CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,495 CVEs tracked 53,311 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,933 Nuclei templates 48,945 vendors 42,609 researchers
110,974 results Clear all
CVE-2016-9375 5.9 MEDIUM EPSS 0.01
Wireshark <2.2.1, <2.0.7 - DoS
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was successful.
CWE-399 Nov 17, 2016
CVE-2016-9374 5.9 MEDIUM EPSS 0.01
Wireshark 2.0.0-2.2.1 - Buffer Overflow
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-alljoyn.c by ensuring that a length variable properly tracked the state of a signature variable.
CWE-119 Nov 17, 2016
CVE-2016-9373 5.9 MEDIUM EPSS 0.01
Wireshark 2.0.0-2.2.1 - Use After Free
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dcerpc-nt.c and epan/dissectors/packet-dcerpc-spoolss.c by using the wmem file scope for private strings.
CWE-416 Nov 17, 2016
CVE-2016-9372 5.9 MEDIUM EPSS 0.00
Wireshark 2.2.0-2.2.1 - DoS
In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a capture file. This was addressed in plugins/profinet/packet-pn-rtc-one.c by rejecting input with too many I/O objects.
CWE-399 Nov 17, 2016
CVE-2016-7917 5.0 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.4.32 - Information Disclosure
The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (infinite loop or out-of-bounds read) by leveraging the CAP_NET_ADMIN capability.
CWE-125 Nov 16, 2016
CVE-2016-7916 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.5.3 - Race Condition
Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obtain sensitive information from kernel memory by reading a /proc/*/environ file during a process-setup time interval in which environment-variable copying is incomplete.
CWE-362 Nov 16, 2016
CVE-2016-7915 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.5.7 - Out-of-Bounds Read
The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstrated by a Logitech DJ receiver.
CWE-125 Nov 16, 2016
CVE-2016-7914 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.5.2 - NULL Pointer Dereference
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.
CWE-125 Nov 16, 2016
CVE-2015-8964 5.5 MEDIUM EPSS 0.00
Linux Kernel < 4.4.32 - Information Disclosure
The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel before 4.5 allows local users to obtain sensitive information from kernel memory by reading a tty data structure.
CWE-200 Nov 16, 2016
CVE-2016-9318 5.5 MEDIUM EPSS 0.00
libxml2 <2.9.4 - XXE
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
CWE-611 Nov 16, 2016
CVE-2016-7165 6.4 MEDIUM EPSS 0.00
Siemens Primary Setup Tool < 14.0 - Security Feature Bypass
A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2), SIMATIC STEP 7 V5.X (All versions < V5.5 SP4 HF11), SIMATIC WinCC (TIA Portal) Basic, Comfort, Advanced (All versions < V14), SIMATIC WinCC (TIA Portal) Professional V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) Professional V14 (All versions < V14 SP1), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1), SIMATIC WinCC V7.0 SP2 and earlier versions (All versions < V7.0 SP2 Upd 12), SIMATIC WinCC V7.0 SP3 (All versions < V7.0 SP3 Upd 8), SIMATIC WinCC V7.2 (All versions < V7.2 Upd 14), SIMATIC WinCC V7.3 (All versions < V7.3 Upd 11), SIMATIC WinCC V7.4 (All versions < V7.4 SP1), SIMIT V9.0 (All versions < V9.0 SP1), SINEMA Remote Connect Client (All versions < V1.0 SP3), SINEMA Server (All versions < V13 SP2), SOFTNET Security Client V5.0 (All versions), Security Configuration Tool (SCT) (All versions < V4.3 HF1), TeleControl Server Basic (All versions < V3.0 SP2), WinAC RTX 2010 SP2 (All versions), WinAC RTX F 2010 SP2 (All versions). Unquoted service paths could allow local Microsoft Windows operating system users to escalate their privileges if the affected products are not installed under their default path ("C:\Program Files\*" or the localized equivalent).
CWE-284 Nov 15, 2016
CVE-2016-9286 5.3 MEDIUM 1 Writeup EPSS 0.00
Exponent CMS <v2.4.0patch1 - Info Disclosure
framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access to user records, which allows remote attackers to read address information, as demonstrated by an address/show/id/1 URI.
CWE-200 Nov 11, 2016
CVE-2016-9285 5.3 MEDIUM 1 Writeup EPSS 0.00
Exponent CMS <2.4.0 - Info Disclosure
framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modified id number, as demonstrated by address/edit/id/1, related to an "addresses, countries, and regions" issue.
CWE-200 Nov 11, 2016
CVE-2016-9284 5.3 MEDIUM 1 Writeup EPSS 0.00
Exponent CMS v2.4.0 - Info Disclosure
getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via users/getUsersByJSON/sort/ and a trailing string.
CWE-200 Nov 11, 2016
CVE-2016-7148 6.1 MEDIUM EPSS 0.00
Moinmoin < 1.9.9 - XSS
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.
CWE-79 Nov 10, 2016
CVE-2016-7146 6.1 MEDIUM EPSS 0.00
Moinmoin < 1.9.9 - XSS
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via page name) component.
CWE-79 Nov 10, 2016
CVE-2016-7252 6.5 MEDIUM EPSS 0.20
Microsoft Sql Server - Information Disclosure
Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."
CWE-200 Nov 10, 2016
CVE-2016-7251 6.1 MEDIUM EPSS 0.08
Microsoft Sql Server - XSS
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."
CWE-79 Nov 10, 2016
CVE-2016-7244 5.5 MEDIUM EPSS 0.17
Microsoft Office - Improper Access Control
Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability."
CWE-284 Nov 10, 2016
CVE-2016-7237 6.5 MEDIUM 1 PoC Analysis EPSS 0.56
Microsoft Windows 10 - Improper Access Control
Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote authenticated users to cause a denial of service (system hang) via a crafted request, aka "Local Security Authority Subsystem Service Denial of Service Vulnerability."
CWE-284 Nov 10, 2016