CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,527 CVEs tracked 53,314 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,934 Nuclei templates 48,968 vendors 42,617 researchers
111,005 results Clear all
CVE-2016-9440 6.5 MEDIUM 1 Writeup EPSS 0.01
Tats W3m < 0.5.3-30 - NULL Pointer Dereference
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.
CWE-476 Dec 12, 2016
CVE-2016-9439 6.5 MEDIUM 1 Writeup EPSS 0.01
Tats W3m < 0.5.3-30 - Memory Corruption
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.
CWE-119 Dec 12, 2016
CVE-2016-9438 6.5 MEDIUM 1 Writeup EPSS 0.01
Tats W3m < 0.5.3-30 - NULL Pointer Dereference
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.
CWE-476 Dec 12, 2016
CVE-2016-9437 6.5 MEDIUM 1 Writeup EPSS 0.01
Tats W3m < 0.5.3-30 - Memory Corruption
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) and possibly memory corruption via a crafted HTML page.
CWE-119 Dec 12, 2016
CVE-2016-9434 6.5 MEDIUM 1 Writeup EPSS 0.01
Tats W3m < 0.5.3-30 - NULL Pointer Dereference
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.
CWE-476 Dec 12, 2016
CVE-2016-9433 6.5 MEDIUM 1 Writeup EPSS 0.01
Tats W3m < 0.5.3-30 - Out-of-Bounds Read
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (out-of-bounds array access) via a crafted HTML page.
CWE-125 Dec 12, 2016
CVE-2016-9432 6.5 MEDIUM 1 Writeup EPSS 0.01
Tats W3m < 0.5.3-30 - Memory Corruption
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (memory corruption, segmentation fault, and crash) via a crafted HTML page.
CWE-119 Dec 12, 2016
CVE-2016-9431 6.5 MEDIUM 1 Writeup EPSS 0.01
Tats W3m < 0.5.3-30 - Memory Corruption
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.
CWE-119 Dec 12, 2016
CVE-2016-9430 6.5 MEDIUM 1 Writeup EPSS 0.01
Tats W3m < 0.5.3-30 - NULL Pointer Dereference
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.
CWE-476 Dec 12, 2016
CVE-2016-9860 5.9 MEDIUM EPSS 0.01
Phpmyadmin < 4.6.5 - Improper Input Validation
An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbitraryServer']=true. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
CWE-20 Dec 11, 2016
CVE-2016-9859 5.3 MEDIUM EPSS 0.01
Phpmyadmin - Improper Input Validation
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
CWE-20 Dec 11, 2016
CVE-2016-9858 5.3 MEDIUM EPSS 0.01
Phpmyadmin - Improper Input Validation
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches feature. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
CWE-20 Dec 11, 2016
CVE-2016-9857 6.1 MEDIUM EPSS 0.00
Phpmyadmin < 4.6.5 - XSS
An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
CWE-79 Dec 11, 2016
CVE-2016-9856 6.1 MEDIUM EPSS 0.00
Phpmyadmin < 4.6.5 - XSS
An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a copy of a hash to avoid a race condition. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
CWE-79 Dec 11, 2016
CVE-2016-9855 5.3 MEDIUM EPSS 0.01
Phpmyadmin - Information Disclosure
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the PMA_shutdownDuringExport issue.
CWE-200 Dec 11, 2016
CVE-2016-9854 5.3 MEDIUM EPSS 0.01
Phpmyadmin - Information Disclosure
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the json_decode issue.
CWE-200 Dec 11, 2016
CVE-2016-9853 5.3 MEDIUM EPSS 0.01
Phpmyadmin < 4.6.5 - Information Disclosure
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the fopen wrapper issue.
CWE-200 Dec 11, 2016
CVE-2016-9852 5.3 MEDIUM EPSS 0.01
Phpmyadmin - Information Disclosure
An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin to display a PHP error message which contains the full path of the directory where phpMyAdmin is installed. During an execution timeout in the export functionality, the errors containing the full path of the directory of phpMyAdmin are written to the export file. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected. This CVE is for the curl wrapper issue.
CWE-200 Dec 11, 2016
CVE-2016-9851 5.3 MEDIUM EPSS 0.00
Phpmyadmin < 4.6.5 - Security Feature Bypass
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.
CWE-254 Dec 11, 2016
CVE-2016-9850 5.3 MEDIUM EPSS 0.01
Phpmyadmin - Security Feature Bypass
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
CWE-254 Dec 11, 2016