5.3 MEDIUM EPSS 0.20
Microsoft Internet Explorer - Information Disclosure
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows Hyperlink Object Library Information Disclosure Vulnerability."
CWE-200 Dec 20, 2016
CVE-2016-7267 5.5 MEDIUM EPSS 0.22
Microsoft Excel - Improper Input Validation
Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
CWE-20 Dec 20, 2016
CVE-2016-7258 5.5 MEDIUM EPSS 0.01
Microsoft Windows 10 - Information Disclosure
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-fault system calls, which allows local users to obtain sensitive information from arbitrary processes via a crafted application, aka "Windows Kernel Memory Address Information Disclosure Vulnerability."
CWE-200 Dec 20, 2016
CVE-2016-7257 6.5 MEDIUM EPSS 0.13
Microsoft Office For Mac - Information Disclosure
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
CWE-200 Dec 20, 2016
CVE-2016-7219 5.5 MEDIUM EPSS 0.01
Microsoft Windows 10 - Information Disclosure
The Crypto driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Windows Crypto Driver Information Disclosure Vulnerability."
CWE-200 Dec 20, 2016
CVE-2016-7206 6.1 MEDIUM EPSS 0.04
Microsoft Edge - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7280.
CWE-79 Dec 20, 2016
CVE-2016-5193 4.3 MEDIUM EPSS 0.00
Google Chrome < 53.0.2785.143 - Improper Input Validation
Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages.
CWE-20 Dec 18, 2016
CVE-2016-5192 6.5 MEDIUM EPSS 0.00
Google Chrome < 53.0.2785.143 - Improper Access Control
Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrackLoader, which allowed a remote attacker to bypass cross-origin restrictions via crafted HTML pages.
CWE-284 Dec 18, 2016
CVE-2016-5191 6.1 MEDIUM EPSS 0.00
Google Chrome < 53.0.2785.143 - XSS
Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pages, as demonstrated by an interpretation conflict between userinfo and scheme in an http://javascript:[email protected] URL.
CWE-79 Dec 18, 2016