CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,263 CVEs tracked 53,300 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 48,906 vendors 42,593 researchers
110,849 results Clear all
CVE-2016-6403 5.9 MEDIUM EPSS 0.01
Cisco IOS 15.6(1)T-IOS XE - DoS
The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service via a crafted packet, aka Bug IDs CSCuy82904, CSCuy82909, and CSCuy82912.
CWE-399 Sep 18, 2016
CVE-2016-4746 5.3 MEDIUM EPSS 0.00
Apple Iphone OS < 9.3.5 - Information Disclosure
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction.
CWE-200 Sep 18, 2016
CVE-2016-4741 5.9 MEDIUM EPSS 0.01
Apple Iphone OS < 9.3.5 - Security Feature Bypass
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.
CWE-254 Sep 18, 2016
CVE-2016-4719 5.5 MEDIUM EPSS 0.00
Apple Watchos < 2.2 - Information Disclosure
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application.
CWE-200 Sep 18, 2016
CVE-2016-1433 5.3 MEDIUM EPSS 0.01
Cisco IOS XR <6.0.1 - DoS
Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packets, aka Bug ID CSCuz66289.
CWE-399 Sep 18, 2016
CVE-2016-6643 6.1 MEDIUM EPSS 0.00
EMC ViPR SRM <3.7.2 - XSS
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 18, 2016
CVE-2016-6642 6.1 MEDIUM EPSS 0.00
EMC ViPR SRM <3.7.2 - CSRF
Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authentication of administrators for requests that upload files.
CWE-352 Sep 18, 2016
CVE-2016-0927 6.1 MEDIUM EPSS 0.00
Pivotal Cloud Foundry <1.6.17 - XSS
Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 18, 2016
CVE-2016-0926 6.1 MEDIUM EPSS 0.00
Pivotal Cloud Foundry Elastic Runtime <1.6.32, <1.7.8 - XSS
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.
CWE-79 Sep 18, 2016
CVE-2016-7419 5.4 MEDIUM 1 Writeup EPSS 0.00
Nextcloud Server < 9.0.51 - XSS
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.
CWE-79 Sep 17, 2016
CVE-2016-6644 5.3 MEDIUM EPSS 0.00
EMC Documentum D2 <4.5-4.6 - Info Disclosure
EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value.
CWE-200 Sep 17, 2016
CVE-2016-6401 5.3 MEDIUM EPSS 0.00
Cisco CRS 5.1-5.1.4 - DoS
Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause a denial of service (line-card reload) via crafted IPv6-over-MPLS packets, aka Bug ID CSCva32494.
CWE-399 Sep 17, 2016
CVE-2016-7420 5.9 MEDIUM 1 Writeup EPSS 0.01
Cryptopp Crypto++ < 5.6.4 - Information Disclosure
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.
CWE-200 Sep 16, 2016
CVE-2016-4278 6.5 MEDIUM EPSS 0.02
Adobe Flash Player <19.x-23.x - Auth Bypass
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4277.
Sep 14, 2016
CVE-2016-4277 6.5 MEDIUM EPSS 0.02
Adobe Flash Player <19.x-23.x - Auth Bypass
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4271 and CVE-2016-4278.
Sep 14, 2016
CVE-2016-4271 6.5 MEDIUM EPSS 0.02
Adobe Flash Player <19.x - Auth Bypass
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-4277 and CVE-2016-4278, aka a "local-with-filesystem Flash sandbox bypass" issue.
Sep 14, 2016
CVE-2016-3379 6.1 MEDIUM EPSS 0.08
Microsoft Exchange Server - XSS
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web script or HTML via a meeting-invitation request, aka "Microsoft Exchange Elevation of Privilege Vulnerability."
CWE-79 Sep 14, 2016
CVE-2016-3374 6.5 MEDIUM EPSS 0.32
Microsoft Edge - Information Disclosure
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.
CWE-200 Sep 14, 2016
CVE-2016-3373 5.5 MEDIUM 1 PoC Analysis EPSS 0.09
Microsoft Windows 10 - Access Control
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly implement registry access control, which allows local users to obtain sensitive account information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
CWE-264 Sep 14, 2016
CVE-2016-3372 6.6 MEDIUM EPSS 0.01
Microsoft Windows Server 2008 - Access Control
The kernel API in Microsoft Windows Vista SP2 and Windows Server 2008 SP2 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
CWE-264 Sep 14, 2016