CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,325 CVEs tracked 53,302 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,931 Nuclei templates 48,916 vendors 42,598 researchers
110,849 results Clear all
CVE-2016-6425 6.1 MEDIUM EPSS 0.00
Cisco CUIC <9.1 - XSS
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.
CWE-79 Oct 06, 2016
CVE-2016-6424 6.5 MEDIUM EPSS 0.01
Cisco ASA 8.4.7.29-9.1.7.4 - DoS
The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service (interface wedge) via a crafted rate of DHCP packet transmission, aka Bug ID CSCuy66942.
CWE-399 Oct 06, 2016
CVE-2016-6027 6.1 MEDIUM EPSS 0.00
IBM Sterling Secure Proxy <3.4.2.0-3.4.3.0 - Info Disclosure
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information or modify data by leveraging use of HTTP.
CWE-79 Oct 06, 2016
CVE-2016-6026 5.3 MEDIUM EPSS 0.00
IBM Sterling Secure Proxy <3.4.2.0-3.4.3.0 - Info Disclosure
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP method that is neither GET nor POST.
CWE-200 Oct 06, 2016
CVE-2016-6025 5.9 MEDIUM EPSS 0.00
IBM Sterling Secure Proxy <3.4.2.0-3.4.3.0 - Info Disclosure
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to obtain access by leveraging an unattended workstation to conduct a post-logoff session-reuse attack involving a modified URL.
CWE-264 Oct 06, 2016
CVE-2016-1454 6.5 MEDIUM EPSS 0.01
Cisco NX-OS - DoS
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
CWE-20 Oct 06, 2016
CVE-2016-6423 6.5 MEDIUM EPSS 0.00
Cisco IOS <15.5(3)M - DoS
The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via crafted IKEv2 packets, aka Bug ID CSCux97540.
CWE-399 Oct 05, 2016
CVE-2016-6421 5.3 MEDIUM EPSS 0.01
Cisco IOS XR <5.2.2 - DoS
Cisco IOS XR 5.2.2 allows remote attackers to cause a denial of service (process restart) via a crafted OSPF Link State Advertisement (LSA) update, aka Bug ID CSCvb05643.
CWE-399 Oct 05, 2016
CVE-2016-6418 6.1 MEDIUM EPSS 0.00
Cisco Videoscape Distribution Suite Service Manager <3.4.0 - XSS
Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552.
CWE-79 Oct 05, 2016
CVE-2016-6416 5.9 MEDIUM EPSS 0.01
Cisco AsyncOS - DoS
The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz86065.
CWE-119 Oct 05, 2016
CVE-2016-7909 4.4 MEDIUM EPSS 0.00
Qemu < 2.7.1 - Infinite Loop
The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0.
CWE-835 Oct 05, 2016
CVE-2016-7908 4.4 MEDIUM EPSS 0.00
Qemu < 2.7.1 - Infinite Loop
The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.
CWE-835 Oct 05, 2016
CVE-2016-7907 4.4 MEDIUM EPSS 0.00
Qemu < 2.8.1.1 - Improper Input Validation
The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.
CWE-399 Oct 05, 2016
CVE-2016-6652 5.6 MEDIUM EPSS 0.00
Pivotal Spring Data JPA <1.9.6-1.10.4 - SQL Injection
SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.
CWE-89 Oct 05, 2016
CVE-2016-6420 6.5 MEDIUM EPSS 0.00
Cisco FireSIGHT System Software - Auth Bypass
Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467.
CWE-200 Oct 05, 2016
CVE-2016-5901 5.4 MEDIUM EPSS 0.00
IBM Business Process Manager Advanced <8.5.7.0 - XSS
Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.09 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 05, 2016
CVE-2016-5892 5.4 MEDIUM EPSS 0.00
IBM 10x - XSS
Cross-site scripting (XSS) vulnerability in IBM 10x, as used in Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications before 1.0.0.5_2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Oct 05, 2016
CVE-2016-6550 5.4 MEDIUM EPSS 0.00
U by BB&T app <1.5.4 - XSS
The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CWE-310 Oct 05, 2016
CVE-2016-8280 6.5 MEDIUM EPSS 0.01
Huawei eSight <V300R003C20SPC005 - Path Traversal
Directory traversal vulnerability in Huawei eSight before V300R003C20SPC005 allows remote authenticated users to read arbitrary files via unspecified vectors.
CWE-22 Oct 03, 2016
CVE-2016-8277 6.5 MEDIUM EPSS 0.00
Huawei USG9520-9580 - DoS
Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote authenticated users to cause a denial of service (device restart) via an unspecified command parameter.
CWE-20 Oct 03, 2016