CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,325 CVEs tracked 53,302 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,931 Nuclei templates 48,916 vendors 42,598 researchers
110,849 results Clear all
CVE-2016-7046 5.9 MEDIUM EPSS 0.04
Redhat Jboss Enterprise Application P... - Resource Management Error
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
CWE-399 Oct 03, 2016
CVE-2016-6905 6.5 MEDIUM EPSS 0.01
Libgd < 2.2.2 - Out-of-Bounds Read
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA image.
CWE-125 Oct 03, 2016
CVE-2015-8086 4.9 MEDIUM EPSS 0.00
Huawei AR <V200R007C00SPC100, Quidway S9300 <V200R009C00, S12700 <V...
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for remote authenticated administrators to obtain encryption keys and ciphertext passwords via vectors related to key storage.
CWE-326 Oct 03, 2016
CVE-2015-8085 4.9 MEDIUM EPSS 0.00
Huawei AR <V200R007C00SPC100, Quidway S9300 <V200R009C00, S12700 <V...
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrators to obtain and decrypt passwords by leveraging selection of a reversible encryption algorithm.
CWE-326 Oct 03, 2016
CVE-2016-7572 4.3 MEDIUM EPSS 0.00
Drupal < 8.1.10 - Access Control
The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.
CWE-264 Oct 03, 2016
CVE-2016-7571 6.1 MEDIUM EPSS 0.00
Drupal < 8.1.10 - XSS
Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an HTTP exception.
CWE-79 Oct 03, 2016
CVE-2016-7570 4.3 MEDIUM EPSS 0.00
Drupal < 8.1.10 - Access Control
Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.
CWE-264 Oct 03, 2016
CVE-2016-6494 5.5 MEDIUM EPSS 0.00
MongoDB - Info Disclosure
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
CWE-200 Oct 03, 2016
CVE-2016-5398 5.4 MEDIUM EPSS 0.00
Redhat Jboss Bpm Suite < 6.3.2 - XSS
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
CWE-79 Oct 03, 2016
CVE-2016-1372 5.5 MEDIUM EPSS 0.00
ClamAV <0.99.2 - DoS
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
CWE-284 Oct 03, 2016
CVE-2016-1371 5.5 MEDIUM EPSS 0.01
ClamAV <0.99.2 - DoS
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
CWE-284 Oct 03, 2016
CVE-2016-7442 4.4 MEDIUM EPSS 0.00
Sophos Unified Threat Management Software - Information Disclosure
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.
CWE-200 Oct 03, 2016
CVE-2016-7397 4.4 MEDIUM EPSS 0.00
Sophos Unified Threat Management Software - Information Disclosure
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.
CWE-200 Oct 03, 2016
CVE-2016-3625 6.5 MEDIUM EPSS 0.01
LibTIFF <4.0.6 - DoS
tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.
CWE-125 Oct 03, 2016
CVE-2016-3622 6.5 MEDIUM EPSS 0.01
LibTIFF <4.0.6 - DoS
The fpAcc function in tif_predict.c in the tiff2rgba tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted TIFF image.
CWE-369 Oct 03, 2016
CVE-2016-3619 6.5 MEDIUM EPSS 0.01
LibTIFF <4.0.6 - DoS
The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.
CWE-125 Oct 03, 2016
CVE-2016-3042 5.4 MEDIUM EPSS 0.00
IBM Websphere Application Server - XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients.
CWE-79 Oct 01, 2016
CVE-2016-0617 5.5 MEDIUM EPSS 0.00
Oracle Linux 6 - DoS
Unspecified vulnerability in the kernel-uek component in Oracle Linux 6 allows local users to affect availability via unknown vectors.
Sep 30, 2016
CVE-2016-6647 5.4 MEDIUM EPSS 0.00
EMC ViPR SRM <4.0.1 - XSS
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 30, 2016
CVE-2016-6636 5.3 MEDIUM EPSS 0.00
Pivotal Cloud Foundry <242 - Open Redirect
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.1; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 mishandles redirect_uri subdomains, which allows remote attackers to obtain implicit access tokens via a modified subdomain.
CWE-601 Sep 30, 2016