CVE & Exploit Intelligence Database

Updated 19m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,263 CVEs tracked 53,300 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 48,906 vendors 42,593 researchers
110,849 results Clear all
CVE-2016-6839 6.1 MEDIUM EPSS 0.00
Huawei FusionAccess <V100R006C00 - CRLF Injection
CRLF injection vulnerability in Huawei FusionAccess before V100R006C00 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CWE-113 Sep 07, 2016
CVE-2016-6670 5.3 MEDIUM EPSS 0.00
Huawei Firmware S12700 - Information Disclosure
Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate.
CWE-200 Sep 07, 2016
CVE-2016-6316 6.1 MEDIUM EPSS 0.02
Ruby on Rails <3.2.22.3-4.2.7.1-5.0.0.1 - XSS
Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.
CWE-79 Sep 07, 2016
CVE-2016-1242 4.4 MEDIUM EPSS 0.00
Tryton <3.2.17, <3.4.14, <3.6.12, <3.8.8, <4.0.4 - Info Disclosure
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
CWE-200 Sep 07, 2016
CVE-2016-1241 5.3 MEDIUM EPSS 0.00
Tryton <3.2.17, <3.4.14, <3.6.12, <3.8.8, <4.0.4 - Info Disclosure
Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated users to discover user password hashes via unspecified vectors.
CWE-200 Sep 07, 2016
CVE-2016-7033 6.1 MEDIUM EPSS 0.00
Redhat Jboss Bpm Suite - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Sep 07, 2016
CVE-2016-6351 6.7 MEDIUM EPSS 0.00
QEMU - DoS/Arbitrary Code Execution
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.
Sep 07, 2016
CVE-2016-6345 6.5 MEDIUM EPSS 0.00
RESTEasy - Info Disclosure
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
CWE-200 Sep 07, 2016
CVE-2016-6344 5.3 MEDIUM EPSS 0.00
Red Hat JBoss BPM Suite 6.3.x - Info Disclosure
Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.
CWE-200 Sep 07, 2016
CVE-2016-7153 5.3 MEDIUM EPSS 0.01
Microsoft Edge - Information Disclosure
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
CWE-200 Sep 06, 2016
CVE-2016-7152 5.3 MEDIUM EPSS 0.01
Opera - Information Disclosure
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
CWE-200 Sep 06, 2016
CVE-2016-5430 5.3 MEDIUM EPSS 0.00
Jose-php < 2.2.1 - Information Disclosure
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).
CWE-310 Sep 03, 2016
CVE-2016-1415 5.5 MEDIUM 1 PoC Analysis EPSS 0.04
Cisco WebEx Meetings Player T29.10 - DoS
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted file, aka Bug ID CSCuz80455.
CWE-399 Sep 03, 2016
CVE-2015-5720 6.1 MEDIUM 1 Writeup EPSS 0.00
MISP <2.3.90 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxification.js.
CWE-79 Sep 03, 2016
CVE-2016-5699 6.1 MEDIUM 2 PoCs Analysis EPSS 0.35
CPython <2.7.10, <3.4.4 - RCE
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
CWE-113 Sep 02, 2016
CVE-2016-5107 6.0 MEDIUM EPSS 0.00
Qemu < 2.6.2 - Out-of-Bounds Read
The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.
CWE-125 Sep 02, 2016
CVE-2016-5106 6.0 MEDIUM EPSS 0.00
Qemu < 2.6.2 - Out-of-Bounds Write
The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command.
CWE-787 Sep 02, 2016
CVE-2016-5105 4.4 MEDIUM EPSS 0.00
Qemu < 2.6.2 - Use of Uninitialized Resource
The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.
CWE-908 Sep 02, 2016
CVE-2016-4952 6.0 MEDIUM EPSS 0.00
Qemu < 2.6.2 - Out-of-Bounds Write
QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (2) PVSCSI_CMD_SETUP_MSG_RING SCSI command.
CWE-787 Sep 02, 2016
CVE-2016-0772 6.5 MEDIUM 1 PoC Analysis EPSS 0.06
CPython <3.4.5-2.7.12 - Info Disclosure
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
CWE-693 Sep 02, 2016