CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,495 CVEs tracked 53,311 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,933 Nuclei templates 48,945 vendors 42,609 researchers
110,974 results Clear all
CVE-2016-6724 5.5 MEDIUM EPSS 0.00
Google Android < 4.4.4 - Improper Access Control
A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to cause the device to continually reboot. This issue is rated as Moderate because it is a temporary denial of service that requires a factory reset to fix. Android ID: A-30568284.
CWE-284 Nov 25, 2016
CVE-2016-6723 4.7 MEDIUM EPSS 0.00
Google Android < 4.4.4 - Improper Access Control
A denial of service vulnerability in Proxy Auto Config in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Android ID: A-30100884.
CWE-284 Nov 25, 2016
CVE-2016-6721 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-30875060.
CWE-200 Nov 25, 2016
CVE-2016-6719 5.5 MEDIUM EPSS 0.00
Google Android < 4.4.4 - Improper Access Control
An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to pair with any Bluetooth device without user consent. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission.) Android ID: A-29043989.
CWE-284 Nov 25, 2016
CVE-2016-6718 5.5 MEDIUM EPSS 0.00
Google Android < 7.0 - Information Disclosure
An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016-11-01 could enable a local malicious application to retrieve sensitive information without user interaction. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission.) Android ID: A-30455516.
CWE-200 Nov 25, 2016
CVE-2016-6716 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Google Android < 7.0 - Improper Access Control
An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create shortcuts that have elevated privileges without the user's consent. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission). Android ID: A-30778130.
CWE-284 Nov 25, 2016
CVE-2016-6715 5.5 MEDIUM EPSS 0.00
Google Android < 4.4.4 - Improper Access Control
An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could allow a local malicious application to record audio without the user's permission. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission.) Android ID: A-29833954.
CWE-284 Nov 25, 2016
CVE-2016-6714 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Improper Access Control
A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-31092462.
CWE-284 Nov 25, 2016
CVE-2016-6713 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Improper Access Control
A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30822755.
CWE-284 Nov 25, 2016
CVE-2016-6710 5.5 MEDIUM EPSS 0.00
Google Android < 5.0.2 - Information Disclosure
An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Android ID: A-30537115.
CWE-200 Nov 25, 2016
CVE-2016-6709 5.9 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is rated as High because it could be used to access data without permission. Android ID: A-31081987.
CWE-200 Nov 25, 2016
CVE-2016-6708 5.5 MEDIUM EPSS 0.00
Google Android < 7.0 - Security Feature Bypass
An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode. This issue is rated as High because it is a local bypass of user interaction requirements for any developer or security setting modifications. Android ID: A-30693465.
CWE-284 Nov 25, 2016
CVE-2016-6698 5.5 MEDIUM EPSS 0.00
Google Android < 7.0 - Information Disclosure
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30741851. References: Qualcomm QC-CR#1058826.
CWE-200 Nov 25, 2016
CVE-2016-3907 5.5 MEDIUM EPSS 0.00
Android <2016-11-05 - Info Disclosure
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30593266. References: Qualcomm QC-CR#1054352.
CWE-200 Nov 25, 2016
CVE-2016-3906 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Android <2016-11-05 - Info Disclosure
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30445973. References: Qualcomm QC-CR#1054344.
CWE-200 Nov 25, 2016
CVE-2016-5991 4.5 MEDIUM EPSS 0.00
IBM Sterling Connect:Direct <4.6.0.6-4.7.0.4 - Privilege Escalation
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0 before 4.6.0.6 iFix008, and 4.7.0 before 4.7.0.4 on Windows allows local users to gain privileges via unspecified vectors.
CWE-264 Nov 25, 2016
CVE-2016-5981 5.4 MEDIUM EPSS 0.00
IBM FileNet Workplace XT <1.1.5.2-WPXT-LA011 & 4.0.2.14-P8AE-IF001 ...
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace XT through 1.1.5.2-WPXT-LA011 and FileNet Workplace (Application Engine) through 4.0.2.14-P8AE-IF001, when RegExpSecurityFilter and ScriptSecurityFilter are misconfigured, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 25, 2016
CVE-2016-5968 5.3 MEDIUM EPSS 0.00
IBM Tealeaf Customer Experience <8.7.1.8847 FP10-<9.0.2.1223 FP3 - ...
The Replay Server in IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP3 allows remote attackers to conduct SSRF attacks via unspecified vectors.
CWE-918 Nov 25, 2016
CVE-2016-5967 5.5 MEDIUM EPSS 0.00
IBM Rational Asset Analyzer <6.1.0 - Info Disclosure
The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.
CWE-532 Nov 25, 2016
CVE-2016-5955 5.4 MEDIUM EPSS 0.00
IBM Rational DOORS Next Gen <6.0.2 - XSS
Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 6.0.2 before iFix004 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Nov 25, 2016